§ Legal

Privacy Policy

Last updated · May 18, 2026

1. What we collect

When you create an account, we store your name, email, and a hashed password. When you use the app, we store your watchlists, alerts, portfolio holdings, journal entries, and account settings.

For paying subscribers, Stripe handles all payment processing. We never see your card details — only a customer ID and subscription status.

2. What we don't do

  • We don't sell your data to anyone.
  • We don't share watchlist, portfolio, or trading activity with third parties.
  • We don't run ad networks. No tracking pixels from Facebook, TikTok, etc.
  • We don't email-spam you. Daily digest and alerts are opt-out at any time.

3. Third-party services

We use these vendors to operate the app:

  • Vercel — application hosting
  • MongoDB Atlas — user account + portfolio storage
  • Stripe — payment processing for paid plans
  • Resend — transactional email delivery
  • Finnhub, Yahoo Finance — market data feeds
  • OpenAI — AI-powered summaries and analysis (paid tiers only)

4. Your rights

You can export all your data as CSV from the Export page. You can delete your account from Settings — all your data is permanently removed within 7 days.

EU residents: you have GDPR rights to access, rectify, port, and delete your data. Email support@thastock.com and we'll respond within 30 days.

5. Cookies

We use a single httpOnly session cookie (tf-session) to keep you logged in. No analytics cookies, no advertising cookies.

6. Children

Thastock is not directed to children under 13. We do not knowingly collect data from anyone under 13.

7. Changes

If we change this policy materially, we'll email all account holders before it takes effect.

8. Contact

Questions? support@thastock.com