Back

Privacy Policy for FindStox

Last Updated: 8 September 2026

PRIVACY POLICY

FindStox ("we", "us", "our") operates https://www.findstox.com. This policy explains what personal data we collect, why, who we share it with, and the rights you have. It applies to the website, the app and the API, and it forms part of our Terms and Conditions.

FindStox handles financial data about your investments. We treat that as the most sensitive thing on the platform and the rest of this policy reflects that.

Controller: [LEGAL ENTITY NAME], [REGISTERED ADDRESS], the Netherlands, [KVK NUMBER]. Contact for all privacy matters: [email protected].


1. WHAT WE COLLECT

Account data
- Name, email address, and profile image.
- A hashed password, if you sign up with email and password. We never store the password itself.
- Your Google account identifier, name, email and avatar, if you sign in with Google.
- Email verification status and the timestamps of verification and reminder emails.

Billing data
- Your Stripe customer and price identifiers, your plan or tier, your credit and allowance balances, and the ledger of credit grants and spends.
- We do not receive or store card numbers. Stripe processes payments and holds the payment instrument.

Portfolio data (only if you connect a brokerage account)
- Your Interactive Brokers Flex Query token and query ID, stored encrypted.
- Daily snapshots imported from IBKR: net asset value, open positions, trades and transaction history, dividends and other income, fees and commissions, cash flows, and base currency. These financial fields are encrypted at rest in our database.
- Derived analytics such as performance metrics, returns, drawdown and IRR.
- Ticker mapping overrides you configure.

Journal and uploads
- Notes and annotations you attach to charts, and any files you upload with them. Files are stored in a private object-storage bucket; the note text is stored in our database.

Research data
- The tickers and briefs you submit, the run record and its status, the intermediate artefacts, the generated report, model, charts and deck, and the computing cost of the run.

Public profile data (only if you switch it on)
- Username, biography, links, and the performance metric blocks you choose to show. This is deliberately published to the open internet.

Access tokens
- For each MCP personal access token: a SHA-256 hash of the token, a short non-secret prefix, the label you gave it, its scopes, and when it was last used. The token itself is shown once at creation and never stored.

Communications and preferences
- Your notification settings, the log of alert and digest emails we sent you, unsubscribe state, and any support conversation you start with us.
- Email addresses submitted to lead, submission or download forms, and newsletter subscription status if you subscribe.

Technical data
- Server and API logs, including IP address, timestamp, endpoint and error information, kept for security, abuse prevention and debugging.
- Cookies and analytics data, as described in section 5.
- Anonymous performance measurements (web vitals).


2. WHY WE USE IT, AND ON WHAT LEGAL BASIS

Performance of our contract with you (Art. 6(1)(b) GDPR)
- Creating and running your account and authenticating you.
- Importing, storing, encrypting and displaying your portfolio, and computing analytics from it.
- Generating research reports and decks you paid for and delivering them to you.
- Sending filing alerts, digests and other coverage you subscribed to.
- Processing payments, tracking credits, and providing support.

Legitimate interests (Art. 6(1)(f) GDPR)
- Keeping the Service secure: rate limiting, abuse detection, fraud and chargeback handling.
- Debugging, monitoring reliability and improving the product in aggregate.
- Sending occasional onboarding or product emails to registered users, which you can switch off at any time.
We balance these against your rights and use the least data that achieves the purpose.

Consent (Art. 6(1)(a) GDPR)
- Analytics cookies, which are only set after you accept the cookie banner.
- Marketing emails and newsletter subscriptions where you opted in.
- Publishing a public profile.
You may withdraw consent at any time, without affecting processing already carried out.

Legal obligation (Art. 6(1)(c) GDPR)
- Retaining invoices and transaction records for tax and accounting purposes.

We do not use your data for automated decision-making that produces legal or similarly significant effects about you. The research pipeline analyses public companies, not you: your personal or portfolio data is not sent to it and is not used to train any AI model, ours or anyone else's.


3. WHO WE SHARE IT WITH

We do not sell personal data, and we do not share portfolio data for advertising.

We use the following processors and service providers, each only for the purpose listed:

Infrastructure
- Vercel — application hosting, serverless execution and the isolated sandbox that runs research code (US/EU).
- MongoDB Atlas — primary database (EU region).
- Cloudflare R2 — object storage for journal attachments, avatars and research artefacts.
- Upstash — Redis cache and distributed rate limiting.

Product and payments
- Stripe — payment processing, subscriptions and the customer portal (US/EU).
- Resend — transactional and notification email delivery.
- Crisp — support chat, if you start a conversation.
- Google — sign-in with Google, if you use it, and Google Analytics 4 if you accept analytics cookies.
- Beehiiv — newsletter delivery, if you subscribe.

Data sources
- Interactive Brokers — the read-only source of your portfolio data. We send your token to IBKR to retrieve your own reports; we send nothing about you to anyone else.
- Alpha Vantage, Financial Modeling Prep, Yahoo Finance, SEC EDGAR and other regulators' filing systems, and a web search provider — these receive tickers and queries, not your identity or holdings.
- DeepSeek — the large language model provider behind report generation. Prompts contain public-company research material. Your identity, account details and portfolio holdings are not sent. DeepSeek processes data outside the EEA.
- Google Translate — used to translate foreign-language headlines and documents. Only that text is sent.

At your own initiative
- If you create an MCP token and connect an external AI client such as Claude, that client reads your portfolio data on your instruction. From that point the data is processed by that provider under its own terms, outside our control. Revoke the token to stop it.

We may also disclose data where legally required, to enforce our Terms, or to protect the rights and safety of users, and to a successor if the business is transferred — in which case we will notify you beforehand.


4. INTERNATIONAL TRANSFERS

We host and store data in the EU where we can. Some providers listed above process data outside the EEA, including in the United States and, in DeepSeek's case, China. Those transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision, with the provider's own supplementary safeguards. You can ask us for details of the mechanism for a specific provider.


5. COOKIES AND ANALYTICS

Strictly necessary cookies keep you signed in and secure your session. They are set without consent because the Service cannot work without them.

Analytics cookies are used only if you accept them in the cookie banner. We use Google Analytics 4 with IP anonymisation enabled and Do Not Track respected. We decline analytics if you decline, and no analytics cookie is set. Your choice is stored locally in your browser; clear your site data to be asked again.

We do not run advertising cookies and do not build advertising profiles.


6. HOW WE PROTECT IT

- Traffic is encrypted in transit with TLS.
- Portfolio financial fields (NAV, positions, trades, dividends, fees, cash flows) and your IBKR token are encrypted at rest with application-level encryption, in addition to the database provider's own encryption.
- MCP tokens are stored only as SHA-256 hashes; passwords only as bcrypt hashes.
- Journal attachments live in a private bucket and are served only through short-lived signed URLs to their owner.
- API routes enforce per-user authorisation, and sensitive endpoints are rate limited.
- Model-generated code runs in an isolated sandbox with no credentials and a narrow network allow-list.

No system is completely secure. If a breach affects your personal data and poses a risk to you, we will notify you and the supervisory authority as required by Art. 33 and 34 GDPR.


7. HOW LONG WE KEEP IT

- Account, portfolio, journal and research data: for as long as your account exists.
- Disconnecting your broker stops new imports; existing snapshots remain until you delete them or delete your account.
- Deleting your account removes your portfolio snapshots, journal notes and attachments, avatar, MCP tokens, votes, invites, sessions and the user record itself, and cancels active subscriptions. Deletion is immediate and irreversible.
- Invoices and payment records are retained for as long as tax law requires (seven years in the Netherlands), and Stripe keeps its own records under its own policy.
- Server and security logs are kept for a short period, normally no longer than 90 days.
- Backups are overwritten on a rolling cycle, so a deleted record can persist in a backup for a short time before it is cycled out.


8. YOUR RIGHTS

Under the GDPR you have the right to access your data, to have it corrected, to have it erased, to restrict or object to processing, to data portability, and to withdraw consent at any time.

Several of these are built into the product:
- Access and portability: your dashboard shows your data, and export is available on request.
- Erasure: delete your account from your settings at any time. It is immediate.
- Objection to email: switch off notifications in your settings, or use the unsubscribe link in any email.
- Withdrawing analytics consent: clear the consent stored in your browser, or ask us.

For anything else, write to [email protected]. We answer within one month. We may ask you to confirm your identity before acting on a request about an account.

If you believe we mishandled your data you may complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or to the authority in your own EU country of residence.


9. CHILDREN

The Service is for adults aged 18 and over. We do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.


10. CHANGES TO THIS POLICY

We may update this policy. For material changes we will notify registered users by email or in the app before they take effect, and we will always update the date at the top. Continued use after the effective date means you accept the updated policy.


11. CONTACT

FindStox — [email protected]
[LEGAL ENTITY NAME], [REGISTERED ADDRESS], the Netherlands