← Depth Desk

Privacy Policy

Last updated: 2026-07-22

1. Data controller

Andreas Hillström (private individual, Sweden), depthdesk.dev@gmail.com. Contact us with any privacy question or GDPR request.

2. What we collect

  • Account: email address and hashed password (via Supabase Auth).
  • App state: your favorite tickers, notification preferences, saved alerts, redeemed invite codes.
  • Subscription: tier, Stripe customer/subscription IDs. Card details never touch our servers — they're handled by Stripe.
  • Technical: minimal server logs (IP, timestamp, endpoint) kept for security and debugging, typically 30 days.

We do not use tracking cookies, advertising cookies, or third-party analytics. The only cookies set are the functional session cookie required to keep you signed in.

3. Why we process it (legal basis)

  • Contract — to provide the Service (account, favorites, alerts, subscription).
  • Legal obligation — Stripe transaction records for accounting.
  • Legitimate interest — securing the platform, preventing abuse.

4. Sub-processors

  • Supabase — database, authentication, storage (EU region).
  • Cloudflare / Lovable — hosting and edge delivery.
  • Stripe — payments and VAT handling (Merchant of Record).
  • Google Gemini — AI text generation. Only the ticker and public market context are sent; no personal data.

5. International transfers

Some sub-processors (Stripe, Google) may transfer data outside the EU under Standard Contractual Clauses.

6. Retention

Account data is kept while your account is active. On deletion, personal data is removed within 30 days except where retention is required by law (e.g. Stripe invoices, 7 years).

7. Your rights (GDPR)

You have the right to access, correct, delete, export, and restrict processing of your data, and to object to processing based on legitimate interest. Email us and we'll respond within 30 days. You may also lodge a complaint with the Swedish Authority for Privacy Protection (IMY).

8. Security

Data is encrypted in transit (HTTPS) and at rest. Row-Level Security ensures you can only access your own data. Secrets and API keys are stored server-side only.

9. Cookies

Only strictly necessary cookies are used (session/auth). No consent banner is required for these under the ePrivacy Directive. No analytics, no ads, no tracking.

10. Changes

Material changes will be announced in the app or by email.