Privacy Policy
Your privacy is important to us. This Privacy Policy explains how FolioFact ("we", "us", "our") collects, uses, and protects your information.
1. Information We Collect
We collect information you provide directly:
- Account information, including your email address and username
- The stocks and funds you follow and the alert preferences you choose
- Messages and feedback you send us
For public research pages, our first-party analytics records limited server-side visit information: the page and referrer, a masked IP address, and browser or device details derived from the user agent. We do not use geolocation, do not store a precise IP address in analytics, and do not use an analytics cookie.
Operational logs contain request identifiers and the minimum technical details needed to secure and run the Service. When the application fails, Sentry receives the error, a request identifier, and, when signed in, a pseudonymous account ID. We configure Sentry not to send default personally identifiable request data.
Stripe processes payment and billing details. We do not receive or store your full card number. Resend processes outgoing email, and Google processes account information only when you choose Google sign-in.
2. How We Use Your Information
- To provide and maintain our Service
- To deliver the alerts, account messages, and billing notices you request
- To improve our Service
- To comply with legal obligations
3. Data Sharing
We do not sell your personal information or use it for advertising. We share only the data needed to operate FolioFact with service providers such as Stripe (billing), Resend (email), Sentry (error reporting), Google (optional sign-in), and our hosting provider. We may also disclose information when required by law.
These providers process data under their own terms and privacy commitments.
4. Your Rights
You can update account preferences in FolioFact and request access, correction, or deletion of your personal data by contacting foliofact@h15n.com.
5. API Keys
If you create API keys for agent access (the MCP server at /mcp or the REST
API at /api/v1/*), we store only:
- A one-way cryptographic fingerprint of the key (never the key itself — it is shown once at creation and cannot be recovered)
- The name you choose, the time it was created, when it was last used, and whether it is revoked
Agent traffic (API and MCP requests) is rate-limited by key or by a hashed IP for anonymous callers. We do not log your request payloads or the content you query.
6. Contact Us
Questions about this policy? Contact foliofact@h15n.com.
Related