← openbias.io

Privacy Policy

Last updated: July 19, 2026

1. Controller

OpenBias, France. Contact: support@openbias.io.

2. What we collect

Account data: email address, hashed authentication data, chosen locale. Billing data: subscription tier and status via Stripe (we never receive or store full card numbers). Usage data: pages/endpoints accessed, instrument/timeframe selections, timestamps, IP address, device/browser type — used for security, rate-limiting, and product analytics. Support data: messages you send us. We do not collect special-category data and do not use the Service to profile you for automated decisions with legal effect.

3. Purposes & legal bases (GDPR art. 6)

Providing the Service and your account — contract (6(1)(b)). Billing and tax records — legal obligation (6(1)(c)). Security, abuse prevention, rate-limiting, service analytics — legitimate interests (6(1)(f)). Product emails about your account/service changes — contract; optional marketing only with consent (6(1)(a)), withdrawable anytime.

4. Processors & recipients

Supabase (database & auth, EU region eu-west-1) · Stripe (payments) · Railway (backend hosting) · Vercel (frontend hosting) · Sentry (error monitoring) · Twelve Data (market data — receives no personal data) · xAI (algorithmic confirmation layer — processes market data only, no personal data). Processors are bound by data-processing agreements; where data leaves the EEA, transfers rely on adequacy decisions or Standard Contractual Clauses.

5. Retention

Account data — for the life of the account and up to 12 months after deletion request completion for security/audit logs; billing records — as required by French tax law (up to 10 years); anonymized/aggregated statistics — indefinitely (no longer personal data).

6. Your rights

Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Email support@openbias.io — we respond within 30 days. Erasure: your account and personal data are deleted; anonymized calibration statistics are retained. You may lodge a complaint with CNIL (cnil.fr) or your local supervisory authority.

7. Cookies & local storage

We use only essential cookies/local storage for authentication and session state. No third-party advertising cookies.

8. Security

TLS in transit, encrypted storage at rest (Supabase), row-level security, least-privilege access, secret scanning, and monitored infrastructure. No method is 100% secure; report concerns to support@openbias.io.

9. Children

The Service is not directed to persons under 18.

10. Changes

Material changes will be announced in-product or by email.