Legal Framework

Privacy Policy

Effective Date: April 7, 2026 • Last Updated: April 7, 2026

01

Information We Collect

We collect information you provide directly to us and information generated through your use of the Platform. This includes:

manage_accountsAccount Data
Email address, display name, and authentication credentials collected via Supabase when you register or sign in with Google OAuth.
paymentsBilling Data
Subscription and payment information processed by Dodo Payments. We do not store raw payment card data - this is handled entirely by Dodo Payments.
analyticsUsage Data
Pages visited, features used, tickers viewed, signals accessed, portfolio entries, and interaction patterns within the Platform.
devicesTechnical Data
IP address, browser type and version, device identifiers, operating system, referring URLs, and session timestamps.
02

How We Use Your Information

We use the information we collect for the following purposes:

  • Service Delivery: To authenticate your identity, maintain your account, provide access to signals and analysis features, and deliver the Platform functionality you have subscribed to.
  • Billing and Subscriptions: To process payments via Dodo Payments, manage your subscription status, handle trial periods, and send billing-related communications.
  • Platform Improvement: To analyze usage patterns, diagnose technical issues, optimize performance, and develop new features based on how users interact with the Platform.
  • Communications: To send transactional emails (account confirmations, password resets, billing receipts), product updates, and - where you have opted in - promotional messages. You may opt out of marketing communications at any time.
  • Legal Compliance: To comply with applicable laws, respond to lawful requests from authorities, enforce our Terms of Service, and protect the rights and safety of ASignal and its users.
  • Security: To detect, investigate, and prevent fraudulent activity, unauthorized access, and other harmful conduct.

We do not sell your personal information to third parties. We do not use your data to train AI models without your explicit consent.

03

Data Storage & Security

Your account and authentication data is stored and managed by Supabase, our backend-as-a-service provider. Supabase stores data in encrypted form at rest and in transit using industry-standard TLS encryption. Authentication tokens are handled as short-lived JWTs and are not persisted beyond their expiry.

Platform data - including your portfolio entries, signal history, and preferences - is stored in our PostgreSQL database hosted on infrastructure we operate and control. This database is not publicly accessible and requires authenticated connections.

We implement commercially reasonable administrative, technical, and physical security measures to protect your personal information from unauthorized access, use, or disclosure, including:

  • Encryption of data in transit via TLS/HTTPS across all endpoints.
  • Encryption of data at rest for authentication and sensitive records.
  • Access controls limiting data access to authorized personnel only.
  • Regular review of our data handling practices and security posture.

No method of electronic transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security. In the event of a data breach that affects your rights and freedoms, we will notify you as required by applicable law.

04

Third-Party Services

The Platform integrates with the following third-party services that may receive your data as part of their function:

lock_personSupabaseAuthentication

Manages user accounts, email/password auth, and Google OAuth sign-in. Receives your email address, name (if provided via Google), and manages session tokens. Governed by the Supabase Privacy Policy.

credit_cardDodo PaymentsBilling & Subscriptions

Dodo Payments processes payments on our behalf. Your payment information is handled directly by Dodo Payments and is subject to Dodo Payments's Privacy Policy. Receives your email address and payment information. ASignal does not store or process your credit card information. Please refer to Dodo Payments's Privacy Policy for details on how your payment data is handled.

bar_chartAnalyticsUsage Telemetry

We may use privacy-respecting analytics tools to measure platform performance and feature usage. Where used, these tools receive anonymized or pseudonymized usage data only - no personally identifiable information is shared with analytics providers.

We enter into data processing agreements with our service providers where required by applicable law, and we require them to implement appropriate security measures for any personal data they process on our behalf.

05

Cookies & Tracking

The Platform uses cookies and similar tracking technologies to operate correctly and to improve your experience. We categorize these as follows:

Essential Cookies

Required for the Platform to function. These include authentication session cookies (managed by Supabase) and security tokens. You cannot opt out of these without disabling your account session.

Analytics Cookies

Optional cookies used to understand how users interact with the Platform, which pages are visited most frequently, and where users encounter issues. You may opt out via your browser settings or account preferences.

Most web browsers are set to accept cookies by default. You can instruct your browser to refuse all cookies or to indicate when a cookie is being set. However, if you disable essential cookies, some parts of the Platform may not function correctly.

We do not use cookies for cross-site behavioral advertising or sell cookie data to third parties.

06

Your Rights

Depending on your jurisdiction, you may have certain rights with respect to your personal information. These may include:

  • Access: The right to request a copy of the personal information we hold about you.
  • Correction: The right to request correction of inaccurate or incomplete personal information.
  • Deletion: The right to request deletion of your personal information, subject to certain exceptions (such as legal obligations to retain records).
  • Export: The right to receive your personal data in a structured, commonly used, machine-readable format.
  • Objection: The right to object to or restrict certain types of processing of your personal information.
  • Withdrawal of Consent: Where processing is based on your consent, the right to withdraw that consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, or if you have questions about how we handle your personal information, please contact us at:

We will respond to verified requests within 30 days, or as required by applicable law.

07

Data Retention

We retain your personal information for as long as your account is active or as needed to provide you with the Platform services. Specifically:

  • Account Data: Retained for the duration of your account. Upon account deletion, your authentication records are removed from Supabase within 30 days, subject to any legal hold obligations.
  • Portfolio and Signal History: Retained while your account is active. You may delete individual entries at any time via the Platform interface.
  • Billing Records: Retained for a minimum of seven (7) years as required by applicable financial recordkeeping regulations, even after account closure.
  • Usage and Analytics Data: Retained in aggregated or anonymized form for up to 24 months for platform improvement purposes.
  • Log Data: Server logs and error logs retained for up to 90 days for security and diagnostic purposes.

If you delete your account or submit a deletion request, we will delete or anonymize your personal information within 30 days, except where retention is required by law or necessary to resolve disputes, enforce our agreements, or protect our legal rights.

08

Children's Privacy

The Platform is intended solely for users who are at least eighteen (18) years of age. We do not knowingly collect, solicit, or process personal information from individuals under the age of 18.

By creating an account, you represent and warrant that you are at least 18 years of age. If we become aware that we have inadvertently collected personal information from a person under 18, we will take immediate steps to delete that information from our systems.

If you are a parent or guardian and believe that your child has provided us with personal information without your consent, please contact us immediately at [email protected] so we can take appropriate action.

09

Changes to This Privacy Policy

We reserve the right to update or modify this Privacy Policy at any time. We will notify you of material changes by:

  • Sending an email notification to the address associated with your account at least 30 days before the changes take effect.
  • Posting a prominent notice on the Platform indicating that the Privacy Policy has been updated.
  • Updating the "Last Updated" date at the top of this page.

Your continued use of the Platform after the effective date of any revised Privacy Policy constitutes your acceptance of the changes. If you do not agree to the revised policy, you should discontinue use of the Platform and close your account before the changes take effect.

We encourage you to review this Privacy Policy periodically to stay informed about how we collect, use, and protect your information.

10

Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

ASignal

Email: [email protected]

You may also review our Terms of Service for additional information about your rights and obligations when using the Platform.

diamond