STOCKATLASS · TRUST & TRANSPARENCY
Privacy notice
Draft for operator review · Describes this build
Prepared 8 October 2026 · Not yet effective
1. Browser preferences
Language settings and guest watchlists are stored in this browser's localStorage. Signed-in watchlists are stored in the Stockatlass server's SQLite database under an account identifier so the same account can use them across devices. Where server storage is unavailable, the interface identifies device-local saving. Guest and account watchlists are separate; signing in does not automatically copy a guest list to an account.
2. Chat and consent
Chat history is held in application memory for the current session; this build has no persistent chat database. If the AI connection is configured and you explicitly consent before sending, your message and relevant research context are sent through the server to OpenAI to generate a response. Do not include passwords, financial account details, or sensitive personal information.
Stopping use prevents further messages being sent. Clearing the session does not erase information already received by an external provider; its applicable processing and retention terms must also be considered.
3. Market requests and external links
When a market-data connection is enabled, requested symbols, exchanges, and related query parameters may be sent to the configured provider. Following a Google Finance, exchange, issuer, or news link takes you to a separate service governed by its own notice.
Loading a TradingView widget connects your browser directly to TradingView for its resources and displayed data. TradingView's widget FAQ identifies the embedding page URL, widget type, displayed symbol and IP address as information processed for widget operation. Stockatlass does not include your account email, password or session identifier in the widget configuration. A selected security is shared as the displayed symbol; the provider's privacy notice applies to its processing.
TradingView states that its widgets do not set cookies. This statement concerns the widget offering; Stockatlass separately uses the sign-in session cookie described below. Widget display data is not imported into a Stockatlass price cache or chat history, and widget access does not authorize downloading or exporting its underlying data.
4. Accounts, sessions and server records
Stock research pages can be viewed without signing in. Registration collects an email address, password and display name. The server stores an account identifier, email, display name, access status, creation and last-seen timestamps, and saved watchlists in SQLite. Passwords are stored as salted scrypt hashes, not as recoverable plaintext passwords. Providing an email address does not verify ownership of its mailbox; an automated verification or password-reset email service is not configured in this build.
Signing in creates an opaque session identifier in a browser cookie. The server stores a hash of that identifier and session records to recognize account access and expiry. Signing out revokes the current session and clears the app's chat and account view; saved server records remain until removed through the service. Stockatlass accounts are separate from ChatGPT and brokerage accounts.
The configured owner can manage Stockatlass account access and saved watchlists, and edit public content, company information, source links, dated news, deals and policies. Saved content revisions record the editor's account identifier and edit time for accountability. Administrative records and account information are not exposed through public content endpoints. Ownership is explicitly configured; registering first does not grant administration rights.
The service runs on an operator-managed VPS. The server and hosting provider may process network addresses, request metadata and security logs. The operator is responsible for server access controls, backups, security updates, retention and incident response, and must identify the hosting provider, recipients and retention periods in the deployed notice. Saved database records and backups require appropriate access protection; this draft does not promise that all processing remains in your browser.
5. Deletion and your choices
Remove signed-in watchlist entries in the app to update the saved account list. Remove guest entries or clear this site's browser storage to delete device-local preferences. Clearing browser storage does not delete a server account profile or watchlist. The owner can clear a saved list and manage account access; contact the operator for profile access, correction, deletion or account-recovery requests. No automated emailed password-reset workflow is configured. Reloading, signing out or changing accounts clears application-memory chat history. These actions do not delete server backups, hosting logs or records retained by connected providers.
6. Rights and international processing
Applicable privacy law may provide rights to access, correction, deletion, consent withdrawal, or complaints, subject to its scope and conditions. The operator must establish a working request channel and assess international transfers before release. This draft does not certify compliance with GDPR, India's DPDP framework, or any other privacy law.
7. Details required before release
Controller identity, privacy contact, lawful processing grounds, vendor retention, transfer safeguards, and any required cookie or tracking disclosures remain pending review. These must reflect the deployed service. No contact address or blanket no-cookie claim is invented here.
Primary references: TradingView widget information — https://www.tradingview.com/widget-docs/faq/general/ ; TradingView privacy notice — https://www.tradingview.com/privacy-policy/ ; EU GDPR — https://eur-lex.europa.eu/eli/reg/2016/679/ ; India's DPDP Act — https://www.meity.gov.in/static/uploads/2024/02/Digital-Personal-Data-Protection-Act-2023-1.pdf