Privacy Policy

Last updated 18 August 2026

Who we are

InsiderPulse is operated by Ayse Burcu Aytekin, based in Ontario, Canada, who is the data controller for the personal information described below. Privacy requests go to support@insiderpulse.co.

The short version

We collect your email address so you can sign in, so we can bill you, and — if you ask for it — to send the free Insider Brief. We do not sell your data and we do not run advertising or cross-site tracking. We measure how the site is used with a cookieless analytics tool that is not tied to your account, and we do not track what you search for inside the app.

What we collect

  • Email address — required for sign-in, account confirmation, password resets and billing receipts. Sign-in and reset emails are delivered by Resend on our behalf.
  • Insider Brief signups without an account — the email address you enter, whether you confirmed it, when, and the page you signed up from (including a campaign tag such as ?ref=tiktok if the link you followed had one). Used only to send the brief. Nothing but one confirmation email is sent until you click its link, and every brief carries a one-click unsubscribe.
  • Your password — stored only as a salted hash by our authentication provider (Supabase). We never see, log or store the password itself, and it cannot be recovered — only reset.
  • Subscription status — whether you have an active plan, which plan, and when the current period ends.
  • A Stripe customer identifier — so we can link your account to your subscription.
  • Usage analytics — which pages are viewed, plus a few product events such as opening the upgrade screen or reaching checkout. Collected by Vercel Web Analytics without cookies and without any persistent identifier, so these measurements are not linked to your account or to you as an individual. We do not attach your email, your user ID or your watchlist to them. If you arrived through a tagged link (?ref=), that tag is remembered for the browser session only and counted with these events.
  • Server logs and abuse prevention — IP address and request metadata, used to diagnose outages and to enforce the rate limits that keep the service available.

We never receive or store your card number, CVC or billing address. Those go directly to Stripe from their hosted checkout page.

What stays in your browser

Your watchlist, filter preferences and alert toggle are stored in your browser's local storage and are never transmitted to us. Clearing your browser data removes them.

Who we share it with

We use a small number of processors, each for one job:

  • Supabase — authentication and database hosting.
  • Stripe — payment processing and subscription management.
  • Resend — delivery of account and notification email.
  • Vercel — application hosting and cookieless usage analytics.
  • Cloudflare — the bot check on the sign-in and sign-up forms. It sees your IP address and browser characteristics in order to tell a person from an automated script, and nothing else about you. It runs only on those forms, never on the rest of the site.

We do not sell or rent personal data, we do not share it for advertising, and we do not disclose it to anyone else except where the law requires it or where it is necessary to establish or defend a legal claim.

Where your data is processed

We are based in Ontario, Canada, but our processors operate infrastructure in the United States and other countries. Your personal information is therefore stored and processed outside Canada, and while it is there it may be accessible to the courts, law enforcement and national security authorities of those countries under their own laws. We use providers that offer standard contractual protections for international transfers, but we cannot exempt data from foreign legal process.

How we protect it

Traffic is encrypted in transit over HTTPS, passwords are salted and hashed by our authentication provider, card details never reach our servers, and administrative access to the database is restricted to the operator. No system is perfectly secure, so we do not claim ours is; if a breach affects your personal information we will notify you and the relevant regulator where the law requires it.

Data we read but do not own

Filing, news and price data comes from SEC EDGAR, the Federal Reserve and public market feeds. Those are public sources and contain no information about you.

Retention

Account data is kept for as long as your account exists. Ask us to delete your account and we will remove your profile and email address within 30 days; Stripe retains transaction records separately for the period financial and tax rules require, and we cannot delete those on your behalf. An Insider Brief signup without an account is kept, marked unsubscribed, after you opt out, so a forwarded old link cannot sign you back up unnoticed; ask and we will delete it outright. Server logs and rate-limit counters are short-lived and are discarded automatically. Analytics measurements are aggregate and are not tied to you, so there is nothing in them to delete.

Your rights

Depending on where you live — including under Canada's PIPEDA, the GDPR and the CCPA — you may have the right to access, correct, export or delete your personal data, to withdraw consent, and to object to certain processing. Write to support@insiderpulse.co and we will respond within 30 days. Exercising these rights costs nothing, and we will not degrade your service for doing so.

If you are not satisfied with our response you may complain to your data protection regulator — in Canada the Office of the Privacy Commissioner, and in the EU or UK your national supervisory authority.

Cookies

We set a session cookie so you stay signed in, and Stripe sets cookies on its own checkout pages for fraud prevention. Our analytics is cookieless. We do not use advertising or cross-site tracking cookies, which is why you are not asked to accept a consent banner.

Children

InsiderPulse is a financial research tool intended for adults and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us their information, write to us and we will delete it.

Changes to this policy

We may update this policy as the service changes. The date at the top of this page always reflects the current version. If a change materially affects how we handle your personal information we will tell you by email or in the app before it takes effect, rather than relying on you to re-read this page.

Keep this page true: this document is a good-faith description of what the software actually does, not legal advice. Every processor currently in use is listed above. Adding one — a marketing email tool, an error tracker, an ad pixel, a support widget — changes this page too, and the two belong in the same commit. Describing a system you no longer run is a compliance problem in itself.

Terms of Service·Back to the dashboard