Privacy Policy

Last updated: July 2026

1. Introduction

Ticker Talk ("we", "our", or "us") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share your information when you use our Service.

2. Information We Collect

2.1 Information You Provide

  • Account Information: Name, email address, and session identifiers processed by Clerk. Ticker Talk does not receive or store your authentication password.
  • Payment Information: Processed securely by Stripe; we do not store full credit card numbers
  • Research Content: Coverage lists, saved research threads, notes, and the questions you submit to the research agent
  • Applications and Communications: Design-partner coverage details and messages you send to our team

2.2 Information Collected Automatically

  • Usage Data: With optional analytics consent, bounded product events such as application, coverage, filing-review, and citation steps. Product analytics does not contain research prompts, application text, names, or email addresses.
  • Request Information: Browser or user-agent data, IP address, request identifiers, and security logs
  • Cookies: Essential cookies for authentication and optional analytics cookies

3. How We Use Your Information

We use your information to:

  • Provide, maintain, and improve the Service
  • Process payments and manage subscriptions
  • Send you important updates about the Service
  • Respond to your questions and support requests
  • Analyze usage patterns to improve user experience
  • Prevent fraud and ensure security
  • Comply with legal obligations

4. Data Sharing

We may share your information with:

  • Service Providers: Clerk (authentication), Railway (hosting), and the configured AI model provider used to process your research request. Stripe is used only if payment features are enabled.
  • Operational Observability: A configured monitoring or model-observability provider may process bounded request and response telemetry needed to operate and debug the Service.
  • Product Analytics: Only the bounded events described above are recorded after optional analytics consent; research prompts and design-partner application text are excluded.
  • Legal Requirements: When required by law or to protect our rights

We do not sell your personal data to third parties.

5. Data Retention

We retain account data while your account is active or as needed to provide the Service. Product analytics follows these additional rules:

  • Consented anonymous session events are automatically deleted after 30 days
  • Authenticated product events are included in data exports and account deletion
  • Account-linked audit history is included in exports. On account deletion, direct identifiers and request metadata are removed; only a non-identifying erasure-completion marker is retained for compliance.
  • Network metadata attached to contact messages is removed after 30 days
  • Completed account-export archives expire and are erased after seven days
  • Account deletion has a seven-day cancellation period before live records are removed

The in-product export covers account-linked product data. A public design-partner application or support message may have been submitted before an account existed and therefore may not be linked automatically; contact us from the same email address to access or erase that record.

6. Data Security

We implement appropriate technical and organizational measures to protect your data, including:

  • Encryption in transit (TLS) and infrastructure encryption at rest
  • Automated security and release testing
  • Access controls and authentication
  • Secure development practices

7. Your Rights (GDPR)

If you are in the EU/EEA, you have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate data
  • Erasure: Request deletion of your data ("right to be forgotten")
  • Portability: Receive your data in a structured, machine-readable format
  • Restriction: Limit how we process your data
  • Objection: Object to certain processing activities

To exercise these rights, contact us at privacy@tickertalk.io.

8. California Privacy Rights (CCPA)

If you are a California resident, you have the right to:

  • Know what personal information we collect and how it is used
  • Request deletion of your personal information
  • Opt out of the sale of personal information (we do not sell data)
  • Non-discrimination for exercising your rights

9. Cookies

We use the following types of cookies:

  • Essential Cookies: Required for authentication and core functionality
  • Analytics Cookies: Help us understand how you use the Service (optional)

You can manage cookie preferences through our cookie consent banner or your browser settings.

10. International Data Transfers

Your data may be processed in countries outside your jurisdiction. Where required, we use the provider and contractual safeguards applicable to those transfers.

11. Children's Privacy

The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children.

12. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of material changes via email or through the Service. Your continued use after changes constitutes acceptance.

13. Contact Us

For privacy-related inquiries, contact our privacy team at privacy@tickertalk.io.