Privacy Policy
Last updated: July 19, 2026
1. Controller
OpenBias, France. Contact: support@openbias.io.
2. What we collect
Account data: email address, hashed authentication data, chosen locale. Billing data: subscription tier and status via Stripe (we never receive or store full card numbers). Usage data: pages/endpoints accessed, instrument/timeframe selections, timestamps, IP address, device/browser type — used for security, rate-limiting, and product analytics. Support data: messages you send us. We do not collect special-category data and do not use the Service to profile you for automated decisions with legal effect.
3. Purposes & legal bases (GDPR art. 6)
Providing the Service and your account — contract (6(1)(b)). Billing and tax records — legal obligation (6(1)(c)). Security, abuse prevention, rate-limiting, service analytics — legitimate interests (6(1)(f)). Product emails about your account/service changes — contract; optional marketing only with consent (6(1)(a)), withdrawable anytime.
4. Processors & recipients
Supabase (database & auth, EU region eu-west-1) · Stripe (payments) · Railway (backend hosting) · Vercel (frontend hosting) · Sentry (error monitoring) · Twelve Data (market data — receives no personal data) · xAI (algorithmic confirmation layer — processes market data only, no personal data). Processors are bound by data-processing agreements; where data leaves the EEA, transfers rely on adequacy decisions or Standard Contractual Clauses.
5. Retention
Account data — for the life of the account and up to 12 months after deletion request completion for security/audit logs; billing records — as required by French tax law (up to 10 years); anonymized/aggregated statistics — indefinitely (no longer personal data).
6. Your rights
Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Email support@openbias.io — we respond within 30 days. Erasure: your account and personal data are deleted; anonymized calibration statistics are retained. You may lodge a complaint with CNIL (cnil.fr) or your local supervisory authority.
7. Cookies & local storage
We use only essential cookies/local storage for authentication and session state. No third-party advertising cookies.
8. Security
TLS in transit, encrypted storage at rest (Supabase), row-level security, least-privilege access, secret scanning, and monitored infrastructure. No method is 100% secure; report concerns to support@openbias.io.
9. Children
The Service is not directed to persons under 18.
10. Changes
Material changes will be announced in-product or by email.