The principle
Broker statements are read by an assistant on the user's own computer. Only the numbers needed for the calculation reach us: dates, tickers, ISINs, quantities, prices and currencies.
This is not a statement of good intentions but the shape of the data: the contract has no fields for personal data. We additionally scan text values, and on finding a national identification number, an email address, a bank account number or a personal name we refuse the request entirely — naming the field, never repeating the value.
What we collect
- The email address given at purchase — the key is sent there.
- A payment identifier from Stripe, so settlements reconcile.
- A hash of the key — the key itself is not stored.
- A ledger of balance events: top-ups, calculations, key exchanges.
- Transaction fingerprints — irreversible digests of content that make recomputing the same transactions free. A transaction cannot be reconstructed from one.
What we never collect
- Broker files — there is no field to upload them into.
- Names, addresses, national identification or bank account numbers.
- File names — people name statements after themselves.
- The content of your conversation with the assistant.
How long
The ledger of balance events is kept as long as accounting rules require — the bookkeeping obligation outlives the right to erasure. On an erasure request the rows are anonymised rather than deleted: amounts and dates remain, the link to a person disappears.
Who else sees it
- Stripe — payment processing.
- Resend — delivering the key by email.
- Supabase — the database.
We do not sell data and do not use it for advertising profiles.
Your rights
You have the right to access, correct, delete and port your data. Write to the contact address — we answer within 30 days. Since accounts are not required, the email address used at purchase is enough to identify you.
The data controller is taxroam. Contact details are on the contact page.