Privacy Policy

Last Updated: August 11, 2026

At Pierce Finance, we are committed to protecting your privacy, maintaining data transparency, and giving you full control over your information while delivering powerful agentic financial research tools. This Privacy Policy explains how Pierce Finance ("we," "us," or "our") collects, uses, stores, shares, and safeguards your personal data when you interact with our application, website, and services (collectively, the "Service").


1. Information We Collect

We collect information directly from you, automatically through your use of the Service, and from third-party authentication services.

1.1 Account and Authentication Data

  • Registration Information: When you create an account, we collect your email address, full name, profile image URL, and verification status.
  • Authentication Credentials: If you register with email and password, we securely hash and store your password using industry-standard cryptography via Better Auth. If you register via social sign-in (e.g., Google OAuth), we receive your basic profile information and OAuth tokens provided by the authentication partner.
  • Session Metadata: For account security, session management, and fraud prevention, we automatically record your IP address (session.ipAddress), browser User-Agent string (session.userAgent), login timestamps, and active session tokens.

1.2 Financial & Investor Profile Declarations

  • Exchange & Licensing Declarations: To comply with financial market data provider regulations and data licensing requirements, we collect and store your investor status declaration (such as your non-professional investor status is_non_professional) and optional trading profile preferences.

1.3 Usage, Credit & Research Data

  • Conversations & Research Prompts: We collect and store your chat queries, financial research prompts, agent response history, trade theses, memos, and custom pulses to maintain persistent context across sessions and power your research dashboard.
  • Credit & Consumption Metering: To track usage against your "Pierce Points" balance and subscription tier, we generate usage logs (usage_logs) recording the AI model invoked, token consumption metrics (input/output tokens), credits deducted, and associated query text.
  • Feedback & Survey Responses: If you submit feedback, survey responses, or exit reasons during account cancellation, we collect your ratings, sentiment tags, and comments.

1.4 Payment Information

  • Stripe Billing Tokens: Financial billing and subscription transactions are processed exclusively by Stripe, Inc. We do not receive, store, or process raw credit card or bank account details on our servers. We store only anonymized Stripe customer identifiers (stripe_customer_id), subscription IDs (stripe_subscription_id), plan tier designations, and transaction logs.

2. How We Use Your Information

We process your personal data for the following legitimate business and contractual purposes:

  1. Service Provision: Operating your account, authenticating logins, delivering financial data, and executing agentic research requests.
  2. Compute & Credit Management: Metering Pierce Points balance, deducting usage credits, and managing subscription entitlements.
  3. AI Fulfillment: Processing your prompts through LLM gateways and financial data APIs to generate synthesis, financial charts, and investment analytics.
  4. Security & Fraud Protection: Detecting suspicious activity, enforcing system rate limits, preventing unauthorized access, and maintaining audit trails.
  5. Product Improvement & Analytics: Analyzing feature usage trends and operational errors to optimize user experience and platform reliability.
  6. Communications: Delivering operational updates, password reset links, billing notices, and security verification codes (e.g., account deletion OTP codes).

3. AI Models, Storage & Sub-Processors

3.1 AI Model Gateway & Zero-Training Commitment

To fulfill agentic research workflows, your queries are routed to Large Language Model (LLM) providers via secure API gateways, including OpenRouter (accessing models from OpenAI, Anthropic, Google Gemini, DeepSeek, Meta Llama) and Cloudflare Workers AI.

  • Non-Training Policy: We utilize enterprise API arrangements requesting that your submitted queries and research context be excluded from training foundational AI models.

3.2 AI Storage Architecture

  • Transcript Storage: Full conversation transcripts are stored securely in Cloudflare R2 object storage (conversations/{userId}/{conversationId}.json).
  • Semantic Vector Indexing: High-dimensional vector embeddings of user conversation context are stored in Cloudflare Vectorize to enable semantic context retrieval during research sessions.
  • Database Metadata: Conversation titles, timestamps, visibility flags, user settings, and usage logs are stored in Cloudflare D1 relational databases.

3.3 Third-Party Sub-Processors & Data Recipients

We share data with third-party service providers bound by strict confidentiality and data protection obligations strictly to provide the Service:

Sub-ProcessorFunctionData DisclosedLocation
Cloudflare, Inc.Cloud Infrastructure, Hosting, Database (D1), Object Storage (R2), Vector Index (Vectorize), KV CacheAccount data, encrypted chat transcripts, session logs, IP addressesUnited States / Global Edge
Stripe, Inc.Payment Processing, Subscriptions & CheckoutPayment methods, billing address, email, Stripe IDsUnited States
PostHog, Inc.Product Telemetry & AnalyticsAnonymized user IDs, feature click events, usage paths, feedback sentimentEuropean Union (EU Cloud)
Functional Software, Inc. (Sentry)Application Error Tracking & Crash DiagnosticsError stack traces, browser/OS diagnostic metadata, request URLsUnited States
Resend, Inc.Transactional Email DeliveryEmail address, name, transactional email contents (password reset, deletion OTP)United States
Financial Data Providers (Alpha Vantage, FMP, SEC EDGAR)Financial & Market Data RetrievalTicker symbols, company search parameters (no user identifiers)United States

4. Analytics, Cookies & Telemetry

4.1 Essential Session Cookies

We use essential session cookies (pierce cookie prefix) for authentication, session verification, and maintaining security state. These cookies are required for the Service to function properly.

4.2 Analytics & Event Telemetry

We use PostHog to collect product telemetry (such as feature usage frequency, navigation flows, and subscription change events) to evaluate platform performance. PostHog telemetry data is processed on servers in the European Union. We do not use third-party advertising retargeting cookies or sell telemetry data to third parties.


5. Account Deletion & User Rights (GDPR & CCPA)

5.1 Self-Service Automated Account Deletion

You maintain full control over your data. You may delete your account and all associated personal data at any time directly through the application:

  1. Open Account Settings and select Delete Account.
  2. Review the confirmation warnings and optional feedback step.
  3. Enter the 6-digit One-Time Password (OTP) sent to your registered email address.
  4. Upon OTP verification, the system executes an immediate cascading deletion purging your user profile, authentication accounts, session tokens, user settings, chat metadata, Cloudflare R2 transcripts, usage logs, pulses, trade theses, and credit records from our active databases.

5.2 European Economic Area (EEA) & UK Privacy Rights (GDPR / UK GDPR)

If you reside in the EEA or UK, you have the following rights under data protection laws:

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete personal data.
  • Right to Erasure ("Right to be Forgotten"): Request permanent deletion of your personal data.
  • Right to Data Portability: Request exported machine-readable copies of your data.
  • Right to Restrict or Object: Object to or request restriction of our processing of your personal data.
  • Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.

To exercise any of these rights, contact us at [email protected]. You also have the right to lodge a complaint with your local data protection supervisory authority.

5.3 California Consumer Privacy Act (CCPA / CPRA) Disclosures

If you are a California resident, the CCPA/CPRA provides you with specific rights:

  • Right to Know: Request details about the categories and specific pieces of personal information collected, sources, business purposes, and third parties with whom data is shared.
  • Right to Delete: Request deletion of your personal information.
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Opt-Out of Sale or Sharing: We do not sell your personal information or share it with third parties for cross-context behavioral advertising.
  • Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.

6. Data Security & Retention

6.1 Security Measures

We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, loss, misuse, or alteration. Data is encrypted in transit using Transport Layer Security (TLS 1.3 / HTTPS) and encrypted at rest within Cloudflare's secure global infrastructure.

6.2 Data Retention

We retain personal data for as long as your account remains active or as needed to provide the Service, comply with financial audit obligations, resolve disputes, and enforce our agreements. When you trigger account deletion, your data is permanently removed from active databases immediately.


7. Children's Privacy

The Service is strictly intended for individuals who are at least 18 years of age (or the legal age of majority in your jurisdiction). We do not knowingly collect or solicit personal information from children under 18. If we discover that a child under 18 has provided us with personal information, we will delete it immediately.


8. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact our Data Protection team at: