Privacy Policy
What is stored, why, for how long, and who else can see it.
The short version
We store the email address you sign up with, the models you save, and a security log. We do not sell data, do not run advertising trackers, and do not use your models to train AI. Card details never touch this service, Paddle handles payment and we only ever see that a subscription exists.
Who is responsible for it
The data controller for everything described on this page is Almaz Abdullayeva, reachable at support@valuatio.co, with a postal address available on request. Paddle is a separate controller for payment data, and its own privacy policy governs that.
What we collect
- Account: email address, and either a password hash or a Google account identifier. Passwords are stored as salted, peppered PBKDF2 hashes and cannot be read back.
- Your name and date of birth, asked once after you sign in. Your name is what a credential we issue is made out in. Your date of birth identifies the holder of that credential and confirms you are old enough to agree to the Terms. Neither is shown to anyone else, and your date of birth is never printed on a certificate or on its public verification page.
- Your work: models you save, their version history, share links you create, monitors you arm, and assessment attempts.
- Billing: a Paddle customer and subscription identifier, your plan, and its renewal date. Not your card, not your billing address.
- Security log: authentication events, plan changes and refusals, with IP address and user agent stored only as keyed one-way digests, correlatable across events, not reversible into an address.
- Founding cohort applications, if you apply for a place: the name, email address and paragraph you send us, plus the same keyed digests as the security log. Kept whether you are accepted or not, so the same address cannot silently apply twice, and erased on request.
- A count of visits to the founding cohort page: the date and the same keyed one-way digest of your IP address as the security log, one row per address per day and nothing else. It exists so we can tell whether that page is being read, it identifies nobody, and because addresses are shared and reassigned it is a rough count rather than a count of people.
- Nothing else. There is no analytics script, no advertising pixel, and no third-party cookie on this site. The visit count above is our own server counting its own traffic, not a tracker.
Why we are allowed to hold it
- To perform the contract: your account, your models, and delivering the plan you paid for. Your name and date of birth sit here too: a credential has to name and identify its holder, and the Terms have to be agreed by somebody able to agree to them.
- Legitimate interest: keeping the service secure and preventing abuse, this is what the security log is for, and why it holds digests rather than raw identifiers.
- Your own request: a founding cohort application exists because you sent it. If you are accepted and you finish the track, your name and credential ID appear on the founding page, which you agreed to when you applied and can withdraw at any time by writing to us.
- Legal obligation: Paddle retains transaction records for tax purposes under its own policy.
Who else processes it
- Cloudflare: hosting, edge network and the database holding your account and models.
- Paddle: payment, invoicing and tax. Paddle is a separate controller for payment data; its own privacy policy governs that.
- Google: only if you choose to sign in with Google, and only to verify your identity and email.
- Anthropic: when you generate an AI thesis, the model summary is sent to produce it. It carries valuation figures, not your identity, and is not used for training.
- A mail provider: only to deliver Thesis Monitor alerts you asked for.
- SEC EDGAR and market-data vendors receive the ticker you are researching, and nothing about you.
How long it is kept
- Account and models, including your name and date of birth: until you delete them or close your account. Closing the account removes them.
- Deleted models: soft-deleted immediately (their share links stop working at once) and removed entirely within 30 days.
- Security log: 90 days, then purged automatically.
- Billing records: retained by Paddle for as long as tax law requires.
Share links
A share link publishes one version of one model to anyone holding the link. The link contains a 256-bit secret and only its hash is stored, so we cannot reconstruct a link you have lost, and neither can anyone who obtains a copy of the database. Revoking a link stops it resolving immediately. A shared page is marked no-index so it does not enter search results, but treat any link you send as public.
Deleting your account
You can erase your account yourself, from Account, at any time and without asking us. It is immediate and permanent: your models, version history, share links, course progress, drill attempts, monitors, name, date of birth and email address are all destroyed, and so is any certificate or credential you have earned, which means its verification page stops working for anyone you have given the link to. There is no grace period and we cannot undo it. Deleting your account does not cancel a paid subscription, so cancel that first from Manage billing.
Your other rights
Beyond deletion, you have the right to access, correct, export and restrict your personal data, and to object to processing based on legitimate interest. Email support@valuatio.co and we will act within 30 days. You may also complain to your local data-protection authority. These rights are not limited to the UK and EU: wherever you live, we will honour the same requests.
What survives a deletion, and why
The security log. It holds authentication events, plan changes and refusals, with your IP address and user agent stored only as keyed one-way digests that cannot be reversed into an address. It is kept on legitimate interest, to detect and investigate abuse, and it does not identify you once the account it referred to is gone. The record that a deletion happened is also kept, with nothing in it about who made it.
Cookies
One cookie: an HttpOnly session token that keeps you signed in. It carries no profile, no claims and nothing readable by JavaScript. There is no consent banner because there is nothing to consent to, a strictly necessary session cookie does not require one, and there is no other kind here.
Children
This service is not directed at children and accounts are not knowingly created for anyone under 18. If you believe a child has created an account, tell us and it will be removed.