Skip to content
theanalystai

Legal · Privacy

Your data, explained in plain structure.

How TheAnalystAI collects, uses, shares, retains, and protects personal information. Last updated September 7, 2026.

Introduction

This Privacy Policy explains how TheAnalystAI ('we', 'us', 'our') collects, uses, and protects your personal information when you use our thesis-monitoring service at theanalystai.com (the 'Service').

The Service does one thing: it records reasoning you write about companies you follow, checks new public disclosures from those companies against that reasoning, and tells you what changed. Some earlier tools remain accessible in an archive for people who were already using them; where this policy differs for those, it says so.

By using the Service, you consent to the practices described here.

Data We Collect

We collect information you give us, and information the Service produces while you use it.

  • Account information: email address and authentication details, handled by Firebase Authentication. We never see or store your password
  • Your reasoning: the text you write about why you own or follow a company, and the checkpoints you confirm. This is the most sensitive thing we hold, because it reveals what you own and why
  • Monitoring records: the companies you follow, the change cards produced for you, your briefings, and any corrections you send us when you think our reading is wrong
  • Notification preferences: whether you want email, how often, your timezone, and any unsubscribe you have used
  • Payment information: handled entirely by Paddle, who are the merchant of record. We receive a customer identifier, a subscription status and a billing period end. We never receive or store card numbers
  • Usage data: pages visited, features used, device type, browser and IP address
  • Cookies: essential cookies for signing you in, preference cookies for your theme and region, and analytics cookies only if you consent to them

We do not ask for and do not want your brokerage credentials, account numbers, position sizes, or the amount you have invested. The Service does not need them and has nowhere to put them.

How We Use Your Data

We use what we collect for these purposes and no others:

  • To run the Service: reading filings, comparing them with the checkpoints you confirmed, and producing your briefings
  • To manage your subscription through Paddle, and to apply the correct plan limits
  • To send you transactional messages about your account, and briefing emails only if you have opted in
  • To investigate a correction you send us when a change card was wrong, and to add that case to our evaluation set so the same mistake is caught in future
  • To detect and prevent abuse of expensive operations, using rate limits keyed to your account or address
  • To meet legal obligations and enforce our Terms of Service

We do not sell your data. We do not use what you own, or why you own it, to target advertising. We do not share your holdings with anyone.

AI Processing & Research Data

How automated processing works here is deliberately narrow, and worth being precise about:

  • The monitoring itself is not generative. Reading a filing's structured XBRL data, matching comparable periods and comparing figures against your checkpoints is deterministic arithmetic. No language model decides whether something changed
  • Matching your wording to an observable measure is done by a fixed set of rules, and anything we assumed is labelled as our assumption. You confirm every checkpoint before it is monitored, and you can edit it at any time
  • Where a model writes an interpretation, it is stored separately from the figures, labelled as interpretation in the interface, and never determines the state of a checkpoint
  • Your reasoning is not used to train any model, ours or anyone else's
  • Your reasoning is never included in the public sample, in a shareable page you have not explicitly turned on, or in any analytics payload. Analytics events carry a step name, a one-way hashed identifier and a timestamp
  • Filings and any file you provide are treated as untrusted data: they are stored, quoted and displayed, never executed and never treated as instructions

Data Sharing & Third Parties

We do not sell, rent or trade your personal information. These are the subprocessors we actually use, and what each one receives:

  • Google Cloud Platform and Firebase (United States): hosting, authentication and the database. They hold everything the Service stores, encrypted at rest
  • Paddle (Paddle.com Market Ltd): merchant of record for payments and tax. They receive your email and payment details directly; we receive only a customer id, a status and a period end
  • Our email provider: receives your email address and the contents of briefing emails you have opted into
  • SEC EDGAR (United States government): we send requests for public company filings, identified by a contact address as their fair-access policy requires. We never send them anything about you
  • Analytics: used only with your consent, and only receives pseudonymous step events, never your thesis text

We may also disclose information if required by law, subpoena or a valid government request, or transfer it as part of a merger, acquisition or sale of assets. If that happens we will say so on this page before it takes effect where we are able to.

Data Security

We implement robust security measures to protect your data:

  • All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption
  • Authentication is managed through Firebase Authentication with support for multi-factor authentication
  • Access to production systems is restricted to authorized personnel with role-based access controls
  • We conduct regular security assessments and penetration testing
  • Database backups are encrypted and stored in geographically distributed locations
  • We maintain an incident response plan and will notify affected users within 72 hours of a confirmed data breach

Data Retention

We keep data only while it is useful to you, or while the law requires it:

  • Your theses, checkpoints, change cards and briefings are kept while your account is open. Your plan determines how far back your briefing history is displayed; the underlying records are kept until you delete them
  • Previous versions of a thesis are kept so you can see how your thinking changed. Deleting your monitoring data removes them too
  • Deletion is available from your settings and removes every thesis, thesis version, scan, change card, briefing, delivery record and notification preference for your account. This is immediate and cannot be undone
  • We ask you to cancel an active subscription before deleting, so you are not charged again for a service you can no longer reach
  • Payment records are retained by Paddle for the period their own tax and accounting obligations require
  • Server logs are retained for 90 days
  • Shared filing documents and extracted figures are public company disclosures, not personal data. They are retained independently of any account, and deleting your account does not remove them because they were never yours
  • Records of automated messages we sent you are retained so that a retry cannot send the same message twice

Your Rights

Depending on your jurisdiction, you have the following rights regarding your personal data:

  • Access: request a copy of the personal data we hold about you
  • Rectification: request correction of inaccurate or incomplete data
  • Erasure: request deletion of your personal data ('right to be forgotten')
  • Portability: request your data in a structured, machine-readable format
  • Restriction: request that we limit the processing of your data
  • Objection: object to the processing of your data for certain purposes
  • Withdraw consent: withdraw consent for marketing communications at any time

To exercise any of these rights, contact us at contact@theanalystai.com. We will respond within 30 days.

International Data Transfers

TheAnalystAI operates globally. Your data may be transferred to and processed in countries other than your country of residence, including the United States and the European Economic Area. We ensure that appropriate safeguards are in place for all international data transfers, including Standard Contractual Clauses where required by GDPR.

Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal information, we will take steps to delete such information promptly.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page and updating the 'Last updated' date. For significant changes, we will also send you an email notification. Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.

Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

  • Email: contact@theanalystai.com
  • Website: theanalystai.com/contact

Privacy Request

Ask about your data or exercise your rights.

Use the contact page and include enough information for us to identify and route the request securely.

Independent thinking. Connected intelligence.