Who we are
Investingly is an investment research service run by Stone Mountain Research (“we”, “us”). This policy covers the website at investingly.io and the Investingly app you use once signed in.
What we collect
| What | Details |
|---|---|
| Account | Email address; your password, stored only as a one-way hash; your Google account ID if you sign in with Google. |
| Profile (optional) | Display name, profile photo, and — if you share a portfolio — a public handle, bio and website link. |
| What you create | Watchlists, notes, price and buy targets, saved screens, paper portfolios and their trades, portfolios you follow, and your settings. |
| Broker connections (optional) | If you connect Interactive Brokers, the Flex query ID and token you give us (stored encrypted) and the positions and account values it returns. If you import a file, its holdings. |
| AI Research (optional) | Your own Anthropic API key (stored encrypted), your conversations, and a record of estimated spend so we can enforce the monthly cap you set. |
| Support | Messages and screenshots you send us, the page you wrote from, and your browser’s user-agent string. Screenshots are re-encoded when uploaded, which removes location and camera data from the file. |
| Billing | Your plan, trial and renewal dates, and our payment processor’s customer ID for you. We never see or store your card number. |
| Usage | Which pages you open and what you click, your device, browser and approximate location (country or city, from your IP address), how you arrived (for example, the referring site), and recordings of page sessions with everything you type hidden. When you’re signed in this is linked to your account. |
| Technical | Standard server logs (IP address, time, page requested) kept by our hosting provider for security and troubleshooting. |
How we use it
- To run your account and the features you use — show your watchlists, value your portfolios, send the alerts you switch on.
- To send the emails you asked for: buy-target alerts, trades in portfolios you follow, and support replies. You can switch each off in Settings → Notifications. Account emails (password resets, receipts) are always sent.
- To answer support requests and fix what’s broken.
- To bill you and prevent abuse (for example, rate limits on sign-in).
- To understand how Investingly is used — which features people find, where they get stuck — so we can improve it.
We don’t sell personal information, we don’t share it for advertising, and we don’t use it to train AI models.
What other people can see
Most of what you create is private to you. The exceptions are things you choose to share:
- Public portfolios — their holdings, trades and performance, plus your display name, handle, photo, bio and website — can be seen by anyone, and appear in Discover.
- Link-only portfolios can be seen by anyone who has the link.
- People who follow your portfolio don’t see your email address, and you don’t see theirs.
Who processes it
We use a small number of service providers, each only for the job listed:
| Provider | What for |
|---|---|
| Railway | Hosting the app and its database |
| Google Drive | Storing database backups |
| Stripe | Payments, invoices and the billing portal |
| Resend | Sending email |
| PostHog | Product analytics: page views, clicks and session recordings (with typed text hidden) |
| Sign-in, if you choose “Continue with Google” | |
| Anthropic | AI Research answers — only if you add your own API key; your questions and the data the AI looks up are sent under your key |
| Interactive Brokers | Importing your statements — only if you connect an account |
Market data providers supply prices and company data; we don’t send them anything about you. Some of these providers store data outside Canada, including in the United States.
Cookies & local storage
We use cookies only to keep you signed in (a session cookie, and a 30-day “remember me” cookie if you tick that box) and to protect forms from cross-site request forgery. Your browser’s local storage remembers display choices such as theme, sidebar state and table columns. We use PostHog for product analytics, which stores an anonymous visitor ID in a cookie and local storage so repeat visits count as one visitor. If your browser sends a “Do Not Track” signal, analytics records nothing. There are no advertising or cross-site tracking cookies.
If you visit from the EU, the European Economic Area, the UK, Switzerland or Quebec, we ask first. Until you accept, analytics runs without cookies or local storage: visits are counted anonymously and there are no session recordings. If you decline, it stays that way. Your choice is saved in your browser, and you can change it at any time.
How long we keep it
- Your account data is kept while your account is open.
- When you ask us to delete your account, we delete it and everything tied to it within 30 days.
- Database backups are kept on a rolling basis and overwritten after about four weeks, so deleted data leaves them within that time.
- We keep billing records as long as tax law requires.
Your choices & rights
- Get a copy — Settings → Your data → “Download my data” gives you everything you’ve created as a JSON file.
- Correct it — edit your profile and settings any time, or ask us to fix something you can’t change yourself (such as your email address).
- Delete it — Settings → Your data → “Request deletion”, or write to us.
- Emails — switch optional emails off in Settings → Notifications.
- Ask or complain — contact us first; you can also complain to the privacy regulator where you live (in Canada, the Office of the Privacy Commissioner).
Security
Connections are encrypted (HTTPS), passwords are hashed, API keys and broker tokens are encrypted at rest, and cookies are marked secure and HTTP-only. No system is perfectly secure; if a breach affects your information we will tell you and the regulator as the law requires.
Changes & contact
If we change this policy in a way that matters, we’ll update the date above and tell signed-in users before it takes effect.
Questions or requests about your data: contact us and choose “Privacy or data request”. We reply within 30 days, usually much sooner.