ForthLogic AI
# Privacy Policy **Last updated:** [DATE] [COMPANY LEGAL NAME] ("Company," "we," "us," or "our") operates [PRODUCT NAME] (the "Service"), an AI-powered trading analysis and education platform. This Privacy Policy explains how we collect, use, share, and protect information about you when you use the Service. **This Service is for educational and informational purposes only. We do not provide investment advice, brokerage services, or financial planning. See our Terms of Service for full details.** By using the Service, you agree to the collection and use of information in accordance with this policy. --- ## 1. Information We Collect ### 1.1 Information You Provide Directly - **Account information:** name, email address, password (stored as a hash), and any profile details you choose to add. - **Billing information:** processed through our payment provider (Stripe). We do not store full credit card numbers on our servers. Stripe stores and processes payment data under their own privacy policy. - **AI conversation content:** every audit request, chat message, chart screenshot, and follow-up question you send to the AI is stored in our database so you can review your audit history. - **Outcome tracking:** if you tag the outcome of a trade audit (e.g., "hit target," "hit stop"), that tag is stored against your audit history. - **Support communications:** any messages you send us through email, contact forms, or support channels. ### 1.2 Information We Collect Automatically - **Usage data:** pages viewed, features used, time spent, click patterns, and similar interaction data. - **Device and connection data:** IP address, browser type, operating system, device identifiers, referring URLs, and timestamps. - **Cookies and similar technologies:** session cookies for authentication, preference cookies for UI settings, and (where applicable) analytics cookies. You can disable non-essential cookies in your browser, though some features may not work without them. ### 1.3 Information from Third Parties - **AI provider data:** when you send a message to the AI, the content is transmitted to our AI infrastructure provider (currently Anthropic) for processing. Anthropic's handling of this data is governed by their commercial API terms; they do not train models on API-submitted data by default. - **OAuth providers:** if you sign in using a third-party identity provider (e.g., Google), we receive basic profile data from that provider as authorized by you. --- ## 2. How We Use Your Information We use the information we collect to: - Provide, maintain, and improve the Service - Process your AI requests and return analysis to you - Store your audit history so you can review past analyses - Process payments and manage your subscription - Send transactional emails (account notices, billing receipts, password resets) - Send product updates and educational content (you can opt out of marketing emails at any time) - Detect, prevent, and address fraud, abuse, security incidents, and technical issues - Analyze usage patterns to improve features and user experience - Comply with legal obligations and enforce our Terms of Service --- ## 3. How We Share Your Information We do **not** sell your personal information. We share information only in the following circumstances: ### 3.1 Service Providers We share information with third parties that perform services on our behalf, including: - **Anthropic** — AI model processing - **Stripe** — payment processing - **[HOSTING PROVIDER, e.g., Laravel Cloud / DigitalOcean]** — infrastructure hosting - **[EMAIL PROVIDER, e.g., SendGrid / Postmark]** — transactional email - **[ANALYTICS PROVIDER, if any]** — usage analytics These providers are contractually obligated to handle your data only for the purposes we specify and to apply reasonable security measures. ### 3.2 Legal Requirements We may disclose information if required by law, subpoena, court order, or other legal process, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others, or to investigate fraud. ### 3.3 Business Transfers If we are involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy. ### 3.4 With Your Consent We may share information with your explicit consent for purposes not listed in this policy. --- ## 4. AI Conversation Data — Specific Notice Because trading analysis is sensitive and personally identifying, we want to be specific: - **Your audit requests and responses are stored** in our database, associated with your account, so you can review your history. - **We do not share individual audit content with other users.** - **We may review anonymized, aggregated audit patterns** to improve the AI prompts and methodology — but we do not review the contents of individual user audits except (a) when investigating a security or abuse issue, (b) when responding to a support request you initiate, or (c) when legally required. - **Anthropic processes your audit content** in order to generate responses. Anthropic's API terms state they do not retain API inputs/outputs for training. See [https://www.anthropic.com/legal](https://www.anthropic.com/legal) for current details. - **You can delete your audit history** at any time from your account settings, or by deleting your account entirely. --- ## 5. Data Retention We retain your information for as long as your account is active or as needed to provide the Service. Specifically: - **Active accounts:** information retained for the duration of your account - **Closed accounts:** core account and billing records retained for up to [7] years to comply with tax, accounting, and legal obligations; audit history deleted within [30] days of account closure unless legal hold applies - **Backups:** information in encrypted backups may persist for up to [90] days after deletion from primary systems - **Aggregated, anonymized data:** may be retained indefinitely for analytics and product improvement --- ## 6. Your Rights Depending on your jurisdiction, you may have the following rights: - **Access** — request a copy of the personal information we hold about you - **Correction** — request that we correct inaccurate or incomplete information - **Deletion** — request that we delete your information ("right to be forgotten") - **Portability** — request your information in a portable, machine-readable format - **Restriction** — request that we limit processing of your information - **Objection** — object to certain types of processing (e.g., direct marketing) - **Withdrawal of consent** — withdraw consent for processing where we rely on consent To exercise any of these rights, email us at [PRIVACY EMAIL]. We will respond within 30 days. We may need to verify your identity before fulfilling certain requests. ### 6.1 California Residents (CCPA/CPRA) California residents have additional rights, including the right to know what personal information is collected, sold, or disclosed, and the right to opt out of sale (we do not sell personal information). To exercise these rights, contact [PRIVACY EMAIL]. ### 6.2 EEA, UK, and Swiss Residents (GDPR) Residents of the European Economic Area, United Kingdom, and Switzerland have additional rights under the GDPR. The legal basis for our processing is generally (a) performance of a contract (providing the Service), (b) legitimate interests (improving the Service, preventing abuse), or (c) your consent (marketing emails). You may lodge a complaint with your local data protection authority. --- ## 7. Security We implement reasonable administrative, technical, and physical safeguards to protect your information, including: - Encryption in transit (TLS) and at rest where applicable - Hashed and salted password storage - Restricted access to production systems - Regular security review of dependencies and infrastructure - Stripe-handled payment data (we do not store card numbers) **No system is 100% secure.** While we work to protect your information, we cannot guarantee absolute security. You are responsible for keeping your account password confidential. --- ## 8. Children's Privacy The Service is not intended for users under **18 years of age**. Trading and financial decision-making is for adults. We do not knowingly collect personal information from children. If we learn that we have collected information from a child under 18, we will delete it. If you believe a child has provided us information, contact [PRIVACY EMAIL]. --- ## 9. International Data Transfers Our infrastructure is primarily hosted in [HOSTING REGION, e.g., the United States]. If you access the Service from outside that region, your information will be transferred to, stored in, and processed in that region. By using the Service, you consent to this transfer. Where required, we rely on standard contractual clauses or other appropriate transfer mechanisms. --- ## 10. Third-Party Links The Service may contain links to third-party websites, services, or resources. We are not responsible for the privacy practices of those third parties. Review their privacy policies before providing any information. --- ## 11. Changes to This Policy We may update this Privacy Policy from time to time. Material changes will be communicated by email or through a prominent notice in the Service at least [14] days before they take effect. The "Last updated" date at the top of this policy reflects the most recent revision. Your continued use of the Service after the effective date constitutes acceptance of the revised policy. --- ## 12. Contact Us Questions or concerns about this Privacy Policy or our data practices: **[COMPANY LEGAL NAME]** Attention: Privacy [BUSINESS ADDRESS] Email: [PRIVACY EMAIL] --- *This Privacy Policy was prepared as a general template and should be reviewed by qualified legal counsel before publication, especially given the financial-services-adjacent nature of the Service.*