Privacy policy
Effective 25 July 2026
This describes what Materiality stores, which third parties receive it, and how to get it removed. It is written to match what the software actually does.
Card details are never sent to or stored by this service. Payments are handled entirely by Stripe, and what is kept here is a customer reference, a subscription status, and a renewal date.
What is collected
- Account. Your email address, a one-way hash of your password (the password itself is never stored or recoverable), and a display name if you provide one.
- What you record. Portfolios and their holdings, including ticker symbols, share counts, cost basis, purchase dates, and any notes. Watchlists. Investment theses, target prices, and bull and bear cases. Journal entries and their rationale.
- Preferences. Analysis style, length, risk profile, timeframe, theme, chart defaults, and notification choices.
- Usage. Which features are used and whether they succeeded, along with page, device type, plan, and a session identifier. This is tied to your account id so that limits and costs can be attributed, and is used to operate and improve the service.
- Billing. A Stripe customer and subscription reference, subscription status, billing interval, and current period end.
- Diagnostics. When something breaks on the server, the error message, the code path that failed, and the route it happened on are recorded so it can be fixed. Request headers, query strings, and submitted content are deliberately not recorded, so what you were looking at is not part of a crash report.
- Password resets. If you request one, a single-use token is stored in hashed form and expires within the hour. The link itself exists only in your email.
- Email confirmation. Whether your address has been confirmed, and a single-use token stored in hashed form while confirmation is pending. Confirming is what unlocks AI analyses; it exists to stop automated signups consuming them, not to identify you.
What is sent to the AI provider
Written analysis is generated by OpenAI. Nothing is sent to it unless you explicitly ask for a generation, and nothing is sent when a page merely loads.
- Company analysis and research reports. The ticker, public filing and market data for that company, and your analysis preferences. No personal data.
- Portfolio reviews and stress summaries. Portfolio-level figures about the portfolio you asked about: its name, how many holdings it contains, its total market value, the ticker symbols and weights of its largest positions, sector weights, volatility and drawdown, and the calculated health scores. Individual share counts, cost basis, and your notes are not included.
- Inbox insights and earnings previews. Ticker symbols you follow and public data about them.
Your email address, password, journal entries, and investment theses are never sent to the AI provider.
Other services involved
- Stripe processes payments and holds your card details under its own privacy policy.
- Vercel hosts the application and processes requests, including IP addresses, as part of serving and protecting it. Its Web Analytics also records page views: the page, referrer, country, and device type, all without cookies and without any identifier that could follow you to another site or be linked back to your account.
- Cloudflare checks that a person rather than a script is submitting the signup form. On that one page it receives your IP address and basic browser information. It is not used anywhere else on the site, sets no advertising cookies, and receives nothing you type into the form.
- Resend delivers the few emails this service sends, which today means password reset links and address confirmation links. It receives the recipient address and the message.
- Neon hosts the database where the data above is stored.
- SEC EDGAR, and market data providers receive requests for company and price data. They receive ticker symbols, not your identity or your holdings.
Your data is not sold, rented, or shared with advertisers, and there are no third-party advertising or tracking scripts on the site.
Cookies
A single sign-in cookie keeps you logged in. It is HTTP-only, so scripts cannot read it, and it exists only to identify your session. A theme preference may also be stored in your browser. There are no advertising or cross-site tracking cookies.
Keeping and deleting your data
Data is kept while your account exists. You can delete individual portfolios, holdings, watchlists, theses, journal entries, and saved analyses at any time from within the application, and those deletions are immediate.
To delete your account and everything attached to it, use Delete account in Settings. Deletion is immediate, permanent, and cancels any active subscription. You can also email norrowstudiossupport@gmail.com from your account address. Records required for tax, accounting, or fraud-prevention purposes, principally payment records held by Stripe, may be retained for as long as the law requires.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to certain processing, or to complain to a data protection authority. Email norrowstudiossupport@gmail.com and your request will be honoured.
Security
Passwords are hashed with bcrypt and never stored in a readable form. Traffic is encrypted in transit. No system is perfectly secure, and no absolute guarantee can be given.
Children
This service is not intended for anyone under 18, and accounts are not knowingly created for them. If you believe a child has provided personal data, email norrowstudiossupport@gmail.com and it will be removed.
Changes and contact
If this policy changes materially, the effective date above will change and account holders will be notified. Questions, access requests, and deletion requests go to norrowstudiossupport@gmail.com. The party responsible for the data described here is Kaleo Kailiuli, identified in full in the terms.