Privacy Policy

Effective Date: July 9, 2026

1. Introduction

Grahamly (“we”, “our”, “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our website at grahamly.io and use our stock analysis application (collectively, the “Service”). For the purposes of the General Data Protection Regulation (GDPR), Grahamly is the data controller of your personal data.

2. Information We Collect

We collect several categories of information to provide, maintain, and secure our Service:

  • Account Information: When you register an account, we collect your name, email address, and password hash.
  • Portfolio and Financial Data: We process any asset names, tickers, transaction dates, or holdings you enter. We do not connect to your live brokerage accounts, request brokerage credentials, or process direct transaction accounts.
  • API Keys (BYOK): If you utilize our Bring Your Own Key functionality, we collect and store your API keys (e.g., OpenRouter). These keys are encrypted in transit and at rest using AES-256 and are only decrypted server-side for API requests.
  • Technical and Usage Data: We automatically collect log file data, IP addresses, browser types, operating systems, referral URLs, pages viewed, and access times.

3. Legal Basis for Processing (GDPR Compliance)

If you reside in the European Economic Area (EEA), we process your personal data under the following legal bases:

  • Performance of a Contract: To set up your account, deliver portfolio analyses, charge subscription fees, and process user support inquiries.
  • Consent: For using analytical cookies, processing cookies through our consent banner, or subscribing to direct marketing newsletters.
  • Legitimate Interests: To improve our agentic models, detect fraudulent activities, ensure network security, and perform platform administration.
  • Legal Obligation: To comply with tax laws, statutory reporting requirements, or court orders.

4. How We Use Your Information

We use the collected information for the following business purposes:

  • To initialize, execute, and verify the multi-agent debate simulations on your selected stock tickers.
  • To deliver daily pre-market portfolio digests and email alerts.
  • To manage payments, subscriptions, and process cancellations.
  • To optimize application performance, debug server runtime errors, and update security frameworks.

5. Cookies & Tracking Technologies

We use essential, analytical, and performance cookies to track user behavior on our Site. Essential cookies are necessary to maintain active sessions, verify login states, and prevent security breaches.

Analytical cookies (such as Google Analytics) are used to aggregate visitor traffic, session duration, and click metrics. You can configure your preferences or decline analytical cookies at any time via our Cookie Consent Banner or by adjusting your local browser cookie settings.

6. Data Sharing & Sub-Processors

We do not sell, rent, or trade your personal data. We share your information with trusted third-party sub-processors who perform services on our behalf, including:

  • Supabase: Auth and database hosting provider.
  • OpenRouter / LLM Providers: For processing AI agent queries when you choose not to use BYOK.
  • Vercel: Next.js app deployment and content delivery network.
  • Lemon Squeezy: Payment processing and invoice management.
  • Redis / Upstash: Real-time caching for agent reasoning and market feeds.

All sub-processors are contractually bound under Data Processing Addendums to maintain bank-grade confidentiality and security.

7. International Data Transfers

Because Grahamly utilizes server clusters located in the United States and other global hosting zones, your personal data may be transferred to, stored, and processed outside your country of residence. For transfers of personal data from the EEA or Switzerland to countries that do not have an adequacy decision, we ensure the implementation of Standard Contractual Clauses (SCCs) approved by the European Commission to ensure data is protected with equivalent standards.

8. Data Retention

We retain your personal data only as long as necessary to fulfill the purposes for which it was collected, including for the duration of your active subscription and to comply with legal, tax, or accounting requirements. Upon subscription termination or account deletion, we delete or anonymize your personal data within thirty (30) days, except where statutory retention regulations require longer storage.

9. Data Security

We implement comprehensive physical, technical, and administrative security protocols. All traffic is encrypted in transit using Transport Layer Security (TLS 1.3), and database tables are encrypted at rest using AES-256. All BYOK credentials are secured using database level encryption. While we strive to protect your personal data, no method of transmission or electronic storage is 100% secure, and we cannot guarantee absolute security.

10. Your Rights Under GDPR (EEA Residents)

If you reside in the EEA, you have the following data protection rights:

  • Right to Access: You can request copies of your personal data.
  • Right to Rectification: You can request that we correct inaccurate or incomplete information.
  • Right to Erasure (“Right to be Forgotten”): You can request that we delete your personal data under certain conditions.
  • Right to Portability: You can request that we transfer your collected data directly to another controller.
  • Right to Object or Restrict: You can object to or request the restriction of our processing of your data.
  • Right to Lodge a Complaint: You have the right to complain to an EU Data Protection Authority.

11. Your Rights Under CCPA/CPRA (California Residents)

If you are a resident of California, you possess specific rights regarding your personal information:

  • Right to Know: You can request disclosure of the categories and specific pieces of personal information collected.
  • Right to Delete: You can request deletion of your personal information.
  • Right to Opt-Out: Grahamly does not sell or share your personal information. If we ever modify this policy, you will have the right to opt-out.
  • Right to Non-Discrimination: We will not deny services or change prices if you exercise any CCPA rights.

12. Children's Privacy

Grahamly is not designed for or targeted to individuals under the age of 18. We do not knowingly collect, request, or process personal data from children. If we become aware that we have inadvertently collected personal data from a child under 18 (or the local equivalent age of consent), we will take immediate steps to delete that data from our servers.

13. Enterprise Accounts & Data Processing Agreement (DPA)

For enterprise and institutional customers where Grahamly acts as a data processor, the processing of personal data under your organization's active subscription is governed by our separate Data Processing Agreement (“DPA”). The DPA details our obligations regarding sub-processors, security audits, data breach notifications, and international transfer mechanisms.

14. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the “Effective Date” above. You are advised to review this page periodically for any changes.

15. Contact Information

If you have any questions, comments, or wish to exercise any of your privacy rights, please contact us at:

Grahamly Privacy Officer

Email: [email protected]