Privacy Policy

Last updated: 2026-08-02

1. Data controller

The controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws is:

Stefan Wensauer Eichweg 27a, 87666 Pforzen, Germany

Email: support@stonksask.me

We have not appointed a data protection officer, as the statutory requirements for this are not met.

2. Scope & definitions

This Privacy Policy informs you about the nature, scope, and purpose of the processing of personal data when using Stonks Ask Terminal. and the associated website and app.

“Personal data” means any information relating to an identified or identifiable natural person. “Processing” means any operation involving personal data (e.g., collection, storage, use, transfer, deletion). The terms used are based on Art. 4 GDPR.

3. Overview of processing

Account & authentication — Email address, session tokens — Contract performance (Art. 6 (1) (b) GDPR) — Until account deletion

Chat sessions — Conversation content, titles — Contract performance — Until account deletion

Model training / fine-tuning (optional) — Chat content (pseudonymized/anonymized) — Consent (Art. 6 (1) (a) GDPR) — Until withdrawal / account deletion; anonymized training datasets and model weights already produced cannot be fully reversed

User memories — AI-extracted preferences (optional) — Consent / contract (Art. 6 (1) (a)/(b) GDPR) — Until deletion or disabled

Settings — Instructions, locale, currency, reasoning mode — Contract performance — Until account deletion

Watchlist & portfolio — Tickers, notes, holdings, Parqet sync metadata — Contract performance — Until account deletion

Payments & subscription — Subscription status, customer/transaction IDs from the payment provider — Contract / legal obligation (Art. 6 (1) (b)/(c) GDPR) — Per statutory retention periods

Usage tracking — Query counts for billing limits — Legitimate interest / contract (Art. 6 (1) (b)/(f) GDPR) — Billing period + retention

Server logs — IP address, timestamps (hosting) — Legitimate interest (Art. 6 (1) (f) GDPR) — Per provider retention

Newsletter / product updates (optional) — Email address from website signup — Consent (Art. 6 (1) (a) GDPR) — Until withdrawal or deletion

4. Legal bases for processing

We process personal data on the following legal bases: consent (Art. 6 (1) (a) GDPR), performance of a contract or pre-contractual measures (Art. 6 (1) (b) GDPR), compliance with legal obligations (Art. 6 (1) (c) GDPR), and protection of legitimate interests (Art. 6 (1) (f) GDPR).

Where we base processing on a legitimate interest, this interest lies in particular in the secure, stable, and economical provision of the Service, protection against misuse, and the improvement of our offering. You may withdraw any consent at any time with effect for the future.

5. Hosting (Vercel)

The application is hosted by Vercel Inc. (340 S Lemon Ave #4133, Walnut, CA 91789, USA). When you access the application, Vercel processes technically necessary data (e.g., IP address, time of access, requested resource, browser/device information) in server log files to ensure the delivery, security, and stability of the Service.

The legal basis is our legitimate interest in a secure and efficient operation (Art. 6 (1) (f) GDPR) and contract performance (Art. 6 (1) (b) GDPR). Vercel processes the data as a processor on the basis of a data processing agreement. For international transfers, see Section 21.

6. Database & authentication platform (Supabase)

For data storage and authentication, we use Supabase (Supabase, Inc., 970 Toa Payoh North #07-04, Singapore; with infrastructure in the regions configured for our project). Account, chat, settings, watchlist/portfolio, and usage data are stored in Supabase.

The legal basis is contract performance (Art. 6 (1) (b) GDPR). Supabase processes the data as a processor on the basis of a data processing agreement.

7. Registration & sign-in

Registration is required to use the protected area. We process your email address and the associated authentication data via Supabase Auth. You can sign in with email and password, a magic link, Sign in with Apple, or Sign in with Google. When using Apple, we receive your Apple user ID and email address (or Apple's private relay address if you hide your email). When using Google, we receive your Google user ID, email address, and name if you grant access. To maintain your login state, technically necessary session cookies or tokens are set.

Legal basis: Art. 6 (1) (b) GDPR (establishment and performance of the user contract).

8. Terminal chat & sessions

Your chat messages and session titles are stored to provide chat history, conversation continuity, and the associated features. Automatic classification of conversations (e.g., by ticker or phase) serves to organize your history.

Legal basis: Art. 6 (1) (b) GDPR. You can delete individual conversations at any time.

Use of chat content for training or fine-tuning our own models is not covered by this contractual basis and takes place only with your separate consent (see Section 9).

9. Model training & fine-tuning (optional)

With your express consent, we may use chat content from your sessions to train or fine-tune our own language models and thereby improve the Service. Without consent, no such training with your chat data takes place.

Before use for training purposes, data is pseudonymized or anonymized where possible (e.g., removal of direct identifiers). We do not sell raw chat transcripts to third parties for their own model training.

You may withdraw your consent at any time with effect for the future (e.g., in settings once the control is available there, or by contacting support@stonksask.me). Withdrawal or account deletion applies to future exports and training runs. Anonymized or pseudonymized training datasets already produced, and model weights derived from them, cannot be fully reversed or "forgotten" as a technical matter.

Legal basis: Art. 6 (1) (a) GDPR (consent).

10. User memories

If the memory feature is enabled, we store AI-extracted preference snippets linked to your account in order to personalize responses. This feature is optional.

The legal basis is your consent or contract performance (Art. 6 (1) (a) or (b) GDPR). You can disable and delete memories at any time in settings.

11. Settings

Settings you make (e.g., custom instructions, language, currency, reasoning mode) are stored to provide the app according to your preferences.

Legal basis: Art. 6 (1) (b) GDPR.

12. Watchlist & portfolio

Symbols, notes, and portfolio positions you enter are stored to provide context-aware analysis in the terminal.

Legal basis: Art. 6 (1) (b) GDPR. This data is only associated with your account and is not used for advertising purposes.

13. Portfolio integration (Parqet)

If you connect the optional Parqet integration, we sync holdings metadata (e.g., ticker, quantity, entry price, purchase date) from your Parqet account at your request. The connection is established via an authorized procedure; we do not store your Parqet credentials on our servers.

Legal basis: Art. 6 (1) (b) GDPR. The respective provider is independently responsible for the processing within your Parqet account.

14. AI processing (OpenRouter & model providers)

To generate responses, chat requests are routed via OpenRouter (OpenRouter, Inc.) to large language model providers. Message content and the context relevant to the response (e.g., watchlist, portfolio, memories) may be transmitted. Please do not enter any particularly sensitive or confidential personal data in the chat.

No automated decision-making with legal effect within the meaning of Art. 22 GDPR takes place (see Section 23).

Legal basis: Art. 6 (1) (b) GDPR. For international transfers, see Section 21.

15. Market data & logos

Market data (quotes, fundamentals, news) is fetched from Financial Modeling Prep (FMP) based on the ticker symbols you query. These requests do not include personal identifiers beyond what is technically necessary for API access.

Stock logos may be loaded via Logo.dev. In this case, your IP address may be transmitted to the respective provider for technical reasons.

Legal basis: Art. 6 (1) (b) and (f) GDPR (provision of the requested content).

16. Payment processing (Stripe)

To process paid plans, we use the payment service provider Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin, Ireland). For a purchase, the data required for payment (e.g., payment method information) is collected and processed directly by Stripe; full payment data (e.g., card numbers) is not stored on our servers. We receive information from Stripe about the payment and subscription status as well as associated customer and transaction IDs.

The legal basis is contract performance (Art. 6 (1) (b) GDPR) and compliance with legal (in particular commercial and tax) obligations (Art. 6 (1) (c) GDPR). With regard to the payment data it collects independently, Stripe is in part a controller in its own right. Stripe's privacy policy applies additionally.

17. Emails & newsletter

As part of authentication and account management, we send necessary transactional emails (e.g., to confirm registration or to reset a password). For this purpose, your email address is processed via the email infrastructure of our authentication provider.

If you subscribe to product updates via a form on our website (e.g., the Gotham announcement page), we store your email address in our database in order to contact you about product news and related updates. Legal basis: Art. 6 (1) (a) GDPR (consent). You may withdraw your consent at any time with effect for the future by contacting support@stonksask.me; we will then delete or stop using your address for this purpose.

Sending of newsletters may later be handled via an external newsletter service (processor). Until such a service is connected, we only store the address and do not automatically send marketing emails.

We only send promotional emails with your consent or within the legally permitted framework. Account newsletter preferences (in settings) are separate from public website signups.

18. Cookies & local storage

We use exclusively technically necessary cookies or tokens, in particular for authentication and maintaining your session. These are required for the operation of the Service; their use is based on § 25 (2) of the German Telecommunications Digital Services Data Protection Act (TDDDG) and Art. 6 (1) (b)/(f) GDPR.

We do not currently use marketing or analytics cookies. In addition, your browser may store settings (e.g., language) and application-related state in local storage to provide functionality.

19. Server log files

When you access the Service, our hosting provider automatically collects information in server log files (e.g., IP address, date and time, requested resource, status code, referrer, browser/operating system type).

This processing is necessary for delivery, ensuring system security, and error analysis. The legal basis is our legitimate interest (Art. 6 (1) (f) GDPR). The data is deleted in accordance with the provider's retention rules.

20. Retention period

We process and store personal data only for as long as is necessary for the respective purposes. We generally store account, chat, settings, watchlist, and portfolio data until the account or the respective content is deleted.

Where you have consented to optional model training, we may store pseudonymized or anonymized dataset snapshots created for training for the duration of the relevant training and evaluation cycles. Withdrawal of consent stops inclusion in future exports; snapshots already produced and model weights derived from them may continue to exist where they no longer contain personal data or cannot be technically unwound (see Section 9).

Once the purpose no longer applies, data is deleted unless statutory retention obligations apply. In particular, statutory retention periods apply to billing- and tax-relevant documents (typically 6 or 10 years under the German Commercial Code/HGB and Fiscal Code/AO); for the duration of these periods, processing is restricted.

21. Transfers to third countries

Some of the service providers used (e.g., Vercel, OpenRouter, and possibly other model or infrastructure providers) may process personal data in countries outside the EU/EEA, in particular in the USA.

Where a transfer to a third country takes place, we ensure appropriate safeguards under Art. 44 et seq. GDPR, in particular by concluding the EU Standard Contractual Clauses (Art. 46 (2) (c) GDPR) and supplementary protective measures or—where the provider is certified—on the basis of the EU-US Data Privacy Framework (adequacy decision). You can obtain further information on request at support@stonksask.me.

22. Processors & recipients

To provide the Service, we use carefully selected service providers that process data on our behalf and according to our instructions (processing under Art. 28 GDPR). These include in particular: Vercel (hosting), Supabase (database/authentication), Stripe (payment processing), OpenRouter and downstream model providers (AI processing), Financial Modeling Prep (market data), and Logo.dev (logos).

Where required, data processing agreements exist with these providers. Data is only shared with other third parties where this is legally permitted, you have consented, or it is necessary for the performance of the contract.

23. Automated decision-making & profiling

There is no decision based solely on automated processing—including profiling—that produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR).

AI-generated content serves exclusively for information and analysis purposes and does not constitute a binding decision or investment advice.

24. Minors

The Service is not directed at minors. Persons under the age of 18 should not transmit any personal data to us without the consent of their legal guardians.

If we become aware that personal data of a minor has been processed without the required consent, we will delete it without undue delay.

25. Data security

We take appropriate technical and organizational measures in accordance with Art. 32 GDPR to protect your data against loss, misuse, and unauthorized access, in particular through transport encryption (TLS), access controls, and the selection of security-vetted service providers.

Our security measures are continuously reviewed and adapted in line with technological developments.

26. Your rights

Under the GDPR, you have the following rights: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection to processing (Art. 21). You may withdraw any consent given at any time with effect for the future (Art. 7 (3)).

Right to object: Where we process data on the basis of legitimate interests (Art. 6 (1) (f) GDPR), you have the right to object at any time on grounds relating to your particular situation.

To exercise your rights, a message to support@stonksask.me is sufficient.

27. Right to lodge a complaint with a supervisory authority

Without prejudice to any other legal remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence, place of work, or the place of the alleged infringement.

The supervisory authority responsible for us is: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany, https://www.lda.bayern.de.

28. Changes to this policy

We may adapt this Privacy Policy if our services, the providers used, or the legal requirements change. The version available at the time of use applies in each case.

The date at the top of this policy indicates the current status.

29. Contact

If you have any questions about data protection or wish to exercise your rights, you can reach us at:

Stefan Wensauer Eichweg 27a, 87666 Pforzen, Germany

Email: support@stonksask.me