Privacy Policy
Last updated: September 26, 2026
This policy explains what information Stockinsky collects, how we use it, which providers help operate the service, and the choices available to you.
Information we collect
When you create an account, we collect your email address and a hashed password. We do not store or have access to your password in plain text.
If you choose to sign in with Google or GitHub, we receive your account's unique identifier and verified email address from that provider and use them only to identify and sign you in. We never receive your password for that provider, read your other data there, or post anything on your behalf.
When you buy or use paid features, we record credit-balance changes and purchase records linked to Creem order identifiers. Creem processes full card and payment-account details directly; we do not receive them.
We also keep ordinary server logs such as IP address, request time and User-Agent for troubleshooting, security and abuse prevention, not for advertising profiles.
We record website usage behaviour (which pages you view, which buttons or links you click), described under “Cookies and local storage” and “Website analytics and behaviour data” below.
Cookies and local storage
We use cookies and browser local storage to keep you signed in, distinguish traffic sources, and run website analytics.
Essential cookie: one cookie that keeps your login session; sign-in cannot persist without it.
Analytics cookies: a cookie named sky_anon holding a randomly generated anonymous identifier that groups visits from the same browser while you are signed out, plus cookies set by Google Analytics.
You can clear these cookies or block non-essential cookies at any time; this does not affect viewing reports or core features but may affect staying signed in. If your browser sends a Do Not Track or Global Privacy Control (GPC) signal, our behaviour-analytics script skips recording automatically.
Website analytics and behaviour data
To understand how the site is used, improve pages and interactions, diagnose problems and prevent abuse, we record page views and interaction events: which pages you visit, which buttons or links you click, when it happened, the referring page, and an approximate grouping by browser session.
These records are linked to the anonymous identifier above (sky_anon) and to an irreversibly hashed digest of your IP address (we do not store your raw IP for this purpose). If you are signed in, this activity is linked to your account email; to reconstruct the full usage path, anonymous activity from the same browser before you signed in is also linked to your account after sign-in.
We use this data only for product analytics and security. We do not sell it, use it for ad targeting, or use it to train AI models. Behaviour data is retained for at most 90 days and then deleted automatically.
We also record where each browser came from on its first visit (the referring site and page, the landing page, and campaign parameters in the link such as utm_source, or whether an ad click identifier was present) so we can understand which channels people find us through. When you create an account, this first-visit source is saved with your account and kept for as long as the account exists; for visitors without an account it is retained for at most 90 days, like other behaviour data.
We also use Google Analytics (provided by Google LLC) for aggregate traffic and source statistics, and to count a few key actions: generating a report, using a valuation, submitting a Why or If–Then analysis and completing a purchase (the purchase event carries the order ID, credit-pack type and amount, never your email or account identifier). Google processes that data under its own privacy policy.
How we use information
We use this information to authenticate accounts, maintain credit balances, generate requested stock research, answer support requests, keep the service reliable and secure, and analyse site usage in aggregate or anonymised form to improve the product.
We do not sell personal information, use it for unrelated purposes, or use account information to train AI models.
Payments and third-party services
Creem acts as Merchant of Record and processes billing details, payment methods and applicable tax information under its own privacy and compliance obligations.
We use an email provider for account verification and may use Anthropic, OpenAI, DeepSeek or similar AI providers to generate research. Stock identifiers may be sent to those providers, but not your account identity. When you use If–Then, the clue text you submit, any link you paste and the body text we read from that publicly accessible page are also sent to those providers for analysis. We only read publicly accessible pages and never sign in to any site on your behalf.
Data sharing
We share information only with service providers needed to operate Stockinsky, when legally required, or to protect users and the security and integrity of the service.
Retention and security
We retain account, purchase and usage records only as reasonably needed to provide the service, resolve disputes, and meet tax and legal obligations. Website analytics and behaviour data are retained for at most 90 days and then deleted automatically. You may ask us to delete your account and associated personal data; public reports contain no personal account data.
We use reasonable safeguards including password hashing and HTTPS, but no storage or transmission method can guarantee absolute security.
Your rights and choices
Depending on applicable law, you may request access, correction or deletion of personal information, or ask us to delete the behaviour records linked to your account. Contact pcyan@happycodes.net from the email address linked to your account.
You can also block or clear cookies in your browser, or enable a Do Not Track / Global Privacy Control signal, to reduce what website analytics records.
Policy updates
We may update this policy from time to time. Material changes will be reflected in the “Last updated” date above.