Privacy Policy
01Who we are
The controller responsible for your personal data is the operator identified above. This policy applies to the Long/Short Terminal website and application (the "Service"). It should be read together with our Terms of Service.
02Data we collect
- Account data. When you register we process your email address, name (if provided), and authentication identifiers through our identity provider (Clerk).
- Subscription & billing data. When you subscribe, our payment provider (Stripe) processes your payment details. We do not receive or store your full card number; we receive your subscription status and limited billing metadata.
- Research content you create. Content you generate in the Service - such as watchlists, portfolio entries, conviction tags, notes, and idea inputs - is stored and associated with your account so it is available across your devices.
- Usage & device data. Technical data such as IP address, browser and device type, pages viewed, and timestamps, processed to operate and secure the Service.
- Aggregate analytics. We use Cloudflare Web Analytics, which is privacy-focused and does not use cookies or fingerprinting to track you across sites.
- Product usage metrics. To understand which parts of the Service are useful and to plan improvements, we record first-party, aggregated engagement counts associated with your account - how many times you open each section of the Service and on which calendar days. We do not record your IP address, time spent on a page, or a detailed per-page browsing trail for this purpose.
- Communications. If you contact us or submit feedback, we process the content of your message and your contact details to respond.
We do not knowingly collect special categories of data, and we do not sell your personal data.
03Why we use it & legal bases
- To provide the Service (accounts, features, storing your research content) - to perform our contract with you.
- To process payments and manage subscriptions - to perform our contract and to comply with legal (e.g. accounting) obligations.
- To secure, maintain, and improve the Service and prevent abuse - based on our legitimate interests in a reliable, safe product.
- To communicate with you about service, security, and account matters - contract and legitimate interest; marketing emails only where permitted or with your consent.
- To comply with legal obligations where applicable.
Under the GDPR the corresponding bases are Art. 6(1)(b) contract, Art. 6(1)(c) legal obligation, Art. 6(1)(f) legitimate interests, and Art. 6(1)(a) consent where relied upon.
04Cookies & local storage
We use strictly necessary cookies and browser storage to keep you signed in (session cookies set by our identity provider) and to remember your interface preferences (such as filters and view settings). These are essential to the Service. Our analytics provider does not set tracking cookies. You can clear cookies and local storage in your browser, but the Service may not function correctly without the essential ones.
05Service providers (subprocessors)
We share personal data with the following providers strictly to operate the Service. They act as our processors under appropriate data-processing agreements.
| Provider | Purpose | Location |
|---|---|---|
| Clerk | Authentication and account management (email, name, session). | United States |
| Cloudflare | Hosting, edge compute, database and object storage, and privacy-focused web analytics. | Global / United States |
| Stripe | Subscription billing and payment processing. | United States / EU |
| AI / LLM providers | Generating summaries and AI-assisted research outputs; if you submit content to AI-assisted features, that content may be processed to produce a response. | United States |
06International transfers
Some of our providers are located outside Switzerland and the EU/EEA, including in the United States. Where personal data is transferred to a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the Swiss addendum recognized by the Swiss Federal Data Protection and Information Commissioner), or equivalent mechanisms.
07Retention
We keep personal data for as long as your account is active and as needed to provide the Service. After you close your account we delete or anonymize your data within a reasonable period, except where we must retain it to comply with legal obligations (for example, billing and accounting records), resolve disputes, or enforce our agreements.
08Your rights
Subject to applicable law, you have the right to access your personal data and to request its correction, deletion, or restriction; to object to certain processing; to data portability; and, where processing is based on consent, to withdraw that consent at any time. To exercise these rights, contact us at jannik@wirtz.ai. You also have the right to lodge a complaint with a supervisory authority - in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC); in the EU/EEA, your local data protection authority.
09Security
We take appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or misuse, including encryption in transit, access controls, and reliance on reputable infrastructure providers. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10Children
The Service is intended for users aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
11Changes to this policy
We may update this policy from time to time. We will post the updated version here with a new "last updated" date and, for material changes, provide additional notice where required.
12Contact
For any privacy question or request, contact jannik@wirtz.ai.