1. Who this policy covers
Copinance (“Copinance,” “we,” “us”) is the controller of personal data collected through copinance.com and the Copinance application, except where a third party acts as an independent controller under its own notice. Questions or privacy requests can be sent to [email protected].
Third-party websites and services may process personal data as independent controllers under their own notices. This includes Google sign-in, Google Analytics when enabled, and the AI provider selected for a Coach request.
2. Data we collect
- Account data: Google account identifier, email address, name, profile image, sign-in events, account role, and account status. Copinance does not receive your Google password.
- Preferences and workspace data: financial-literacy level, interface scale, theme, watchlist symbols, saved workspace settings, selected symbols, and weekly digest records.
- Coach and AI data: prompts, messages, selected model, page and market context, tool events, generated answers, and attachments you choose to submit. When you use Coach, Copinance saves this information as conversation history so you can list and resume past conversations.
- User-supplied AI credentials:if you choose to save an AI-provider API key, the backend encrypts the full key before storing it in the account database. The encryption secret is supplied to the deployment separately from the database. We also store the provider name and a masked preview containing only the key's final four characters so you can identify the credential. After saving, the app and credential API return only that preview, not the full key. The backend decrypts the key when needed to authenticate a request to your selected provider. You can replace or remove a saved key from Profile. Encryption reduces the risk of database exposure, but it cannot eliminate every security risk.
- Technical and security data: IP address, request identifiers, timestamps, browser and device information, error and security events, and server logs.
- Membership data: selected plan, subscription and customer identifiers, subscription status and billing-period dates, and complimentary-access records. Payment card details are collected and handled by our payment processor, not Copinance.
- Optional analytics data: page visits, approximate location, device and browser characteristics, and interaction events. Google Analytics is not loaded unless you allow analytics cookies.
- Communications: information you include when contacting us or responding to a service message.
We do not ask for brokerage credentials, payment-card data, government identifiers, or details about your actual trades, holdings, income, net worth, objectives, or risk tolerance. Copinance is not designed to build an investor profile or provide personalized financial advice. Please do not put sensitive personal information in Coach prompts or attachments.
3. Why we use it
- Provide sign-in, account security, saved preferences, watchlists, and requested features.
- Ground Coach responses in the page and market context you choose to send.
- Generate and, where enabled, save conversations and weekly educational digests.
- Operate, debug, secure, measure, and improve the service.
- Prevent abuse, enforce our Terms, and comply with legal obligations.
- Send transactional service email when enabled. We do not sell mailing lists.
Where applicable law requires a lawful basis, we process personal data only on an applicable legal ground. Depending on the purpose, this may include providing the account or feature you requested, protecting the security and integrity of the service, complying with legal obligations, or obtaining your consent for optional analytics. Where we rely on consent, you may withdraw it at any time without affecting processing already carried out lawfully.
4. AI processing deserves special clarity
Do not use Coach for confidential, legally privileged, medical, or highly sensitive personal information. AI output can be incomplete or wrong. Copinance does not use Coach to make legal, employment, credit, insurance, investment-suitability, or other decisions with legal or similarly significant effects about you.
6. International transfers
Providers may process data in locations other than where you live. The transfer mechanism depends on the provider, destination, and applicable law. Where required, transfers must use a legally recognized mechanism and appropriate contractual, technical, or organizational safeguards. Contact us for information about safeguards relevant to your data.
7. How long we keep data
- Active account, watchlist, preference, digest, and encrypted credential records are kept while the account is active and as needed to provide the service.
- Subscription identifiers, status history, complimentary grants, and webhook receipts may be retained for billing reconciliation, fraud prevention, disputes, and legal or accounting obligations.
- Deleting a conversation archives it and schedules it for automatic deletion after 30 days. Messages, tool events, and analysis records associated with it receive the same deletion schedule.
- Security logs, revoked-token records, caches, and backups are kept for limited periods based on operational and security needs, then rotated or overwritten.
- Google Analytics stores analytics information under Google’s applicable controls and retention settings. The analytics cookies set through this application are configured for no more than 180 days.
We periodically review retention and aim not to keep identifiable data longer than its stated purpose requires.
8. Your choices and rights
Depending on where you live and subject to legal exceptions, you may have rights to know whether and how we process your data; access, correct, delete, port, or restrict it; know recipients; object to certain processing; challenge certain decisions based solely on automated processing; withdraw consent; and complain to an appropriate data-protection authority.
You can change profile preferences, remove saved AI keys, delete individual conversations, or deactivate your account in the app. For a copy, correction, objection, or full erasure request, email [email protected]. We may need to verify that the account is yours. Authorized agents may submit requests where local law permits. We will not discriminate against you for exercising a privacy right.
You can reject or withdraw optional analytics at any time through Cookie preferences. Browser controls can also clear locally stored preferences, although doing so may sign you out or reset the interface.
9. Security and children
We use safeguards designed for the nature of the service, including encrypted transport, HttpOnly session cookies, CSRF protection, access controls, and encryption of saved AI credentials. No internet service can promise absolute security. If you believe your account is at risk, sign out and contact us promptly.
Copinance is intended for adults and is not directed to children under 18. We do not knowingly collect personal data from children. A parent or guardian who believes a child has provided data should contact us so we can investigate and delete it.
10. Changes and contact
We may update this policy as the product or law changes. We will change the date above and provide a more prominent notice when a change materially affects your rights or how data is used.
Privacy questions and requests: [email protected].