Privacy Policy
Quick Summary
- We collect account, portfolio, and usage data to provide analysis.
- We use AI for insights and send only minimal, anonymized context to OpenAI.
- We don’t sell your data and share only what’s necessary with trusted providers.
- You can access, export, or delete your data and cancel anytime.
1. Introduction
At Wingardium, your privacy is our priority. We wrote this policy to explain, in simple terms, what data we collect, why we collect it, and how we protect it — so you can invest with confidence.
2. Information We Collect
Personal Information
- Name and email address (when you create an account via Clerk)
- Authentication identifiers and session data from Clerk (our authentication provider)
- Subscription status and limited billing metadata from Polar (payment processor)
Portfolio Data
- Stock ticker symbols and quantities
- Purchase prices and dates
- Portfolio snapshots and analysis history
Usage Data
- Log data (IP address, browser type, pages visited)
- Analytics data (via Vercel Analytics)
- Feature usage patterns
Cookies and Local Storage
- Authentication cookies set by Clerk to manage sessions
- A simple theme preference cookie ("theme=new|old") set by our site
- Analytics cookies or local storage used by Vercel Analytics
3. How We Use Your Information
We use your information to:
- Provide and maintain our portfolio analysis service
- Process your portfolio data and generate insights
- Communicate with you about your account and service updates
- Process payments and manage subscriptions
- Improve our service and develop new features
- Comply with legal obligations
AI processing: We use AI to generate portfolio insights. We send only the minimum required data — such as portfolio metrics and anonymized context — to OpenAI’s API. We never send personal identifiers, passwords, or payment details. As of today, OpenAI states API data is not used to train their models by default. Please review OpenAI’s policy for updates.
4. Data Security
We implement industry-standard security measures to protect your data:
- TLS encryption in transit for all data transmissions
- Secure cloud storage with Supabase (encryption at rest managed by the provider)
- Regular security audits and updates
- Limited access to personal data on a need-to-know basis
- Secure authentication through Clerk
While no online service can guarantee 100% security, we use bank-grade encryption and strict access controls to protect your data.
5. Third-Party Services
We work with trusted partners to operate our platform:
- Clerk: Authentication and user management
- Supabase: Database and data storage
- OpenAI: AI-powered portfolio parsing and insights
- Yahoo Finance: Real-time market data
- Polar: Payment processing
- Vercel: Hosting and analytics
Each of these services has their own privacy policies and we encourage you to review them. We only share the minimum data required and never sell your information. Market data is retrieved from Yahoo Finance based on the tickers you provide; we do not share your identity with Yahoo when fetching quotes.
6. Data Sharing
We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:
- With your consent
- To comply with legal obligations
- To protect our rights and prevent fraud
- With service providers who assist in operating our platform
- In connection with a business transfer (e.g., merger, acquisition), as permitted by law
- As aggregated or de-identified information that does not identify you
7. Legal Bases (EEA/UK)
- Performance of a contract (to provide the Service)
- Legitimate interests (to secure and improve the Service)
- Consent (for optional communications where required)
- Compliance with legal obligations
If you are located in the EEA, UK, or Switzerland, we process your personal data in accordance with applicable data protection laws, including GDPR and the Swiss Federal Act on Data Protection.
8. Your Rights
You have the right to:
- Access your personal information
- Correct inaccurate data
- Request deletion of your data
- Export your portfolio data
- Opt-out of marketing communications
- Close your account at any time
Depending on your location, you may have additional rights (e.g., to object to processing or request restriction). To exercise any rights, contact us at wingardium.ai@gmail.com.
9. Data Retention
We retain your personal information for as long as your account is active or as needed to provide you services. If you close your account, we will delete your personal information within 30 days, except where we are required to retain it for legal purposes.
Portfolio snapshots and analytics may be stored to enable historical insights; you can request deletion at any time. Basic system logs may be retained for a limited period for security, debugging, and compliance.
10. Children's Privacy
Our service is not intended for children under 18 years of age. We do not knowingly collect personal information from children under 18.
11. International Transfers
Your information may be processed in countries other than your own (including the United States). Where required, we rely on appropriate safeguards such as Standard Contractual Clauses provided by our processors.
12. Do Not Track
We do not currently respond to browser "Do Not Track" signals. You can control cookies through your browser settings.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.
14. Contact Us
If you have any questions about this Privacy Policy, please contact us at:
- Email: wingardium.ai@gmail.com
- Website: wingardium.ai
Last updated: 12/14/2025