Position Intelligence

Privacy

Privacy Policy

This policy describes the data practices implemented in the current Position Intelligence application.

Effective and last updated: September 10, 2026

This is a product policy for Position Intelligence. It is intended to explain the service in practical terms and is not a substitute for advice from a qualified lawyer about the laws that apply to you or the operator.

1 · Data we collect

  • Account data: email address, a normalized copy used for sign-in, optional name, a salted password hash, account and last-seen timestamps, onboarding status, and administrator status. We do not store your plain-text password.
  • Session data: a hashed session-token identifier, account ID, creation and expiry times, and a shortened user-agent string. The un-hashed token exists in an HTTP-only browser cookie.
  • Data you enter: asset, direction, notional exposure, entry price, leverage, liquidation price, time horizon, status, thesis text, structured thesis assumptions, saved items, and notes.
  • Generated product data: matches, scores, explanations, calculated figures, analysis-run results, source provenance, and timestamps associated with your positions.
  • Subscription data: plan, status, PayPal subscription and plan IDs, next billing time when PayPal supplies it, and webhook event identifiers, event types, related subscription IDs, and processing timestamps.
  • First-party product analytics: a closed set of events such as page views, feature use, checkout progress, and purchase completion; the relevant page path; limited event properties; a random anonymous ID; and, when signed in, your internal account ID. The application does not send these events to a third-party analytics platform.
  • Technical data: the application uses a temporary hash derived from IP address and user agent for in-process rate limiting, but does not retain the raw IP in its database. Vercel, network providers, and other infrastructure may independently process request and log data under their own policies.

2 · Cookies

The current application uses:

  • pi_session, a necessary HTTP-only, SameSite=Lax session cookie that expires after 30 days and is marked Secure in production; and
  • pi_anon, a first-party HTTP-only, SameSite=Lax random analytics identifier with a one-year maximum age.

PayPal may set or read its own cookies when its subscription controls are loaded. Blocking necessary cookies may prevent sign-in or checkout from working.

3 · How we use data

We use the data described above to:

  • create and secure accounts, maintain sessions, and enforce plan limits;
  • store positions and produce the filtering, calculations, and explanations you request;
  • start, verify, administer, and cancel PayPal subscriptions;
  • operate, troubleshoot, secure, and improve the service; and
  • understand product use through first-party analytics.

4 · Processors and disclosures

The application is hosted on Vercel and stores application data in a PostgreSQL database hosted by Neon in production. PayPal processes checkout and payment data; Position Intelligence does not receive your card, bank-account, or PayPal credentials. It receives and stores the limited subscription-state information described above.

Server-side requests obtain public market information from CoinGecko and OKX and publisher feeds from CoinDesk, Cointelegraph, and The Block. Those requests contain the market symbols needed to retrieve data, not your account identity.

If the optional Anthropic integration is configured, selected position fields, market facts, calculated figures, and a draft explanation are sent to Anthropic solely to refine the wording of an explanation. The fact sheet can include asset, direction, exposure, leverage, entry price, liquidation price, and time horizon. It does not include your name, email, password, account ID, or thesis text. When the integration is not configured, this processing does not occur.

We may also disclose information where reasonably necessary to comply with law, protect users or the service, investigate abuse, or complete a business transfer. We do not claim to sell personal information, and no sale mechanism exists in the inspected application.

5 · Storage, retention, and deletion

Account, position, generated intelligence, subscription, analytics, and webhook data are stored in the application database. The current code does not impose a single automatic retention period for those records. Data is generally retained while needed to provide, secure, and account for the service, and may be retained longer where reasonably needed for fraud prevention, disputes, backups, or legal obligations.

Session records expire after 30 days; signing out deletes the current session record, and expired session records are removed opportunistically. Deleting a position in the product deletes that position and dependent theses, matches, generated intelligence, and saved references through database relationships.

The current product has no self-service account-deletion control. You may request account deletion through the contact page from the registered email address. Account deletion is handled manually. Some de-identified analytics or payment and operational records may remain where they are not directly attached to the deleted account or must be retained for legitimate operational or legal reasons.

6 · Security

The application uses measures including salted scrypt password hashes, hashed stored session tokens, HTTP-only session cookies, secure cookies in production, restricted account queries, webhook-signature verification, and HTTPS production URLs. No system is completely secure, and this policy does not promise that unauthorized access or loss can never occur.

7 · Your choices

You may choose not to provide optional profile or position fields, delete individual positions in the product, sign out to end the current session, cancel Pro from Subscription settings, or request access, correction, or deletion through the Contact / Support page. Requests may require verification and are subject to applicable law and records we legitimately need to retain.

8 · International processing

Position Intelligence is offered to users internationally. The service providers named above may process data in countries other than the one where you live, whose laws may differ. This policy does not claim a particular international transfer certification or legal framework.

9 · Changes and contact

We may update this policy as the product or its data practices change. The updated version will be posted here with a revised date and, where appropriate, an in-product notice. For privacy questions or requests, use the contact page.