Privacy Policy
Version: 2.1.0 | Effective Date: December 22, 2025
Introduction
We value your privacy and implement measures to protect your personal data. This privacy policy explains how we handle your data when you visit our website, describes your rights, and outlines how the law protects you.
Geographic Scope: The Services are intended for users located in the United States and Canada. We do not market to, target, or actively solicit users in the European Union, United Kingdom, or European Economic Area. However, we apply strong data protection, minimization, and security practices to all users regardless of location.
Information We Collect
We collect minimal information to provide and enhance our services. Specifically, we collect:
Personal Information
- Email Address: Collected during account creation and used for account management, authentication, and subscription services through a secure OAuth 2.0 system.
- Username/Display Name: Used for account identification and personalization of your experience.
- Mobile Phone Number: Collected when you opt into SMS alert services. Stored securely and used exclusively for delivering market alert notifications via text message.
- SMS Consent Records: When you opt into SMS services, we record timestamp, IP address, user agent, and consent details for regulatory compliance with TCPA and telecommunications laws.
- Subscription Information: Current plan status, billing history, and preferences stored in our secure database.
- User Preferences: Settings such as watchlists, dashboard configurations, display preferences, and SMS alert settings.
Technical Information
- Analytics Data: Google Analytics collects anonymized usage data including page views, session duration, and feature usage to help us improve our services. This data cannot identify individual users.
- Application Logs: Server logs containing IP addresses, request timestamps, and technical error information for security and performance monitoring.
- API Usage Data: Records of your interactions with our financial data services, including requested stock symbols and timestamps.
Mobile App Information
When you use our mobile applications, we may also collect:
- Device Information: Device model, operating system version, unique device identifiers, and mobile network information for app functionality and support.
- App Usage Data: Which features you use, crash reports, and performance metrics to improve app stability and user experience.
- Push Notification Tokens: Device tokens to send you important account and market alerts (only with your permission).
- Biometric Data: If enabled, fingerprint or face recognition data is processed locally on your device for authentication and is never transmitted to our servers.
Third-Party Payment Processing
For transactions, we use Stripe, a third-party payment processor compliant with PCI DSS Level 1 standards, the highest level of payment data security. We do not store or process your payment details directly. All payment information is handled securely by Stripe on their platform according to their privacy policy.
Affiliate Program Data Collection
When you click an affiliate referral link to Profitelligence, we collect limited data for attribution and fraud prevention purposes:
- Affiliate Code: The unique identifier from the referral link URL parameter to credit the referring affiliate partner
- Click Timestamp: Date and time of your initial click on an affiliate link
- IP Address: Used for fraud detection and as a fallback attribution method (stored for 90 days)
- User Agent: Browser and device information for analytics and fraud prevention
- Referrer URL: The website or page where you clicked the affiliate link (for performance analytics)
- Landing Page: Which page on Profitelligence you arrived at via the affiliate link
LocalStorage for Attribution (Not Cookies)
We store affiliate codes in your browser's localStorage (not cookies) to maintain attribution for up to 30 days. This is different from tracking cookies:
- Not sent to servers with every request (unlike cookies)
- Not accessible across different websites (domain-locked)
- Not used for advertising or cross-site tracking
- Used exclusively for affiliate attribution functionality
- You can clear it anytime via browser settings or incognito mode
How we use affiliate data:
- Attribute signups to affiliate partners for commission purposes
- Detect and prevent fraudulent affiliate activity (self-referrals, bot traffic, etc.)
- Provide performance analytics to affiliates (aggregated, not individual user data)
- Ensure accurate commission calculations
Data retention for affiliate tracking:
- Click data: 90 days, then permanently deleted
- Attribution data: Permanent (while your account exists) - required for contract performance to pay affiliate commissions
- Commission records: 7 years for tax and financial compliance
Who has access to affiliate data:
- Affiliate partners see their own aggregated performance metrics only (clicks, conversions, commissions)
- Affiliates do NOT see individual user identities, emails, or personal information
- Profitelligence staff access data for fraud detection and payout processing only
- Affiliate data is never sold or shared with third parties
Why we process this data: Click tracking is necessary for fraud prevention and accurate affiliate attribution. Once you sign up, attribution data is required to honor our contractual obligations to affiliate partners. This data cannot be deleted while your account is active as it is essential for contract fulfillment.
Your Rights Regarding Affiliate Data
Before signup: You can request deletion of click data before creating an account by contacting us.
After signup: Attribution data is required for contract performance (paying affiliate commissions) and cannot be deleted while your account is active. Upon account deletion, all attribution data is anonymized or deleted except records required for tax compliance.
Important: Affiliate attribution is permanent and cannot be changed or transferred. Your pricing and service terms are not affected by affiliate attribution.
For Affiliate Partners
If you participate in our Affiliate Partner Program, we collect additional information:
- Application Data: Name, email, company name, website URL, promotional channels, platform, audience size, promotion plan, and experience level
- Payment Information: PayPal email address for commission payouts
- Performance Data: Clicks, conversions, commission amounts, and payout history
- Terms Acceptance: Record of your agreement to Affiliate Partner Terms including version, timestamp, and IP address
- Communication Records: Emails and support tickets related to your affiliate account
How we protect affiliate data:
- Encrypted storage using AWS encryption at rest
- Access limited to authorized personnel only
- Never sold or shared with third parties
- You can request data export (JSON format) at any time
Affiliate data rights:
- Access your performance data anytime via the affiliate dashboard
- Request complete data export in machine-readable format
- Update contact, payment, and promotional information
- Delete your affiliate account (forfeits pending commissions under 60 days)
- Commission records retained for 7 years for tax compliance even after account deletion
Data Processing Infrastructure
We store data in AWS with encryption at rest and in transit for ALL data. Minimal personal data is stored on servers as possible to meet compliance and regulation requirements.
AI Assistant and MCP Server Data
We maintain user privacy when using our AI-powered Assistant and MCP Server. Our data practices for these services are as follows:
Privacy-First AI Design
- No Query Content Logging: We do not persistently store, analyze, or perform analytics on your AI conversation content or queries. Requests may be temporarily processed in memory for response generation but conversation content is not persisted to any database or log storage.
- No User Data Selling: Your AI interactions are never sold, shared, or used for advertising purposes
- No Training on User Data: Your conversations are not used to train or improve AI models
- Minimal Data Retention: AI conversations are not persisted beyond your active session unless you explicitly save them
What we DO track for AI services:
- API Usage Counts: We track the number of API calls made to enforce subscription plan limits (e.g., daily/hourly request quotas)
- Timestamps: Request timestamps for rate limiting and usage metering purposes
- Error Logs: Technical error information (without conversation content) for debugging and service reliability
What we DO NOT track:
- The content of your questions or prompts to the AI Assistant
- The AI's responses to your queries
- Topics, symbols, or companies you ask about
- Patterns or trends in your AI usage behavior
- Any personally identifiable information within conversation context
MCP Server (Open Source)
Our MCP Server is open source and available at github.com/profitelligence/profitelligence-mcp-server. Regarding data handling:
- The MCP Server itself does not collect, store, or transmit any user data
- When the MCP Server makes API calls to Profitelligence backends, only usage metering data (API call counts) is recorded for subscription compliance
- You can inspect the complete source code to verify our data handling practices
- We encourage community review, modification, and self-hosting of the MCP Server
Why we track usage: API usage metering is essential for service delivery under your subscription agreement. This tracking is necessary for contract performance (enforcing plan limits) and does not require separate consent.
How We Use Your Information
We use the personal data collected for the following purposes:
- Providing secure access to our website and its features.
- Managing your account and subscription.
- Delivering SMS alert notifications when you opt-in to text message services.
- Maintaining compliance records for SMS and telecommunications regulations.
- Improving the functionality and performance of our services.
- Communicating updates about your account or changes to our policies.
We do not sell, share, or otherwise use your personal data for advertising or marketing purposes.
SMS Communication
When you opt-in to SMS alert services, we use your mobile phone number exclusively for:
- Sending market alerts and trading notifications based on your subscription preferences
- System notifications related to your account or service interruptions
- Compliance with opt-out requests (STOP messages) and managing your SMS preferences
- Delivery confirmations and troubleshooting message delivery issues
Your phone number is never shared with third parties for marketing purposes. You can opt-out of SMS services at any time by replying STOP to any message or updating your preferences in your account settings.
Data Security
We implement reasonable and appropriate security measures to protect your personal data from unauthorized access, use, or disclosure. Our security practices include:
- Limiting data access to authorized personnel who are bound by confidentiality obligations.
- Relying on third-party providers like Stripe and Google Analytics that meet industry-standard security practices.
- Ensuring all interactions with our website are encrypted using HTTPS.
Mobile App Tracking and Permissions
iOS App Tracking Transparency (ATT)
On iOS devices, we respect Apple's App Tracking Transparency framework:
- We do not currently use IDFA (Advertising Identifier) for advertising, cross-app tracking, or personalization
- We do not request ATT tracking permission as we do not engage in cross-site or cross-app tracking
- All app features work fully without any tracking permissions
- We do not sell your personal information or use it for targeted advertising
Android App Permissions
Our Android app requests permissions only when necessary for core functionality:
- Internet Access: Required to fetch financial data and sync your account
- Notifications: Optional permission to send market alerts and account updates
- Biometric Authentication: Optional permission for secure app access using fingerprint or face unlock
- Camera: Only requested if you need to scan QR codes or upload documents
Third-Party SDKs and Libraries
Our mobile apps may include third-party software development kits (SDKs) that collect data:
- Google Analytics for Mobile: Anonymized app usage analytics (with your consent)
- Firebase Crash Reporting: Anonymous crash and error reporting to improve app stability
- Authentication Services: Secure login and user verification services
- We ensure all third-party SDKs comply with our privacy standards and do not collect personal data without disclosure
Your Legal Rights
Under applicable data protection laws, you have the following rights regarding your personal data:
- Request access to the personal data we hold about you.
- Request correction of inaccurate or incomplete personal data.
- Request deletion of your personal data.
- Object to the processing of your personal data.
- Request restrictions on the processing of your personal data.
- Request the transfer of your personal data to another service provider.
Please note that we retain minimal user data: username, email, subscription status (necessary for account management), and mobile phone number with consent records when SMS services are enabled.
SMS-Specific Rights
In addition to your general data protection rights, you have specific rights regarding SMS data:
- Opt-Out Rights: You can stop SMS messages at any time by replying STOP or updating your account preferences
- Consent Withdrawal: You can withdraw SMS consent at any time, which will immediately stop all text message delivery
- Phone Number Updates: You can update or remove your phone number from your account settings at any time
- Delivery Preferences: You can modify which types of alerts are sent via SMS in your subscription settings
- Consent History: You can request a copy of your SMS consent records and opt-out history
Account Deletion
You have the right to request complete deletion of your account and associated data:
- Self-Service Deletion: You can delete your account directly through the app settings or web dashboard
- Email Request: Contact us at contact@profitelligence.com to request account deletion
- Processing Time: Account deletion requests are processed within 30 days of your request
- What Gets Deleted: Your profile, preferences, watchlists, subscription history, and all personal data
- What We Keep: Only anonymized analytics data and records required for legal compliance (tax records, etc.)
SMS Data Deletion: When you opt-out of SMS services or delete your account, your phone number is immediately removed from our active SMS systems. However, consent records and delivery logs may be retained for the periods specified in our data retention policy for regulatory compliance.
Important: Account deletion is permanent and cannot be undone. You will need to create a new account to use our services again.
Data Export and Portability
You have the right to receive a complete export of your personal data in a structured, commonly used, and machine-readable format. Our data export includes all personal information we maintain about you:
- Account Profile: Your email address, display name, subscription details, and account preferences stored in our database
- Authentication Profile: Your Firebase authentication record, including email verification status, account creation date, and login provider information
- Activity History: Login events with timestamps and user agent information (IP addresses are not stored for privacy compliance)
- Subscription Records: Complete transaction history, billing details, subscription changes, and payment provider information
- SMS Records: Your mobile phone number, SMS consent records with timestamps, opt-out preferences, and message delivery history
- User Content: Your watchlists, saved symbols, and dashboard configuration preferences
What We Cannot Export
- Google Analytics Data: Usage analytics are maintained in anonymized form and cannot be linked to individual users for export
- Payment Card Information: Credit card details and payment methods are processed and stored exclusively by Stripe. To obtain this information, please contact Stripe directly through their customer portal or privacy request system
- Market Data: Financial data and stock information are third-party services and not considered personal data
How to Request Your Data
You can export your data through two methods:
- Self-Service Export: Use the "Export Data" button in your account settings to instantly download a comprehensive JSON file containing all your personal data
- Email Request: Contact us at contact@profitelligence.com and we will provide your data export within 30 days of verification
Age Limitations
Our services are intended for individuals aged 18 and older. We do not knowingly collect data from anyone under 18. If we become aware of any such collection, we will delete the data immediately.
Cookies and Local Storage
We use cookies and local storage to enhance your experience and provide essential functionality. Here's what we use:
Essential Cookies (Always Active)
- Authentication Cookies: Secure session cookies for OAuth 2.0 authentication (SameSite=None;Secure)
- Preference Storage: Local storage for user interface preferences like dark mode and language settings
- Affiliate Attribution Storage: Browser localStorage (not cookies) storing affiliate referral codes for up to 30 days to ensure proper commission attribution. This does not track you across websites and is used solely for affiliate functionality. See "Affiliate Program Data Collection" section for details
- Security Tokens: Temporary tokens for API authentication and CSRF protection
Optional Cookies (Consent Required)
- Google Analytics Cookies: _ga, _gid, _gat cookies for usage analytics (only loaded with your consent)
- Performance Monitoring: Anonymous performance metrics to improve application speed
Cookie Management
You have full control over optional cookies:
- Grant or withdraw consent for analytics cookies at any time
- Our system automatically removes analytics cookies when consent is withdrawn
- Essential cookies cannot be disabled as they are required for core functionality
- You can clear all cookies through your browser settings, though this may impact functionality
Data Processing Location
Your data is processed and stored in AWS data centers located in the United States. By using our Services, you consent to the transfer and processing of your data in the United States. We apply strong encryption, access controls, and security practices to all stored data regardless of user location.
Data Retention
We retain your personal data only as long as necessary to provide our services and comply with legal obligations:
- Account Data: Retained while your account is active, plus 30 days after account deletion to allow for recovery
- Subscription Data: Billing history retained for 7 years for tax and accounting purposes, then permanently deleted
- SMS Data: Phone numbers retained while SMS services are active. Consent records retained for 3 years for regulatory compliance. Message delivery logs retained for 30 days for troubleshooting
- Affiliate Click Data: IP addresses, user agents, and referrer information retained for 90 days after initial click, then permanently deleted
- Affiliate Attribution Data: Permanent retention while your account exists (required for contract performance to pay affiliate commissions). Anonymized or deleted upon account closure except for tax compliance records
- Affiliate Commission Records: Retained for 7 years for tax reporting and financial compliance, then permanently deleted
- Affiliate Partner Data: Application information, performance data, and payment details retained while affiliate account is active. Commission history retained for 7 years after account closure for tax compliance
- Analytics Data: Google Analytics retains anonymized usage data for 26 months, then automatically deletes it
- Application Logs: Server logs containing IP addresses and technical data retained for 90 days for security monitoring
- Authentication Tokens: Session tokens automatically expire within 24 hours
- Payment Data: Processed and retained by Stripe according to their retention policies (we do not store payment details)
You can request immediate deletion of your account data at any time by contacting us. Upon account deletion, we will permanently remove all personal data except what is required for legal compliance (tax records, commission history, etc.).
Data Breach Notification
In the unlikely event of a data breach that may affect your personal information:
- We will promptly investigate and assess the breach upon discovery
- Affected users will be notified without unreasonable delay, as required by applicable law, via email with details about the breach
- We will provide clear information about what data was affected and steps we're taking to resolve the issue
- If required by law, we will notify relevant regulatory authorities
- We will provide guidance on steps you can take to protect yourself
Our security team continuously monitors our systems and has incident response procedures in place to minimize any potential impact.
Mobile App Store Compliance
Privacy Policy Accessibility
This privacy policy is available in multiple locations for your convenience:
- Within our mobile applications (iOS and Android) via the settings or legal section
- On our website at profitelligence.com/privacy
- In the Google Play Store and Apple App Store listings for our apps
Platform-Specific Disclosures
- Apple App Store: Our iOS app complies with Apple's App Privacy Details requirements (Privacy Nutrition Labels)
- Google Play Store: Our Android app includes a completed Data Safety Form disclosing all data collection practices
- Third-Party Services: All third-party SDKs and services used in our apps are disclosed in this policy
- No Surprise Data Collection: We do not collect any data not disclosed in this privacy policy
Mobile App Updates
When we update our mobile applications, any changes to data collection practices will be reflected in an updated privacy policy. Users will be notified of significant changes through in-app notifications or email.
Contact Us
If you have any questions or concerns about this privacy policy, please contact us at: contact@profitelligence.com.
Updates to Our Privacy Policy
This privacy policy may be updated periodically. Changes will be posted here, and we encourage you to review the policy regularly to stay informed.