Effective date: January 1, 2026
Account Information: Email address, display name, and subscription status collected at registration and through your profile.
API Keys: If you choose to add your own AI provider API keys, they are stored encrypted using industry-standard encryption. They are used solely to fulfill your requests and are never shared.
Usage Data: We collect session-level data including queries made, AI provider used, and token usage for cost tracking purposes displayed to you in the app.
Payment Information: Payment details are processed by Stripe and never stored on our servers. We receive subscription status and customer identifiers from Stripe.
We use collected information to: (a) provide and improve the Service; (b) process payments and manage subscriptions; (c) send email alerts and briefings you have subscribed to; (d) display your usage statistics; (e) enforce our Terms of Service; (f) communicate service updates and important notices.
Your chat queries are sent to AI providers (Anthropic Claude, OpenAI, Google Gemini, or xAI Grok) to generate responses. If you use Investment Council's shared key, queries are processed under our provider accounts. If you use your own API key, queries are processed under your provider account directly. We do not store the content of individual chat messages in our database.
If you subscribe to email alerts, we send morning briefings, end-of-day recaps, AI picks, and market alerts based on your preferences. Every email includes an unsubscribe link. You may update your preferences at any time in the Alerts section of the app.
We do not sell your personal data. We share data only with: (a) Supabase — our database provider; (b) Stripe — for payment processing; (c) Resend — for transactional email delivery; (d) AI providers (Anthropic, OpenAI, Google, xAI) — solely to process your queries; (e) as required by law.
We implement industry-standard security measures including encryption at rest and in transit, secure API key storage, and access controls. However, no system is completely secure. You are responsible for maintaining the security of your account credentials.
We retain your account data for as long as your account is active. Upon account deletion, we delete your personal data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., billing records).
You have the right to: (a) access the personal data we hold about you; (b) correct inaccurate data; (c) request deletion of your data; (d) opt out of marketing emails at any time; (e) export your data. To exercise these rights, contact us at support@investmentcouncil.io.
We use essential cookies for authentication and session management. We do not use third-party tracking or advertising cookies. Your locale preference is stored in a cookie to remember your language setting.
The Service is not directed to children under 18. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal information, contact us immediately.
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or in-app notice. Continued use of the Service after changes constitutes acceptance of the revised Policy.
For privacy-related questions or requests, contact us at: support@investmentcouncil.io