DRAFT — FOR ATTORNEY REVIEW, NOT YET IN EFFECT
This document is a working draft. It has not been published and creates no obligations until reviewed by counsel and posted with an effective date. Remove this banner at publication.
CloverBull Privacy Policy
Effective Date: [EFFECTIVE DATE]
Operator: [COMPANY LEGAL NAME — likely Starion Ecommerce Inc., attorney to confirm] ("CloverBull," "we," "us," or "our")
Contact: [SUPPORT EMAIL — support@cloverbull.com planned]
This Privacy Policy explains what information we collect when you use CloverBull (cloverbull.com), why we collect it, how we handle it, and the choices you have. We have tried to write it in plain English. If anything is unclear, email us at [SUPPORT EMAIL].
1. Who We Are
CloverBull is a stock-screening and market-research web application operated by [COMPANY LEGAL NAME]. It provides pre-computed stock screeners, watchlists, a portfolio tracker, backtesting, market dashboards, and an AI trading coach. CloverBull is an educational and informational tool only — it does not provide investment advice and does not connect to your brokerage account.
2. Information We Collect
We collect only what we need to run the service. Here is the full inventory, organized by category.
2.1 Account Information
- Email address and password. When you sign up with email and password, your password is stored as a secure hash by our authentication provider (Supabase). We never see or store your plain-text password.
- Google sign-in. If you sign in with Google, we receive your email address and basic profile information from Google. We do not receive your Google password.
- Profile and subscription tier. We store your account tier (Scout, Trader, or Champion) and basic profile settings.
2.2 Billing Information
- Payment processing. Payments are handled by Stripe. We never store your card number — your payment details go directly to Stripe, which processes them on our behalf.
- What we keep. We store your subscription status, plan, and billing state (for example: active, canceled, past due), along with an identifier that links your CloverBull account to your Stripe customer record.
2.3 Usage and Content Data
To provide the service's features, we store the content you create in the app:
- Watchlists and the stocks you add to them, including any notes and alert settings
- Portfolio tracker entries (trades you manually log — paper or live journaling; we have no connection to any brokerage)
- Your preferences and settings
- Your chat history with the AI coach (stored so the coach can remember context across conversations)
- Alert and notification settings, including your email digest toggles
2.4 Technical and Error Data
- In-house error tracking. If something breaks in your browser while using CloverBull, we log the error message, stack trace, the page URL, and your browser's user-agent string so we can find and fix bugs. This is our own system — we do not use third-party analytics or error-tracking services (no Google Analytics, no Sentry, and no advertising trackers).
- Sign-in protection. We use Cloudflare Turnstile (a CAPTCHA alternative) on sign-in to block bots. Cloudflare processes that check; see the processor table in Section 5.
- Browser localStorage. We store UI preferences and cached screener data in your browser's localStorage so the app loads faster and remembers your settings. See Section 7.
- Server and hosting logs. Our hosting and database providers (Netlify and Supabase) generate standard operational logs (such as request logs and IP addresses) as part of running the infrastructure.
3. How We Use Your Information
We use the information above to:
- Create and secure your account, and let you sign in
- Provide the features you use — screeners, watchlists, portfolio tracker, alerts, AI coach, and the rest
- Process your subscription payments and manage your plan (via Stripe)
- Send transactional emails you have turned on — alerts and digests (via Resend). These are controlled by your own toggles; we do not send marketing spam
- Power the AI coach — your messages are sent to Anthropic (the AI provider) to generate responses
- Find and fix bugs using our in-house error tracking
- Prevent abuse, enforce our Terms of Service, and comply with legal obligations
We do not use your information to build advertising profiles, and we do not sell it. See Section 6.
4. Legal Bases for Processing
[ATTORNEY TO REVIEW — applicability of GDPR, CCPA/CPRA, and other privacy laws to this service, and the appropriate legal-basis framework.]
In simple terms, where such laws apply, we process your information because:
- It is necessary to provide the service you signed up for (contract) — account, billing, features, transactional emails
- We have a legitimate interest in keeping the service secure and working — error tracking, abuse prevention, sign-in protection
- You have consented — where consent is the applicable basis, such as optional email toggles
- The law requires it — for example, tax and accounting records tied to payments
[ATTORNEY TO REVIEW — whether CCPA/CPRA consumer-rights disclosures, a "Do Not Sell or Share" statement, and GDPR data-subject-rights sections need to be added based on user base and revenue thresholds.]
5. Third-Party Service Providers (Processors)
We rely on a small set of service providers to run CloverBull. Each receives only what it needs to do its job:
| Provider |
Role |
What It Handles |
| Stripe |
Payment processing |
Card details and payment processing. We never store card numbers; Stripe handles all payment data. |
| Supabase |
Database and authentication (US region) |
Account credentials (password hashes), profile, watchlists, portfolio entries, preferences, AI coach chat history, and application data. |
| Netlify |
Hosting and serverless backend |
Serves the website and runs backend functions; generates standard hosting logs. |
| Anthropic |
AI provider (Claude models) |
Processes your AI coach messages and related context to generate responses. |
| Resend |
Transactional email |
Sends alert and digest emails to your address, based on your toggles. |
| Cloudflare Turnstile |
Sign-in bot protection |
Processes the CAPTCHA-style check when you sign in. |
| TradingView |
Embedded chart widgets |
Third-party chart content embedded in the app; loading a widget involves your browser connecting to TradingView. |
| Financial Modeling Prep |
Market data supplier |
Provides market and fundamentals data to us. It does not receive your personal information. |
These providers act on our behalf under their own terms and privacy policies. We do not give any of them your data for their own marketing purposes.
6. What We Don't Do
- We do not sell your personal data. Ever.
- We do not use advertising trackers or ad networks.
- We do not use third-party analytics — no Google Analytics, no Sentry, no behavioral tracking pixels. Our error tracking is built and run in-house.
- We do not connect to your brokerage or handle your investment funds. The portfolio tracker is manual journaling only.
- We do not send marketing spam. Emails are transactional (alerts and digests) and controlled by your own settings.
7. Cookies and localStorage
CloverBull is light on browser storage:
- localStorage — we store your UI preferences (like theme and layout choices) and cached screener data in your browser so the app is fast and remembers how you like it. This data stays on your device; you can clear it anytime through your browser settings.
- Authentication — your sign-in session is maintained by our authentication provider (Supabase) using browser storage, so you stay logged in between visits.
- Third-party widgets — embedded TradingView charts and the Cloudflare Turnstile check may set their own cookies or use their own storage, governed by their privacy policies.
We do not use tracking or advertising cookies.
8. Data Retention
- Account and content data (profile, watchlists, portfolio entries, preferences, AI chat history) is kept for as long as your account is active.
- Billing records are retained as long as required for tax, accounting, and legal purposes, even after account deletion.
- Error logs are kept only as long as needed for debugging and are periodically cleared.
- Deleted accounts — when you request deletion (Section 9), we delete your personal data from our systems, except what we are legally required to keep (such as payment records held by Stripe and our related billing history).
9. Deleting Your Data
To delete your account and personal data, email us at [SUPPORT EMAIL] from the email address on your account. We will verify the request, delete your data as described in Section 8, and confirm when it is done. Deletion is permanent — your watchlists, portfolio entries, and chat history cannot be recovered afterward.
10. Security
We take reasonable, industry-standard measures to protect your information:
- Encryption in transit — all traffic between your browser and CloverBull uses HTTPS/TLS.
- Password security — passwords are hashed by our authentication provider; we never store or see them in plain text.
- Access controls — database access is restricted by row-level security policies and scoped credentials, so backend services and users can only reach the data they are supposed to.
- Payment isolation — card data never touches our servers; it goes directly to Stripe.
No online service can guarantee perfect security, and we do not promise that ours is an exception — but we work to keep our practices sound and to fix issues quickly when we find them.
11. Children
CloverBull is for adults. You must be at least 18 years old to create an account. We do not knowingly collect personal information from anyone under 18. If we learn that we have, we will delete it. If you believe a minor has created an account, contact us at [SUPPORT EMAIL].
12. International Users
CloverBull's infrastructure and database are located in the United States. If you use the service from outside the US, your information will be transferred to and processed in the US. [ATTORNEY TO REVIEW — international data-transfer mechanisms and disclosures, if applicable.]
13. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you — by email, by a notice in the app, or both — before the changes take effect. The "Effective Date" at the top always reflects the current version. Continued use of CloverBull after changes take effect means you accept the updated policy.
14. Contact Us
Questions, requests, or concerns about privacy:
- Email: [SUPPORT EMAIL — support@cloverbull.com planned]
- Operator: [COMPANY LEGAL NAME]
- Address: [COMPANY MAILING ADDRESS — attorney/owner to provide]
We aim to respond to all privacy requests within a reasonable time, and within any timeframe required by applicable law.