Version 1.0·Updated 2026-08-13

Privacy Policy

PLACEHOLDER — REQUIRES LEGAL REVIEW

This wording is a product draft for MVP launch preparation. It is not legal advice and has not been reviewed by a qualified lawyer. Replace the text in the legal content files before public launch.

This Privacy Policy is a structural draft. It has not been reviewed by a qualified lawyer. It is not a statement of legal compliance.

Investment Coach does not offer user accounts in the MVP. We do not ask for your name, email, password, or portfolio.

What information we collect

The MVP is designed so you can use company analysis without creating an account.

We do not collect names, email addresses, financial account details, portfolio holdings, or passwords through the product UI.

  • Legal acknowledgement: when you agree to the Terms, Privacy Policy, and Disclaimer, we store an anonymous consent record (timestamp, document versions, consent type, and a random identifier).
  • Optional product analytics (only if you opt in): anonymous usage events described below.
  • Company analysis requests: the ticker and market you ask us to analyse are sent to our backend so scores can be generated.
  • Optional Investor View: if you share how you feel about a company, we store an anonymous perception response (sentiment, business trend, valuation lean, confidence, optional short comment, and a random session/visitor id). No account is required. Individual comments are not shown publicly — only aggregated totals above sample thresholds.
  • Optional AI Coach messages: if you use AI Coach, your questions and the packaged educational analysis context are sent to our backend, and may be sent to a language-model provider when that feature is configured.

Information automatically collected

If you opt in to anonymous product analytics, the browser may send usage events to our backend. Those events can include:

  • A random visitor identifier stored in local storage (not your name).
  • A random session identifier stored in session storage.
  • Page path (for example /about or /coach).
  • Selected market (ASX or US) and searched ticker symbols.
  • Coarse device class (mobile / tablet / desktop) and browser family derived from the user agent.
  • A coarse region hint derived from the browser timezone (for example Australia/). This is not IP geolocation.

IP address and device information

Application code does not store IP addresses in the product analytics or consent databases.

PLACEHOLDER — REQUIRES LEGAL REVIEW: web servers, hosting providers, and reverse proxies commonly record IP addresses in operational access logs. Retention of those logs depends on the hosting setup and must be confirmed before public launch. This policy does not claim that no IP address is ever processed at the infrastructure layer.

Pages viewed

With analytics opt-in, we record page_view events with the URL path so we can see which screens are used.

Search activity and company / ticker searches

With analytics opt-in, we record when a company is searched and when an analysis or comparison is viewed, including ticker symbols and (where available) a company name or sector label returned by the analysis.

Separately, analysing a company always sends the ticker to our backend — that is required for the educational analysis to run, whether or not analytics is enabled.

Usage analytics

Optional analytics exist so the operator can learn which lessons, scores, and sections people open — not to identify individuals.

Events can include: session start/end, scroll depth milestones, market selection, score clicks, education content opened, metric explanations opened, section opened, comparison performed, AI Coach usage, legal/disclaimer page views, and (when such links exist) external company-website clicks.

Analytics are not turned on until you opt in. You can change this later from Privacy choices in the footer.

Cookies

The MVP does not set third-party advertising cookies.

The browser’s local storage and session storage are used for essential product preferences (theme, selected market, logo cache) and, after acknowledgement, the consent record. Analytics identifiers are written only if you opt in to analytics.

PLACEHOLDER — REQUIRES LEGAL REVIEW: whether local storage is treated as a “cookie” under applicable law should be confirmed by counsel.

Purpose of collecting data

We use the information above to:

  • Provide the educational analysis you requested.
  • Remember that you acknowledged the current document versions.
  • Improve which educational content and product areas need more time and clarity (analytics opt-in only).
  • Build anonymous, aggregated Investor View perception stats (optional submissions only).
  • Operate founder-level product metrics on an internal dashboard (analytics events only; admin-gated).

Third-party analytics providers

The MVP does not currently send analytics to Google Analytics, Mixpanel, Amplitude, or similar third-party product-analytics vendors.

Events are posted to our own backend and stored in a local database. The frontend uses an AnalyticsService abstraction so a vendor could be added later — that would require an updated privacy notice and, where required, consent.

Data storage

Consent records, analytics events, and Investor View responses are stored on the application backend (SQLite files under the server data directory in the current architecture).

Company analysis results are generated on demand and are not stored as a user history in the MVP (there is no login or saved portfolio).

Data retention

PLACEHOLDER — REQUIRES LEGAL REVIEW: a formal retention schedule has not been set.

Until then, analytics events and consent records remain in the backend database until the operator deletes them. Browser storage remains until you clear site data or withdraw analytics consent (analytics identifiers).

Security

We use standard web transport (HTTPS in production deployments) and keep API keys on the server, not in the public frontend.

PLACEHOLDER — REQUIRES LEGAL REVIEW: this is not a certification of security standards. Production hosting, backups, and access control must be reviewed before launch.

User rights

PLACEHOLDER — REQUIRES LEGAL REVIEW: applicable privacy rights (access, deletion, complaint processes) depend on jurisdiction and must be completed by counsel.

In the product today you can: decline analytics, later change analytics via Privacy choices, and clear site data in your browser. Because there is no account, we cannot look up a person by name or email.

How users can contact us

Operator: [LEGAL ENTITY NAME — PLACEHOLDER]

Privacy contact: [CONTACT EMAIL — PLACEHOLDER]

Third-party services

When you analyse a company, our backend requests financial data from Yahoo Finance using the ticker you entered.

When you use AI Coach and a model key is configured, conversation content and educational analysis context may be processed by OpenAI.

Those providers have their own terms and privacy policies. We do not control how they independently process data.

International data transfers

PLACEHOLDER — REQUIRES LEGAL REVIEW: Yahoo Finance and OpenAI may process data outside your country. Hosting location for this application is not specified in this draft.

Do not assume a particular hosting region until the operator documents it.

Changes to this privacy policy

This policy is version 1.0. Substantial changes increment the version. Users who acknowledged an older version can be asked to acknowledge the new one.

Educational and informational only — not personal financial advice and not a recommendation to buy, sell, or hold securities. Investment Disclaimer