StoxSage Privacy Policy

Last updated: October 8, 2025

This Privacy Policy explains how StoxSage ("we") handles limited technical and usage data when you access our educational financial analytics platform. We do not execute trades or collect sensitive financial account data.

1. Core Principles

  • Collect the minimum viable data necessary to operate and improve the platform.
  • No sale of personal data to third parties.
  • Data used only for security, reliability, performance, and product evolution.
  • Transparent disclosure of any future expansion of data categories.

2. Data We Currently Process

CategoryExamplesPurposeRetention
TechnicalIP (truncated/anonymized), user-agent, device typeSecurity, abuse prevention, regional performance routing7–30 days (log rotation)
Usage MetricsPage paths, feature interactions, response timingsCapacity planning & feature prioritization30–60 days (aggregated after)
Error DiagnosticsStack traces (scrubbed), request IDsBug triage & stability improvements90 days

3. Future / Conditional Data (Not Yet Active)

  • User Accounts: Display name, email (for authentication & saved watchlists) – only if you opt‑in when launched.
  • Advertising Identifiers: If we enable contextual or limited personalized ads, a consent banner will precede activation.
  • Portfolio Simulation Inputs: Hypothetical holdings you manually enter – never shared, purge-on-demand.

4. Cookies & Local Storage

  • Session / preference tokens: Theme choice, locale, UI settings.
  • Analytics (future optional): Will require explicit opt‑in.
  • No third‑party marketing pixels currently deployed.

5. Data Processors & Infrastructure

We may utilize reputable cloud and analytics infrastructure. Any sub‑processors added will be listed in a changelog.

6. Your Rights

  • Request access or export (when accounts launch).
  • Request correction or deletion (subject to legal holds).
  • Withdraw analytics / cookie consent (forthcoming UI control).
  • Lodge a complaint with an applicable supervisory authority (EU/UK users).

7. Security Measures

  • Transport Layer Security (TLS) for in‑transit encryption.
  • Principle of least privilege for internal service roles.
  • Automated dependency vulnerability scanning.
  • Selective log redaction & minimal PII footprint.

8. International Access

Data may be processed in the United States or other regions where infrastructure providers operate. We apply protective controls irrespective of jurisdiction.

9. Policy Changes

Material changes: on‑site banner + version note. Minor clarifications: changelog entry only. Your continued use after effective date signifies acceptance.

10. Contact

Privacy inquiries: [email protected]

Summary: We collect minimal operational telemetry today. If we expand scope (accounts, ads, advanced analytics) you will be given clear choice and updated controls first.
Privacy Policy | StoxSage – Data & Usage Transparency