Privacy Policy
Last Updated: August 11, 2026
At Pierce Finance, we are committed to protecting your privacy, maintaining data transparency, and giving you full control over your information while delivering powerful agentic financial research tools. This Privacy Policy explains how Pierce Finance ("we," "us," or "our") collects, uses, stores, shares, and safeguards your personal data when you interact with our application, website, and services (collectively, the "Service").
1. Information We Collect
We collect information directly from you, automatically through your use of the Service, and from third-party authentication services.
1.1 Account and Authentication Data
- Registration Information: When you create an account, we collect your email address, full name, profile image URL, and verification status.
- Authentication Credentials: If you register with email and password, we securely hash and store your password using industry-standard cryptography via Better Auth. If you register via social sign-in (e.g., Google OAuth), we receive your basic profile information and OAuth tokens provided by the authentication partner.
- Session Metadata: For account security, session management, and fraud prevention, we automatically record your IP address (
session.ipAddress), browser User-Agent string (session.userAgent), login timestamps, and active session tokens.
1.2 Financial & Investor Profile Declarations
- Exchange & Licensing Declarations: To comply with financial market data provider regulations and data licensing requirements, we collect and store your investor status declaration (such as your non-professional investor status
is_non_professional) and optional trading profile preferences.
1.3 Usage, Credit & Research Data
- Conversations & Research Prompts: We collect and store your chat queries, financial research prompts, agent response history, trade theses, memos, and custom pulses to maintain persistent context across sessions and power your research dashboard.
- Credit & Consumption Metering: To track usage against your "Pierce Points" balance and subscription tier, we generate usage logs (
usage_logs) recording the AI model invoked, token consumption metrics (input/output tokens), credits deducted, and associated query text. - Feedback & Survey Responses: If you submit feedback, survey responses, or exit reasons during account cancellation, we collect your ratings, sentiment tags, and comments.
1.4 Payment Information
- Stripe Billing Tokens: Financial billing and subscription transactions are processed exclusively by Stripe, Inc. We do not receive, store, or process raw credit card or bank account details on our servers. We store only anonymized Stripe customer identifiers (
stripe_customer_id), subscription IDs (stripe_subscription_id), plan tier designations, and transaction logs.
2. How We Use Your Information
We process your personal data for the following legitimate business and contractual purposes:
- Service Provision: Operating your account, authenticating logins, delivering financial data, and executing agentic research requests.
- Compute & Credit Management: Metering Pierce Points balance, deducting usage credits, and managing subscription entitlements.
- AI Fulfillment: Processing your prompts through LLM gateways and financial data APIs to generate synthesis, financial charts, and investment analytics.
- Security & Fraud Protection: Detecting suspicious activity, enforcing system rate limits, preventing unauthorized access, and maintaining audit trails.
- Product Improvement & Analytics: Analyzing feature usage trends and operational errors to optimize user experience and platform reliability.
- Communications: Delivering operational updates, password reset links, billing notices, and security verification codes (e.g., account deletion OTP codes).
3. AI Models, Storage & Sub-Processors
3.1 AI Model Gateway & Zero-Training Commitment
To fulfill agentic research workflows, your queries are routed to Large Language Model (LLM) providers via secure API gateways, including OpenRouter (accessing models from OpenAI, Anthropic, Google Gemini, DeepSeek, Meta Llama) and Cloudflare Workers AI.
- Non-Training Policy: We utilize enterprise API arrangements requesting that your submitted queries and research context be excluded from training foundational AI models.
3.2 AI Storage Architecture
- Transcript Storage: Full conversation transcripts are stored securely in Cloudflare R2 object storage (
conversations/{userId}/{conversationId}.json). - Semantic Vector Indexing: High-dimensional vector embeddings of user conversation context are stored in Cloudflare Vectorize to enable semantic context retrieval during research sessions.
- Database Metadata: Conversation titles, timestamps, visibility flags, user settings, and usage logs are stored in Cloudflare D1 relational databases.
3.3 Third-Party Sub-Processors & Data Recipients
We share data with third-party service providers bound by strict confidentiality and data protection obligations strictly to provide the Service:
| Sub-Processor | Function | Data Disclosed | Location |
|---|---|---|---|
| Cloudflare, Inc. | Cloud Infrastructure, Hosting, Database (D1), Object Storage (R2), Vector Index (Vectorize), KV Cache | Account data, encrypted chat transcripts, session logs, IP addresses | United States / Global Edge |
| Stripe, Inc. | Payment Processing, Subscriptions & Checkout | Payment methods, billing address, email, Stripe IDs | United States |
| PostHog, Inc. | Product Telemetry & Analytics | Anonymized user IDs, feature click events, usage paths, feedback sentiment | European Union (EU Cloud) |
| Functional Software, Inc. (Sentry) | Application Error Tracking & Crash Diagnostics | Error stack traces, browser/OS diagnostic metadata, request URLs | United States |
| Resend, Inc. | Transactional Email Delivery | Email address, name, transactional email contents (password reset, deletion OTP) | United States |
| Financial Data Providers (Alpha Vantage, FMP, SEC EDGAR) | Financial & Market Data Retrieval | Ticker symbols, company search parameters (no user identifiers) | United States |
4. Analytics, Cookies & Telemetry
4.1 Essential Session Cookies
We use essential session cookies (pierce cookie prefix) for authentication, session verification, and maintaining security state. These cookies are required for the Service to function properly.
4.2 Analytics & Event Telemetry
We use PostHog to collect product telemetry (such as feature usage frequency, navigation flows, and subscription change events) to evaluate platform performance. PostHog telemetry data is processed on servers in the European Union. We do not use third-party advertising retargeting cookies or sell telemetry data to third parties.
5. Account Deletion & User Rights (GDPR & CCPA)
5.1 Self-Service Automated Account Deletion
You maintain full control over your data. You may delete your account and all associated personal data at any time directly through the application:
- Open Account Settings and select Delete Account.
- Review the confirmation warnings and optional feedback step.
- Enter the 6-digit One-Time Password (OTP) sent to your registered email address.
- Upon OTP verification, the system executes an immediate cascading deletion purging your user profile, authentication accounts, session tokens, user settings, chat metadata, Cloudflare R2 transcripts, usage logs, pulses, trade theses, and credit records from our active databases.
5.2 European Economic Area (EEA) & UK Privacy Rights (GDPR / UK GDPR)
If you reside in the EEA or UK, you have the following rights under data protection laws:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete personal data.
- Right to Erasure ("Right to be Forgotten"): Request permanent deletion of your personal data.
- Right to Data Portability: Request exported machine-readable copies of your data.
- Right to Restrict or Object: Object to or request restriction of our processing of your personal data.
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, contact us at [email protected]. You also have the right to lodge a complaint with your local data protection supervisory authority.
5.3 California Consumer Privacy Act (CCPA / CPRA) Disclosures
If you are a California resident, the CCPA/CPRA provides you with specific rights:
- Right to Know: Request details about the categories and specific pieces of personal information collected, sources, business purposes, and third parties with whom data is shared.
- Right to Delete: Request deletion of your personal information.
- Right to Correct: Request correction of inaccurate personal information.
- Right to Opt-Out of Sale or Sharing: We do not sell your personal information or share it with third parties for cross-context behavioral advertising.
- Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.
6. Data Security & Retention
6.1 Security Measures
We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, loss, misuse, or alteration. Data is encrypted in transit using Transport Layer Security (TLS 1.3 / HTTPS) and encrypted at rest within Cloudflare's secure global infrastructure.
6.2 Data Retention
We retain personal data for as long as your account remains active or as needed to provide the Service, comply with financial audit obligations, resolve disputes, and enforce our agreements. When you trigger account deletion, your data is permanently removed from active databases immediately.
7. Children's Privacy
The Service is strictly intended for individuals who are at least 18 years of age (or the legal age of majority in your jurisdiction). We do not knowingly collect or solicit personal information from children under 18. If we discover that a child under 18 has provided us with personal information, we will delete it immediately.
8. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact our Data Protection team at:
- Email:
[email protected] - Website: https://pierce.finance