Privacy Policy

Effective Date: July 21, 2026

Private pre-beta notice. Obtain qualified privacy review before expanding beyond controlled testing.

Scope and accountability

This notice describes how InvestorOS handles personal information in its research and decision-support portal. InvestorOS is responsible for personal information under its control, including information processed by service providers.

Information we collect

  • Account and profile information you provide, such as username, name, email, age or date-of-birth information, and optional address details.
  • Authentication and security information, including a password hash, session identifiers, IP address, browser or device information, and security audit events.
  • Information you create in the service, including watchlists, journals, theses, portfolios, alerts, settings, custom scans, and support messages.
  • Usage events used to operate, secure, troubleshoot, and improve the private beta.
  • Browser-local preferences and drafts stored on your device, such as theme, navigation mode, ticker notes, and trade-planning drafts.

Why we use it

  • Provide, personalize, and support the features you request.
  • Authenticate users, prevent abuse, investigate incidents, and protect the service.
  • Maintain user-created research records and send alerts a user enables.
  • Measure reliability and feature use during the private beta.
  • Meet legal obligations and respond to valid legal requests.

InvestorOS does not sell or rent personal information. A new materially different purpose requires notice and, where required, fresh consent.

Service providers and transfers

InvestorOS uses Vercel for frontend hosting, Render for backend hosting, Neon for PostgreSQL storage, and market-data providers such as Financial Modeling Prep. These providers process limited information needed to deliver their services. Information may be processed outside your province or country and may be subject to the laws of those locations. GitHub is used for source code and is not an approved runtime store for user records.

Cookies and device storage

The portal uses essential, HttpOnly authentication cookies. It also uses browser local storage for preferences and selected local drafts. InvestorOS does not currently use advertising cookies. Blocking essential cookies prevents sign-in; browser-local information can be removed through your browser settings.

Retention, safeguards, and incidents

Account records and user-created content are retained while the account is active and as needed for the purposes described above. Expired sessions and bounded audit records are removed through operational controls. Provider logs and backups follow provider retention settings. InvestorOS uses access controls, password hashing, encrypted network connections, restricted origins, and monitoring appropriate to the private-beta environment. No system can guarantee absolute security.

Your choices and rights

Subject to applicable law, you may request access to or correction of personal information, export account data, challenge InvestorOS's privacy practices, or request account deletion. Account deletion does not automatically erase browser-local information on every device; clear that information in the applicable browser as well.

Contact and changes

Privacy questions or requests can be sent to privacy@investoros.com. Before broader testing, InvestorOS should confirm this address is monitored and identify the accountable privacy role. Material changes will be communicated and versioned; fresh acknowledgement or consent will be requested when required.