Privacy policy
This policy explains what personal data AI Investor collects, why we use it, and the choices you have. It covers ai-investor.com, including the app, the cover page, and the book pages on this site.
The book checkout on Gumroad is a separate service. Gumroad's own privacy policy applies to that payment.
1. Who we are
Urban Pilgrim Analytics Pte. Ltd. (UEN 202643609W), a company incorporated in Singapore, is the organisation responsible for your personal data under the Personal Data Protection Act 2012 ("PDPA"). We run AI Investor. The registered address is 60 Paya Lebar Road, #06-28, Paya Lebar Square, Singapore 409051. The data protection contact is [email protected].
If UK GDPR or EU GDPR applies to you because of where you live, we are also the controller for that purpose. We have not appointed a UK or EU representative. You can complain to the Personal Data Protection Commission in Singapore (pdpc.gov.sg). If GDPR applies to you, you can also complain to your local data protection authority.
2. What we collect
Account. Username, email address, a hash of your password, a Firebase user id, profile name, and the time you accepted these policies. We do not store your password in a form we can read.
Portfolios. Names, base currencies, transactions, holdings, notes you enter, and figures calculated from them, including tax-worksheet figures.
Files you upload. Broker statements and screenshots you choose to import, and the text we extract from them. These can contain account numbers, names, and transaction history. Do not upload a file you are not allowed to share, and remove extra pages you do not need.
Chat. Messages you send, the replies, follow-up chips, and short holdings snapshots attached so the model can talk about a portfolio you asked about.
Watchlist, settings, and usage. Tickers you save, display settings, the chat model choice where we store one, and counts of generated chat tokens so we can apply limits.
Payments. If you subscribe, Stripe processes the card. We store a Stripe customer id, subscription status, price id, and the end of the current period. We do not receive or store your full card number.
Technical data. IP address, browser type, and timestamps in server and Cloudflare logs, used to deliver the site and investigate abuse. The login cookie is described below.
Book pages. The public book pages load Google Analytics (measurement id G-KT8EP4M893). That can set analytics cookies and send page and device data to Google. The logged-in app does not load that tag.
Email you send us. Whatever you include when you write to us.
3. How we use it
We use personal data to:
- create and secure your account, including password reset through Firebase;
- store portfolios, imports, the watchlist, and chat, and show them back to you;
- run AI chat and related summaries you ask for;
- take payment, keep a subscription in force, and handle failed payments and cancellations;
- apply usage limits, prevent abuse, debug, and keep the service available;
- tell you about a change to these terms, this policy, or the price of a plan you are on;
- meet a legal duty, such as tax and accounting records for payments, or a lawful request.
Under the PDPA we rely on your consent, including consent given when you open an account or start a subscription, and on the other bases the Act allows, including business improvement and legitimate interests for security, limits, and fixing faults. Where UK GDPR or EU GDPR applies to you, the matching bases are contract, legitimate interests, legal obligation, and consent where a non-essential cookie needs it.
The book-page analytics tag is not behind a consent banner today. You can block it with your browser, with a tracker-blocking extension, or with Google's Analytics opt-out add-on. We do not use that tag to advertise to you, and we do not sell personal information.
4. AI chat and statement files
When you use chat, the message and any holdings snapshot for that chat can be sent to the model that answers it. That may be xAI, if the reply uses Grok, or a model we run on machines we control. Those providers process the text to produce the reply. Do not put passwords, full payment card numbers, or other people's secrets into chat.
Broker-statement files are extracted on machines we operate. We do not send those files to xAI.
Chat output is unreviewed text. It is not a decision about you that produces a legal or similarly significant effect. Paying or not paying is what turns a subscription on or off.
5. Who we share data with
We use processors who handle data only to provide their service to us:
- Stripe — subscriptions and card payments;
- Google Firebase — authentication and password-reset email;
- xAI — chat replies when Grok is the model in use;
- EODHD — market data. We send ticker symbols and query parameters, not your name or account id;
- Cloudflare — delivery, DNS, and protection of the public site and API;
- Linode (Akamai) — the server that stores the application database;
- Google Analytics — book pages only, as described above.
We may also disclose information if the law requires it, or if we need to protect the service, our users, or our rights. If we sell or reorganise the service, the data needed to run it may transfer to the buyer, and we will tell you if the law requires notice.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
6. International transfers
We operate the service from Singapore. Stripe, Google, xAI, Cloudflare, and the server host process data in the United States and other countries. Before a transfer out of Singapore we take steps the PDPA requires so the recipient protects the data to a standard comparable to the PDPA. Where UK GDPR or EU GDPR also applies, we rely on the provider's standard contractual clauses, the UK International Data Transfer Addendum, or an equivalent safeguard in that provider's terms. A country's courts and authorities may be able to reach data stored there.
7. How long we keep it
We keep account, portfolio, chat, and upload data for as long as the account is open. If you ask us to delete the account, we delete or anonymise that data within 30 days, except records we need to keep for tax, accounting, fraud prevention, or legal claims. Payment records of that kind are typically kept for up to six years. Server logs are kept for up to 90 days unless a security investigation needs longer. Backups age out on their normal cycle after deletion. Stripe keeps payment records on Stripe's own schedule.
8. Security
We use HTTPS, hashed passwords, an HttpOnly session cookie, and access limits on the server. Statement files are not sent to xAI. No method of storage or transmission is perfectly secure. Please use a unique password.
9. Your rights
Under the PDPA you can ask for access to your personal data, ask for a correction, and withdraw consent. Withdrawing consent does not affect processing that already happened, and we may have to close the account if we cannot provide it without that data. You can complain to the PDPC.
Where UK GDPR, EU GDPR, or a US state law also applies, you can ask us to:
- confirm whether we hold personal data about you and for a copy of it;
- correct it;
- delete it;
- restrict or object to certain processing;
- receive a portable copy of data you provided, where the law gives that right;
- withdraw consent, where processing was based on consent. Withdrawal does not affect earlier lawful processing.
Email [email protected] from the address on the account, or tell us enough that we can verify it is you. We respond within one month, or we tell you if we need longer. There is no in-app delete or export button yet. A request by email is enough.
If you are in California, you can ask us to know, correct, or delete personal information, and to opt out of sale or sharing. We do not sell or share personal information as those terms are used in the CCPA, and we do not use sensitive personal information to infer characteristics for advertising. We will not discriminate against you for exercising these rights. You may use an authorised agent if you prove the agent is authorised and we can verify you. If we deny a request you may reply to that email and ask us to review it.
10. Children
The service is not for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us personal data, email us and we will delete the account.
11. Cookies and local storage
AIINVESTORSESSID is the login session cookie. It is strictly necessary to keep you signed in. It lasts up to 30 days, and it is HttpOnly, Secure on HTTPS, and SameSite Lax. Reading this policy does not set it. Signing in does.
The app stores a display preference (including the on-screen privacy mask) in local storage in your browser. That stays on your device.
Firebase may store its own authentication state in the browser when you use sign-in.
Book pages may set Google Analytics cookies, as described above. The logged-in app does not.
12. Changes
If we change this policy we will post the new version on this page and change the date at the top. If a change is material and we have your email, we will also email you. Where the law requires consent for a new use, we will ask.
13. Contact
Privacy questions and requests: [email protected]. The contract for using the service is the Terms of Service.