What TickerTrac collects
We collect account information such as your email address, authentication records, watchlists, theses you author, alert and digest preferences, feedback, and the product events needed to operate and improve the service. If you choose to dictate instead of typing, we also process that voice recording as described below. Passwords are stored as one-way hashes. Payment details are handled by Stripe; TickerTrac does not store full card numbers.
Editorial email subscriptions
If you request the Editorial review, we store your email address, confirmation and consent timestamps, subscription status, and a general signup source such as an Instagram profile or Story. Our email provider receives your address to send confirmation and subscription emails. Subscription data is separate from your TickerTrac account and personal monitoring; subscribing creates neither an account nor a saved thesis. Your subscription address is not sent to AI providers.
Signup uses Cloudflare Turnstile to check browser, device, and network signals for automated abuse. We do not send your email address to Cloudflare. We retain provider message identifiers, delivery outcomes and timestamps, rather than copying email content or recipient addresses into the delivery-event ledger.
Unsubscribing removes your deliverable address from the subscription record. We retain a keyed identifier, consent history and delivery outcomes to honor suppression and prevent duplicate requests. Account deletion and Editorial unsubscribe are separate choices. For deletion or correction of subscription records, contact [email protected].
Research and AI processing
TickerTrac processes public-company filings, news, transcripts, market data, and your thesis to provide cited research and monitoring. Relevant prompts, excerpts, and authored thesis text may be sent to contracted AI and data infrastructure providers solely to deliver the service. We do not sell your thesis or personal information.
For the no-signup reason preview, the reason you submit is sent once to our contracted AI provider solely for that comparison. TickerTrac does not save the submitted reason, add it to analytics or public research, or carry it into signup.
The no-signup preview uses Cloudflare Turnstile to deter automated abuse. Cloudflare processes browser, device, and network signals for that anti-abuse check. TickerTrac does not send your submitted reason to Cloudflare.
Voice input
Voice is optional. When you dictate a reason, your device asks for microphone permission, and the recording, at most 90 seconds, is sent to our contracted speech-to-text provider solely to turn it into text. TickerTrac does not store the audio. The resulting text is shown to you to edit and kept as a private draft: in a Reason Interview until you delete it, the interview, or your account, and in the conversation composer for at most 24 hours. Only text you choose to save becomes part of a thesis. We keep each recording's length, size, and format to enforce daily limits and account for cost. We do not use recordings to identify you by your voice.
Mobile apps
The TickerTrac apps for Android and iPhone use the same account and data as the website. Your sign-in is kept in your phone's secure storage (the Android Keystore or iOS Keychain) and is removed when you log out.
Notifications are off until you turn them on. If you do, we store an encrypted notification token for your device, linked to your account, and deliver notifications through Google Firebase Cloud Messaging on Android or the Apple Push Notification service on iPhone. A notification says only that a scheduled review is ready; it never contains your theses, companies, or findings. Turning notifications off, or deleting your account, deletes the token.
When you create an account in the Android app, the app may ask Google Play to confirm that it is the genuine TickerTrac app on a genuine device, and our server checks Google's answer before creating the account. The request carries a one-way hash of your email address, not the address itself. Google processes app and device integrity signals for this check under its own terms.
Analytics and operational data
We use privacy-minimized first-party events to understand activation, reliability, alert usefulness, and cost. Product telemetry avoids copying thesis text into the analytics event ledger. A landing-page visit uses a tab-scoped random session value whose one-way server signature is retained solely to deduplicate refreshes; the analytics event does not retain the visitor's IP address, user agent, referrer, or a third-party tracking cookie. Server logs and error monitoring may contain request metadata needed to diagnose security and reliability problems.
For signed-in app performance, we collect limited timing and failure counts by broad world region. The browser reduces Cloudflare's approximate network country to a broad region before sending it to TickerTrac. This performance record contains no IP address, precise location, page URL, thesis text, or account ID. A daily keyed account signature bounds collection and deduplicates daily activity; it expires within two days. Aggregate measurements expire within 30 days. We honor browser Do Not Track and Global Privacy Control signals for this collection. Blocking it does not restrict product access.
For digest emails, our email provider may report delivery, bounce, complaint, approximate open, and link-click events. Open measurement uses a small tracking image and can be inaccurate when an email client blocks, caches, or preloads images. TickerTrac retains message identifiers, outcome types, and timestamps for delivery reliability and aggregate engagement measurement; the delivery-event ledger does not retain the message body, subject, or recipient address.
How information is shared
Information is shared only with service providers that help run authentication, hosting, databases, email, notifications, billing, error monitoring, abuse prevention, market-data retrieval, and AI processing; when required by law; or as part of a corporate transaction. We do not permit providers to use account data for unrelated advertising.
Retention, deletion, and export
Account data is retained while your account is active and as needed for security, billing, legal, and operational obligations. You can delete your account from the signed-in Settings page. Primary account records are removed through that flow; encrypted backups and security logs expire on their normal retention schedule. Request a portable export or correction at [email protected].
Security and choices
We use access controls, tenant-scoped authorization, encrypted network transport, and bounded operational logging. No online service can guarantee absolute security. You can pause alerts, change delivery preferences, cancel a paid plan, or delete your account at any time.
Children
TickerTrac is for adults 18 and older and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has created an account, contact [email protected] and we will delete it.
Contact and policy changes
Questions and privacy requests can be sent to [email protected]. Material policy changes will be posted here with a new effective date.