Privacy Policy
Effective July 22, 2026. Launch draft subject to counsel review.
Privacy nutrition label
Collected: account details, forecasts, private research, product activity, market evidence, and connected-broker records you authorize.
Why: operate, secure, measure, personalize, and improve the service.
Shared: processors needed to run the service; AI providers only for disclosed tasks. No private notes or identifiable event stream is sold.
Control: export or locally pseudonymize data and opt out of commercial aggregation in Privacy & Data.
AI and model use
Deterministic models calculate probabilities and risk gates. Generative AI may classify sources and draft explanations. Inputs may include public source excerpts and research context; provider, model, prompt version, input digest, confidence, and citations are recorded where agents are used. See the AI disclosure.
Internal learning and commercial products
Relevant first-party data may improve Forecast Alpha. Commercial feeds use platform-originated evidence and aggregate consumer-derived indicators. They exclude private notes, individual records, and pseudonymous event streams. Accounts may opt out of commercial aggregation.
Retention
- Market, signal, feature, and strategy evidence: Indefinite where source licensing permits.
- Price and quote history: Hot for 90 days, then eligible for archival.
- Product telemetry: 12 months.
- Private notes and theses: Until user deletion.
- Forecasts: Pseudonymously as part of the calibration record.
Rights and security
You may export account data or deactivate and pseudonymize the local Forecast Alpha account. Deactivation requires recurring subscriptions to be terminal, removes local Stripe customer and subscription crosswalks, revokes broker and webhook authority, and removes stored broker secrets. It does not delete records Stripe independently retains under its legal obligations and policies, or the separate Supabase authentication identity; signing in again may create a new local account. Contact forecast.alpha.support@gmail.com to request identity-provider erasure. Server-only credentials, row-level security, append-only evidence, access controls, and audit logs protect sensitive records.