← Back to ImpliedLens
Legal

Privacy Policy

Effective date: June 1, 2025  ·  Last updated: June 1, 2025

Short version: We collect the minimum data needed to run the platform. We don't sell your data. We use it to serve you, improve the product, and process payments. That's it.

1. Who We Are

ImpliedLens ("we," "us," "our") is a stock analysis platform operated as an independent service. You can reach us at support@impliedlens.com.

2. Information We Collect

Account data — When you create an account, we collect your username, email address, and a hashed password. We never store your password in plain text.

Usage data — We log anonymized events such as which sections you visit, analyses you run, and conversion funnel steps (e.g., upgrade modal views). These events are tied to your session ID and, if logged in, your account ID. They are used exclusively for product improvement.

Saved analyses — Any analyses you save to your account are stored in our database. You can delete them at any time from the account panel.

Payment data — Payments are processed by Stripe. We store your Stripe customer ID and subscription ID, but we never see or store your card number or billing details — those go directly to Stripe.

Log data — Our servers automatically record IP addresses, browser user agents, and request timestamps for security and abuse prevention. These logs are rotated and not linked to your account for analytics purposes.

3. Cookies and Sessions

We use a single session cookie (il.sid) to keep you logged in. This cookie is httpOnly, SameSite: lax, and marked Secure in production. We do not use advertising cookies, tracking pixels, or third-party analytics scripts.

4. How We Use Your Data

5. Data Sharing

We do not sell, rent, or trade your personal data. We share data only with the following service providers, and only to the extent needed to operate the platform:

We may disclose data if required by law or to protect against fraud and abuse.

6. Data Retention

Account data is retained for as long as your account is active. If you delete your account, we remove your personal data within 30 days. Aggregated, anonymized analytics events may be retained indefinitely as they cannot be traced back to you.

7. Your Rights

You have the right to access, correct, or delete your personal data at any time. You can manage most of this from the account settings panel. To request full account deletion or a data export, email support@impliedlens.com.

If you are in the European Economic Area, you have additional rights under the GDPR, including the right to data portability and the right to lodge a complaint with a supervisory authority.

8. Security

Passwords are hashed with bcrypt. All connections use HTTPS with TLS. We enforce HTTP-only cookies, CSRF tokens on all state-changing requests, and a strict Content Security Policy. We take reasonable technical measures to protect your data, but no system is perfectly secure — we will notify you promptly if a breach affects your account.

9. Children

ImpliedLens is not directed at children under 13. We do not knowingly collect data from anyone under 13. If you believe we have, please contact us immediately.

10. Changes to This Policy

We will post updates to this page with a revised "last updated" date. Continued use of the platform after changes constitutes acceptance of the updated policy.

11. Contact

Questions? Email support@impliedlens.com.