Privacy Policy
Last updated: 2026-04-25
NewsProbe.io is committed to GDPR (Regulation EU 2016/679) compliance. This page describes what data we collect, why, the legal bases, and your rights as a data subject.
1. Data controller
The data controller is the editor of NewsProbe.io. For any privacy-related request, contact: privacy@newsprobe.io.
We have not designated a Data Protection Officer (DPO) because our processing does not meet the criteria of GDPR Art. 37 §1 (we are not a public authority, our core activities do not require systematic monitoring of data subjects on a large scale, nor do we process special-category data on a large scale). The privacy contact above remains the single point of contact for any data-protection question.
2. What we collect
Account data (when you sign up): email address, authentication identifier from Clerk, creation timestamp.
Trading journal data (only if you choose to use the Journal): trade entries you log manually or import via CSV / broker sync — ticker, direction, prices, quantities, dates, optional notes.
AI Reviewer output: structured analysis of your closed trades, including identified behavioral biases and a score. Generated from the trade data you provided.
Billing data (if you subscribe): processed by Stripe via Clerk Billing; we do not store card numbers.
Usage data: page views, feature usage events, and aggregate statistics. Collected via privacy-friendly analytics (Plausible, no tracking cookies) only after you have given consent.
Technical data: IP address (truncated), user agent, request timestamps — for security and rate-limiting.
3. What we do not collect
We do not collect: bank or brokerage credentials beyond what is strictly required for an OAuth integration you explicitly authorize; advertising identifiers; cross-site tracking data; biometric data; political or religious opinions; data from minors under 16.
4. Legal bases (Art. 6 GDPR)
- Performance of contract (Art. 6 §1 b): account creation, journal storage, paid-subscription delivery.
- Legitimate interest (Art. 6 §1 f): security, fraud prevention, debugging.
- Consent (Art. 6 §1 a): non-essential analytics, marketing emails. You can withdraw consent at any time via Cookie settings in the footer or by unsubscribing.
- Legal obligation (Art. 6 §1 c): tax invoicing, retention of accounting records.
5. Sub-processors
A current list with locations and safeguards is maintained on /legal/dpa.
6. International transfers
Some sub-processors are located outside the European Economic Area (United States: Clerk, Vercel, Anthropic, OpenAI, Polygon, Finnhub, Stripe). Transfers rely on the Standard Contractual Clauses (SCCs) adopted by the European Commission on 4 June 2021 (Decision 2021/914), specifically Module 2 (controller to processor), supplemented where applicable by additional technical and organizational measures (encryption in transit, no plaintext credentials shared).
7. Retention
- Account & journal data: kept until you delete your account.
- Logs & technical data: 90 days max.
- Billing records (invoices): 10 years (French legal obligation, L.123-22 Code de commerce).
- Marketing email lists: until you unsubscribe.
- Audit log of data-export and account-deletion requests: 3 years (legitimate interest, abuse prevention).
8. Your rights (GDPR Articles 15–22)
You have the right to:
- access your data (export available at
/account/data); - rectify it;
- erase it (delete account at
/account/data); - restrict processing;
- portability (export is provided as JSON);
- object to processing;
- lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés) at cnil.fr or your national data-protection authority.
Self-service export and deletion are available at /account/data. For other requests, contact privacy@newsprobe.io — we respond within 30 days.
9. Cookies and tracking
See /legal/cookies for our cookie policy.
10. Changes
We may update this policy. Material changes are announced at least 30 days before they take effect.