Back

Privacy Policy

InvestIQ · Last updated: June 13, 2026

1.Who we are

InvestIQ ("we", "the platform") is an AI-powered financial analysis service. Data controller: Alex Maxim, contact: investiq.dev@yahoo.com

2.What data we collect

  • Account data: email, name, encrypted password
  • Financial data: stock symbols, transactions, portfolio — voluntarily entered by the user
  • Usage data: nr. analyses, access dates
  • Payment data: managed exclusively by Stripe (we do not store card numbers)

3.Why we collect this data

  • Providing the financial analysis service
  • Processing payments and managing subscriptions
  • Improving the platform
  • Communication about account and service

4.Legal basis (GDPR)

  • Contract performance (subscription)
  • Your explicit consent
  • Legitimate interests (security, fraud prevention)

5.How we protect data

  • All data is encrypted in transit (HTTPS/TLS)
  • Passwords stored with bcrypt hash
  • Financial data isolated per user
  • API keys stored in secure environment variables
  • Limited data access (principle of least privilege)
  • Providers: EU infrastructure, Anthropic (US - SCC), Stripe (EU/US - PCI DSS certified)

6.How long we keep data

  • Account data: for the duration of the subscription + 30 days
  • Financial data (portfolio): deleted upon request
  • Payment data: as per Stripe and tax requirements
  • AI analyses: 12h cache, 1 year history

7.Your rights (GDPR Art. 15-22)

  • Right of access — you can download all your data
  • Right to rectification — you can correct your data
  • Right to erasure ("right to be forgotten")
  • Right to data portability — CSV/JSON export
  • Right to object
  • Right to withdraw consent

To exercise these rights: investiq.dev@yahoo.com

8.Cookies

We only use essential cookies:

  • Session cookie (authentication)
  • Preferences (language, theme, currency)

We do not use tracking or advertising cookies.

9.International transfers

  • Anthropic (USA) — Standard contractual clauses
  • Data stored in EU (Frankfurt)
  • Stripe — PCI DSS Level 1 certified

10.Changes

We will notify you by email 30 days before significant changes.

11.Contact and complaints

TermsPrivacyContact
Created by Alex Maxim