Legal

Privacy policy

What we collect, why we need it, who helps us process it, and how to get a copy or have it deleted. The short version: we collect what the product needs to work, we don’t sell it, and we don’t run ads or third-party trackers.

Last updated September 29, 2026Applies to investingly.io

Who we are

Investingly is an investment research service run by Stone Mountain Research (“we”, “us”). This policy covers the website at investingly.io and the Investingly app you use once signed in.

What we collect

WhatDetails
AccountEmail address; your password, stored only as a one-way hash; your Google account ID if you sign in with Google.
Profile (optional)Display name, profile photo, and — if you share a portfolio — a public handle, bio and website link.
What you createWatchlists, notes, price and buy targets, saved screens, paper portfolios and their trades, portfolios you follow, and your settings.
Broker connections (optional)If you connect Interactive Brokers, the Flex query ID and token you give us (stored encrypted) and the positions and account values it returns. If you import a file, its holdings.
AI Research (optional)Your own Anthropic API key (stored encrypted), your conversations, and a record of estimated spend so we can enforce the monthly cap you set.
SupportMessages and screenshots you send us, the page you wrote from, and your browser’s user-agent string. Screenshots are re-encoded when uploaded, which removes location and camera data from the file.
BillingYour plan, trial and renewal dates, and our payment processor’s customer ID for you. We never see or store your card number.
UsageWhich pages you open and what you click, your device, browser and approximate location (country or city, from your IP address), how you arrived (for example, the referring site), and recordings of page sessions with everything you type hidden. When you’re signed in this is linked to your account.
TechnicalStandard server logs (IP address, time, page requested) kept by our hosting provider for security and troubleshooting.

How we use it

We don’t sell personal information, we don’t share it for advertising, and we don’t use it to train AI models.

What other people can see

Most of what you create is private to you. The exceptions are things you choose to share:

Who processes it

We use a small number of service providers, each only for the job listed:

ProviderWhat for
RailwayHosting the app and its database
Google DriveStoring database backups
StripePayments, invoices and the billing portal
ResendSending email
PostHogProduct analytics: page views, clicks and session recordings (with typed text hidden)
GoogleSign-in, if you choose “Continue with Google”
AnthropicAI Research answers — only if you add your own API key; your questions and the data the AI looks up are sent under your key
Interactive BrokersImporting your statements — only if you connect an account

Market data providers supply prices and company data; we don’t send them anything about you. Some of these providers store data outside Canada, including in the United States.

Cookies & local storage

We use cookies only to keep you signed in (a session cookie, and a 30-day “remember me” cookie if you tick that box) and to protect forms from cross-site request forgery. Your browser’s local storage remembers display choices such as theme, sidebar state and table columns. We use PostHog for product analytics, which stores an anonymous visitor ID in a cookie and local storage so repeat visits count as one visitor. If your browser sends a “Do Not Track” signal, analytics records nothing. There are no advertising or cross-site tracking cookies.

If you visit from the EU, the European Economic Area, the UK, Switzerland or Quebec, we ask first. Until you accept, analytics runs without cookies or local storage: visits are counted anonymously and there are no session recordings. If you decline, it stays that way. Your choice is saved in your browser, and you can change it at any time.

How long we keep it

Your choices & rights

Security

Connections are encrypted (HTTPS), passwords are hashed, API keys and broker tokens are encrypted at rest, and cookies are marked secure and HTTP-only. No system is perfectly secure; if a breach affects your information we will tell you and the regulator as the law requires.

Changes & contact

If we change this policy in a way that matters, we’ll update the date above and tell signed-in users before it takes effect.

Questions or requests about your data: contact us and choose “Privacy or data request”. We reply within 30 days, usually much sooner.