ticklume
TermsPrivacyRisk disclosureMethodology

Ticklume was previously named StockBrief. The review-candidate document below retains that historical name pending its versioned legal update. It is not approved for public launch.

Privacy notice

A minimal account should create a minimal data footprint.

This review candidate explains the data used by the current preview. Controller identity, contact details, legal bases, processor terms, international-transfer safeguards and retention periods require final legal confirmation before launch.

Status
Review candidate · not approved for launch
Version
privacy-eu-eea-2026-08-24-review-candidate-v1
Perimeter
EU/EEA preview

Data handled by the preview

  • Account identity data managed through Supabase Auth, including email address and authentication identifiers.
  • Optional display name, language and theme preferences.
  • Watchlist tickers, which are saved reading references rather than portfolio holdings.
  • Versions and timestamp of approved legal documents when acceptance is later enabled.
  • Technical request, security and deployment logs that hosting providers may create, such as IP address, device information, timestamps and error records.

Why data is used

  • Provide and secure the account, saved preferences and watchlist.
  • Operate, diagnose and protect the application and prevent abuse.
  • Respond to account export, correction and deletion requests.
  • Record approved document acceptance when the legal gate permits it.

Infrastructure and recipients

The current architecture uses Vercel for the web application, Render for the private API and jobs, and Supabase for authentication and PostgreSQL. Their technical processing, sub-processors, regions and transfer mechanisms must be confirmed in the final processor register and privacy notice.

StockBrief does not send account profiles or watchlists to the interpretation model. AI tasks use bounded company-source content, not a reader's personal circumstances.

Retention and security

Account data is retained while the account is active and removed through the account-deletion flow, subject to backups, security records and legal retention requirements that must be finalized. Secrets are kept outside the repository, private API access requires a verified token and user-owned database rows are protected by row-level security.

Your choices and rights

  • Export your profile, preferences and watchlist from the account page.
  • Correct optional profile data and remove watchlist entries.
  • Delete the account and its user-owned application data.
  • EU/EEA rights may include access, rectification, erasure, restriction, objection, portability and a complaint to a supervisory authority, depending on the confirmed legal basis and circumstances.

Local preferences and contact

Theme preference may be stored locally so the interface can respect light, dark or system mode. A final cookie inventory, controller contact and privacy-request channel must be published before launch. Until then, this page does not invite production account use.

Official reference points

These links support the review process; they are not a legal opinion about Ticklume.

  • EU General Data Protection Regulation

Educational information and scenario analysis—not personal investment advice. Markets involve risk; data and assumptions may be incomplete.

MethodologyRisk disclosurePrivacyTerms
EU/EEA preview · Legal review required before public launch