Legal

Privacy Policy

Last updated September 12, 2026

01

What We Collect

InsiderWatch collects only what it needs to run an alert service. The complete inventory:

  • Account data, held by Clerk, our authentication provider: your name, email address, a password hash if you use password sign-in, your Google account link if you use Google sign-in, session cookies, and CAPTCHA verification data.
  • Subscription data: your email address, plan, Stripe customer ID, phone number, Telegram chat ID if you link a chat, alert preferences including your watchlist tickers, and a manage-page token. The authoritative record is our Neon Postgres database, protected by Neon’s own point-in-time restore. A mirrored copy in Vercel Blob storage, along with our other pipeline data, follows our daily backup schedule, retained for 30 days.
  • Free weekly digest signup, stored in the same database: the email address you enter, the page you signed up from, the time you signed up, a confirmation and unsubscribe token, and the time you confirmed or unsubscribed. Nothing is sent to an address until it clicks the confirmation link we email it (double opt-in).
  • Phone number: collected by Stripe at checkout and used for account verification and support only. We do not send automated text messages.
  • Payment data: handled entirely by Stripe. We never see or store full card numbers.
  • Support correspondence: when you email us, we keep the message and our reply for as long as needed to resolve the request and to keep a record of it.
  • First-party analytics: a pageview beacon records aggregate page counts only. No IP address, no identifiers, no cross-site tracking, no ads, no data sales.
  • Cookies and browser storage: Clerk session cookies for authentication, an admin session cookie used only by site operators, Stripe cookies during checkout, and a light-or-dark theme preference kept in your browser’s local storage. No advertising cookies, no third-party analytics cookies.
  • First-touch attribution cookie: on your first visit, we set one cookie recording the referring page, the landing page you arrived on, and any campaign parameters in the URL (such as utm_source). It expires after 90 days and is used only to understand where sign-ups come from, never for advertising or cross-site tracking.

We do not collect precise location, biometric data, financial account details beyond what Stripe needs to bill you, or any special categories of personal data. Brokerage accounts are never connected to InsiderWatch.

02

How We Use It

  • Deliver alerts: send you the alerts and service communications your plan and preferences select, by email, Telegram, and push where enabled.
  • Send the digest: send the free weekly digest to addresses that confirmed their signup, and nothing else to those addresses.
  • Billing: process payments and manage your trial and subscription through Stripe.
  • Support: respond to your requests and verify your account when you contact us.
  • Service integrity: keep accounts secure, prevent abuse, and diagnose technical issues.

We do not sell your personal information, we do not use it for advertising, and we do not send marketing unrelated to the service you subscribed to.

No automated decisions about you. Our AI reads public filings and disclosures to write alerts. It never sees your personal data and makes no decision about you, your account, or your pricing.

03

Delivery Channels

Email: alerts and the digest are sent through Resend. Alert emails contain a personal manage link: anyone with the link can view and change your alert preferences, so treat it like a password and do not forward alert emails without sharing it.

Telegram: optional. A chat is linked only when you open the connect link from your own dashboard and start the chat; that action is the opt-in. Send /stop in the chat or use Disconnect in the dashboard to unlink at any time.

Signal API, connected apps and webhooks (Pro): optional. If you create an API key we store only a hash of it, plus a short prefix so you can recognise it. If you connect an AI assistant or other app through our sign-in flow we store the app’s registration (its name and return address), hashed access and refresh tokens tied to your account, and when each was last used, so you can see and revoke every connection from your dashboard. What a connected app reads is then held by that app under its own privacy terms. If you register a webhook endpoint we store the URL, a signing secret, and a short delivery log (timestamps and response codes) so you can see what was sent. Alert content is then transmitted to the endpoint you chose; what that endpoint does with it is under your control, not ours. Removing the endpoint or revoking the key deletes those records.

Push: if you use the mobile app, Expo delivers push notifications; a web push pilot may deliver browser notifications where you enable them.

Discord: a Discord mirror may carry alert content for community distribution. It carries no personal data.

We do not send automated text messages. The phone number Stripe collects at checkout is used for account verification and support only.

04

Processors and Sharing

We use the following providers to operate InsiderWatch. Each receives only the data named here, processes it on our instructions, and is bound by its own contractual and security commitments:

  • Clerk: account authentication (name, email, password hash, Google sign-in, sessions, CAPTCHA).
  • Stripe: payment processing and subscription management, including the phone number collected at checkout.
  • Neon: database hosting for subscriber and digest records.
  • Vercel: cloud hosting and Blob storage, including the subscriber mirror and daily backups.
  • Resend: email delivery. Your email address is transmitted to Resend for sending.
  • Telegram: alert delivery for subscribers who link a chat (only the chat identifier and the alert text are transmitted). Separately, when a subscription is created, a short internal notice containing your email address and plan is sent over Telegram to the operator’s own private chat so we know a new member has joined. That notice goes to no one else, and your phone number is never sent to Telegram.
  • Expo: mobile push delivery when the mobile app is used (push token, platform, device name). Web push endpoints are stored for the web push pilot.
  • Anthropic: alert content is generated by sending public source material (filings, disclosures, press releases) to Anthropic’s Claude API. Subscriber personal data is never sent to the AI.
  • OpenAI: the first-pass screen that decides which public source items deserve full analysis can run on OpenAI’s API. It receives the same kind of public material (titles and short excerpts of filings, disclosures, and press releases) and never subscriber personal data.

A Discord mirror may carry alert content, which contains no personal data. Our public social accounts post only public filing and disclosure data, never anything about subscribers.

Beyond these processors, we disclose personal data only when the law requires it (a valid subpoena, court order, or similar legal process), to protect the rights or safety of our users or the service, or as part of a merger, acquisition, or sale of the service, in which case this policy continues to apply to your data until you are told otherwise. We do not sell or rent personal data, and we use no third-party advertising.

05

Data Retention

We keep your subscription data for the lifetime of your active subscription. When you cancel, the Stripe webhook deletes your subscriber record; your login account persists until you delete it in the dashboard (Account tab). Deleting your account removes your login, your subscription record, and your registered devices.

Digest signups are kept until you unsubscribe. After you unsubscribe we keep the address and the unsubscribe time only as a suppression record, so an old link or a stray form submission can never put you back on the list; email privacy@insiderwatch.ai if you want that record erased too.

Stripe keeps billing records for as long as tax and accounting law requires. Your subscriber record lives in our Neon Postgres database, protected by Neon’s own point-in-time restore, not a fixed backup window. The mirrored copy of that record in Vercel Blob storage, along with our other pipeline data, follows our daily backup schedule and ages out of the backup set within 30 days.

06

Your Rights

You can access, correct, and delete your data through the dashboard (Account tab) or by emailing privacy@insiderwatch.ai. You can also ask for a copy of the personal data we hold about you. We honor these requests regardless of jurisdiction, we respond within 30 days (45 days where a state law allows it, and we will tell you if we need more time), and we never charge for them unless a request is manifestly repetitive.

To protect your data we may ask you to confirm a request from the email address on the account. An authorized agent may submit a request on your behalf with your written permission.

EU, EEA, UK and Swiss residents: our legal bases for processing are performance of our contract with you (delivering the service you signed up for), your consent (the digest and Telegram channel, which you can withdraw at any time), and our legitimate interest in operating and securing the service. You have the rights of access, rectification, erasure, restriction, portability, and objection, and you may lodge a complaint with your supervisory authority.

California residents: the categories listed in What We Collect are the complete CCPA inventory of personal information we collect, and we have collected no other categories in the preceding 12 months. We do not sell or share personal information as defined by the CPRA, including for cross-context behavioral advertising, and we have no actual knowledge of selling or sharing data of anyone under 16. You may exercise your rights to know, delete, and correct via privacy@insiderwatch.ai; we will not discriminate against you for doing so.

Other US states (including Colorado, Connecticut, Virginia, Texas, Oregon, and others with comprehensive privacy laws): you have equivalent rights of access, correction, deletion, and portability, and the right to appeal a decision on your request by replying to our response. We do not engage in targeted advertising, sell personal data, or profile you in a way that produces legal or similarly significant effects.

Global Privacy Control and Do Not Track: because we do not sell or share personal data or use third-party tracking, there is nothing for these signals to switch off. We treat a GPC signal as an opt-out of sale and sharing as a matter of policy.

07

Security

We protect your data with encryption in transit, access controls, log redaction, and signed admin sessions. No method of transmission or storage is 100% secure. If a breach affects your personal data, we will notify affected users and regulators as required by law.

We will never ask for your password by email, chat, or phone. If a message claiming to be from InsiderWatch asks for it, forward it to privacy@insiderwatch.ai.

08

Children

InsiderWatch is for users 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If you believe we have inadvertently collected information from a minor, contact us at privacy@insiderwatch.ai and we will delete it promptly.

10

International

InsiderWatch is operated from the United States, and your data is processed in the United States by us and by the processors listed above. By using the service, you understand that your data is transferred to and processed there. Where a processor offers standard contractual clauses or an equivalent transfer mechanism for users outside the United States, we rely on it.

11

Changes

We may update this policy as the service evolves. Updates are posted on this page with a new date, and material changes are announced on the site or by email to active subscribers. Continued use after a change constitutes acceptance.

12

Contact

Questions about this policy or your data: privacy@insiderwatch.ai. Our accessibility commitments are described on the Accessibility page.