Privacy policy
What Schmatz collects, why it is used, which service providers process it, how long it is kept, and how to access or delete it. We do not sell personal information or use it for advertising.
Scope
This policy applies to the Schmatz website, account and sign-in flows, stock and index pages, the Lab and research copilot, contact forms, account settings, and billing if a paid plan applies. It covers information you provide, information created through your use of the service, and limited technical information needed to operate and protect it.
What we collect
Account and profile information
- Email address — required for account creation, sign-in, and important account messages
- Name, username, and profile image — supplied by you or, if you choose Google sign-in, returned by Google
- Authentication records — account identifiers, provider linkage, email-verification timestamps, session state, terms-acceptance records, and optional two-factor settings
- Legacy phone field — an older beta flow could store a phone number; the current product does not request phone numbers and does not send SMS
Research and account content
We store content needed to provide account features, including watchlists, trackers, saved backtest summaries, research questions and answers, survey responses, in-app updates, feedback, and support or contact messages. Some features save automatically so you can reopen recent work; the interface identifies controls that save, clear, or delete information.
Usage and security records
Schmatz records events such as feature use, API calls, route or ticker context, timestamps, success or error state, and limited request metadata. These records support daily entitlement limits, debugging, abuse prevention, and aggregate product decisions. The public contact form may process an IP address and user agent for rate limiting and security. The retired access-request form stored the same fields with historical submissions. Normal infrastructure logs may also contain IP addresses, request paths, and timestamps.
The Command Desk analytics layer stores structured facts such as a pseudonymous actor identifier, feature area, intent category, prompt-length bucket, outcome, latency, token and cache counts, and source state. It does not store raw prompts, email bodies, passwords, API keys, brokerage information, raw market data, or private tool payloads. The separate operator support mailbox is not used for product analytics or prompt clustering.
Billing information
Public checkout is currently disabled. If billing applies, Stripe processes payment details. Schmatz stores identifiers and event records needed to associate a subscription with an account, handle renewals or cancellations, and maintain financial records. Schmatz does not receive or store full card numbers.
AI-assisted features
When you use an AI-assisted research feature, your question and selected research context may be sent to Anthropic to generate a response. Schmatz may store the question, answer, tool activity, and usage metadata so the result can be displayed again and audited. Do not include confidential, account-password, brokerage, or other sensitive personal information in a research prompt.
Information we do not request
- Brokerage credentials, portfolio positions, or trading history
- Social security numbers or government identification numbers
- Health, biometric, or precise-location data
- Passwords — sign-in uses email magic links or Google OAuth
Why we use it
- Provide the service — authenticate accounts, run requested research, save account content, and display results
- Operate safely — enforce limits, prevent abuse, investigate errors, secure accounts, and maintain audit records
- Improve the product — understand which features are used and prioritize reliability and usability work
- Communicate — deliver sign-in links, respond to messages, and send important account or policy notices
- Billing and legal obligations — administer any paid subscription, keep required records, and respond to lawful requests or protect legal rights
Service providers
Account and research data is primarily stored in Schmatz’s SQLite database on U.S.-based infrastructure. Limited data is also processed by providers that perform specific functions for us:
- Resend — transactional email delivery
- Google — authentication, only if you choose Google sign-in
- Anthropic — AI-assisted research responses
- Stripe — checkout, subscriptions, and payments if billing applies
- Hosting, proxy, and backup providers — delivery, security, and recovery
These providers process data under their own terms and privacy policies. We do not authorize them to use Schmatz personal information for advertising on our behalf.
Retention
- Account and user-created content — retained while the account is active or until you clear or delete it
- Usage records — retained for product, security, and entitlement purposes; raw Command Desk events are normally retained for 30 days and privacy-safe aggregate rollups for up to two years, subject to operational and legal needs. Account-linked events can be cleared through the available account tools
- Contact messages and legacy access requests — retained while the message is reviewed and afterward as reasonably needed to document the response, prevent abuse, or comply with law
- Billing records — retained or anonymized as needed for financial, fraud-prevention, and legal obligations
- Backups — deleted account information may remain in rotating backups until those backups expire and will not be restored except as part of disaster recovery
Your choices and rights
Regardless of where you live, you may ask us to:
- Provide a copy of personal information associated with your account
- Correct inaccurate profile information
- Delete your account and associated personal information, subject to limited exceptions
- Stop non-essential email communications
- Choose privacy-safe analytics or necessary-only processing
- Separately opt in or out of redacted research samples; this is off by default
Use Settings → Data & Privacy to export account data, clear activity, or delete the account. For anything else, submit a privacy request or email [email protected]. We may verify a request using the email on file before disclosing or deleting account information.
California residents — CCPA / CPRA
Schmatz does not currently believe it meets the statutory thresholds that make it a covered business under the CCPA. As a matter of practice, however, California residents may request access, deletion, or correction and may ask how personal information is collected and disclosed. Schmatz does not sell personal information or share it for cross-context behavioral advertising, and it does not knowingly use sensitive personal information for purposes that require a right to limit.
Submit a request through the contact form or email above. If the CCPA applies to a request, we will respond within 45 calendar days and may extend that period as the law permits after giving notice. We will not discriminate against you for exercising a privacy right. See our do-not-sell notice.
Children and eligibility
Schmatz is intended for adults and the Terms require users to be at least 18. We do not knowingly collect personal information from a child under 13. If you believe a minor has created an account or provided personal information, contact us so we can investigate and delete it where appropriate.
Cookies and local storage
Auth.js uses strictly necessary cookies for sessions, request protection, and sign-in flows. Schmatz does not use third-party advertising or analytics cookies. Browser local storage keeps display, consent, and in-app preference settings. See the cookies notice.
International use
Schmatz is operated from the United States, stores and processes information in the United States, and is directed to U.S. users. It is not currently offered as a service specifically directed to the European Economic Area or United Kingdom. Privacy protections in the United States may differ from those in your location.
Security and incidents
We use reasonable administrative and technical measures appropriate to this early-stage service. No system is perfectly secure. If an incident affects personal information, we will investigate, contain it, and notify affected people and authorities when required by applicable law. See the security overview.
Changes to this policy
We may update this policy as the product and its providers change. We will revise the date above and provide an appropriate in-app or email notice before a material change when required by law.
Contact
Send privacy questions and requests through the privacy contact form or email [email protected].