Privacy Policy
Last updated: January 15, 2026
1. Introduction
At Invstify, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, Chrome extension, and related services.
We are committed to protecting your personal information and your right to privacy. If you have any questions or concerns about this policy or our practices, please contact us at hello@invstify.com.
Privacy by Design: Your browsing data stays on your device. We don't track which companies you research unless you explicitly request an AI analysis.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address (required for authentication)
- Account preferences and settings
- Subscription and billing information (processed by Stripe)
2.2 Usage Data
When you use our Service, we may collect:
- Companies you've requested AI analyses for
- Watchlist data and saved companies
- Feature usage patterns (aggregated, anonymized)
2.3 Technical Data
We automatically collect certain technical information:
- Browser type and version
- Device type and operating system
- IP address (anonymized after 30 days)
- General geographic location (country/region level)
What We Don't Collect: We do not track your general SEC.gov browsing activity. The extension operates locally on your device, and we only receive data when you explicitly request an AI analysis.
3. How We Use Your Information
We use the information we collect to:
- Provide the Service: Deliver AI analyses, maintain your watchlist, and send filing alerts
- Process Payments: Handle subscription billing through our payment processor
- Improve the Service: Analyze usage patterns to enhance features and fix bugs
- Communicate: Send service updates, security alerts, and support messages
- Ensure Security: Detect and prevent fraud, abuse, and security incidents
We do not sell your personal information to third parties. We do not use your data to build advertising profiles.
4. Data Sharing and Disclosure
We may share your information only in the following circumstances:
4.1 Service Providers
We work with trusted third-party service providers who assist in operating our Service:
| Provider | Purpose | Data Shared |
|---|---|---|
| Stripe | Payment processing | Billing info, email |
| Vercel | Hosting | Technical data |
| AI Provider | Filing analysis | SEC filing data (public) |
4.2 Legal Requirements
We may disclose your information if required by law, court order, or government request, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
4.3 Business Transfers
If Invstify is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.
5. Data Security
We implement appropriate technical and organizational measures to protect your personal information, including:
- Encryption of data in transit (TLS 1.3) and at rest
- Regular security assessments and penetration testing
- Access controls and authentication requirements
- Employee security training and confidentiality agreements
However, no method of transmission over the Internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
6. Your Rights
Depending on your location, you may have the following rights regarding your personal information:
6.1 Access
You can request a copy of the personal information we hold about you.
6.2 Correction
You can request that we correct any inaccurate or incomplete information.
6.3 Deletion
You can request that we delete your personal information. You can delete your account at any time from your Settings page.
6.4 Export
You can request a portable copy of your data in a machine-readable format.
6.5 Opt-Out
You can opt out of marketing communications at any time by clicking the unsubscribe link in our emails or updating your notification preferences.
To exercise any of these rights, please contact us at hello@invstify.com. We will respond to your request within 30 days.
8. Third-Party Services
Our Service may contain links to third-party websites or services, including:
- SEC.gov (U.S. Securities and Exchange Commission)
- Chrome Web Store
- Payment processing pages (Stripe)
We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal information.
9. Children's Privacy
Our Service is not intended for children under 18 years of age. We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
10. International Data Transfers
Your information may be transferred to and processed in countries other than your own. These countries may have different data protection laws. When we transfer data internationally, we ensure appropriate safeguards are in place, including:
- Standard contractual clauses approved by relevant authorities
- Data processing agreements with our service providers
- Compliance with applicable data protection frameworks
11. Data Retention
We retain your personal information for as long as necessary to provide the Service and fulfill the purposes described in this policy. Specifically:
- Account data: Retained until you delete your account
- Analysis history: Retained for 2 years, then anonymized
- Technical logs: Retained for 90 days
- Billing records: Retained for 7 years (legal requirement)
When you delete your account, we will delete or anonymize your personal information within 30 days, except where retention is required by law.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the new policy on this page with an updated date
- Sending you an email notification (for significant changes)
- Displaying a notice within the Service
We encourage you to review this policy periodically. Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.
13. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
- General inquiries: hello@invstify.com
For GDPR-related inquiries, you may also contact your local data protection authority.