Privacy

Privacy Policy.

Effective 22 August 2026

What this site collects, why it collects it, and the things it never collects.

  1. Introduction

    Nemati Capital LLC operates this website. This policy explains what we hold about you, why we hold it, and what happens to it. It covers the public site, the research pages and the investor portal. By using the site you agree to it.

  2. Account data

    If you open an account we store your email address, the name you give us, and your password as an Argon2id hash — never in a form anyone can read back. Multi-factor devices and recovery codes are held against your account so we can verify a sign-in. If you sign in with Google or Apple we receive the identifier that they return and nothing else from them.

  3. Technical data

    Our servers record the IP address, path and time of requests so we can rate-limit abuse and investigate incidents. Sign-in, sign-up and sign-in-link forms are protected by Cloudflare Turnstile: your IP address and a challenge token go to Cloudflare so it can confirm the request is not automated. Cloudflare acts as a processor for that check alone.

  4. Reading and activity

    Comments, saved articles and reactions are stored against your account while you are signed in. Your credit balance and the record of credits bought and spent — which pack, when, and which run each credit paid for — are held against your account too. When you are not signed in, a random key minted in your browser tells one reader from another so that a second click replaces the first instead of counting twice. The server keeps only a hash of that key, it is tied to no account, and clearing your browser storage discards it.

  5. Payments

    When you buy a credit pack, Stripe takes the payment and we never touch the card. The card number, its security code and the billing address you give Stripe do not reach our servers and are not stored by us at any point. What Stripe returns, and all we keep, is the record of the purchase: the amount, which pack, the time, whether it succeeded, and the transaction identifier we would need to trace or refund it. That record is tied to your account because it must be — your credit balance is built from it.

  6. Investor portal

    If you are a client with portal access, we additionally hold:

    • the statements and tax forms we issue you, kept in encrypted object storage
    • your brokerage connection, if you choose to link one — the access and refresh tokens are encrypted at rest and used only to read your own account
    • the account identifier your broker returns when you connect
  7. Enquiries and updates

    The contact and update forms store the email address you enter, your name and message where you give them, which form they came from, and the language you were reading in so we can reply in it. Every email we send carries an unsubscribe link, and unsubscribing stops future sends.

  8. What we do not collect

    Some of this policy is about what is absent, and that is deliberate:

    • no analytics, tracking pixels, advertising networks or third-party profiling — this site runs none of them
    • no card data — Stripe takes the card when you buy credits, and neither the number, the security code nor the billing address ever reaches us
    • no identity attached to a free research request: the queue records a ticker and a count, never a user, an IP address or a session, so there is nothing in it to erase later — a Pro run is necessarily tied to the account that paid for it
    • we never sell personal data, and we never let anyone train a model on it
  9. Research runs

    Free research runs are published to everyone: a signed-out reader sees exactly what a signed-in one sees for the same ticker, and there is no per-reader version of a published run. A Pro run is the opposite — it belongs to the account that generated it, no other reader can reach it, and it is not published unless you create a share link for it yourself. Either way, what we send to the model that writes an analysis is the ticker, its market data, the parameters chosen for the run and the run's own earlier steps — never your identity, your account, or anything from your portal.

  10. Who else handles your data

    Each of these acts on our instructions, for the one purpose named, and for nothing else:

    • Cloudflare — bot challenge and protection at the network edge
    • Anthropic — the model that writes research analysis; its prompts carry no personal data
    • Brevo — delivery of the email you asked us for
    • Cloudflare R2 — encrypted storage of documents we issue you
    • Google and Apple — only if you choose their sign-in
    • Interactive Brokers — only if you choose to connect your account
    • Stripe — card payment for credit packs, and only if you buy one; your card details go to Stripe and never to us
  11. How long we keep it, and how to have it deleted

    We keep account data for as long as the account is open. Write to [email protected] and we will delete the account and everything attached to it — documents, broker connection, comments, saved articles and the Pro reports you generated — from live systems; encrypted backups age out within 14 days. You need not wait for us: you may delete a report yourself, and revoking a share link stops it working at once, though neither can recall a copy someone has already taken. Unused credits are forfeited when an account is deleted. Request logs are kept briefly, for security only. Records we must keep by law — the record of a credit purchase, for tax and accounting, among them — are kept for as long as the law requires and for nothing else.

  12. International transfers

    We are based in the United States and our infrastructure runs there. If you use the site from anywhere else, your data is transferred to and stored in the United States, which may not give it the same protection your own country does.

  13. Your rights

    You may ask us to show you the personal data we hold about you, correct it, export it, or delete it, and you may object to how we process it. Write to [email protected] — we may need to confirm who you are first. These rights are the law in the EU, the EEA, the UK and California; we honour them for everyone who asks, wherever they live.

  14. Cookies and browser storage

    One cookie is essential: the session cookie that keeps you signed in, which is HTTP-only and cannot be read by scripts. Everything else stays in your own browser and never reaches us — your light or dark preference, a dismissed install prompt, the market list you last opened, your saved articles, and the anonymous reading key described above. We set no advertising or tracking cookies at all.

  15. Security

    Passwords are hashed with Argon2id. Broker tokens are encrypted where they rest. Multi-factor authentication is available on every account, sessions can be revoked, and traffic runs over TLS. No system is perfectly secure, and if a breach ever affects your data we will tell you.

  16. Children

    This site is for adults. It is not directed at anyone under 18, and we do not knowingly collect data about them. If we learn that we have, we delete it.

  17. Changes to this policy

    We will post any change on this page and move the effective date at the top. If a change materially affects you, we will email account holders rather than rely on you noticing.

  18. Contact

    Questions about this policy, or a request about your data: [email protected].