Legal
Privacy policy
Who is responsible
[LEGAL NAME, S.L.] (NIF [NIF], [REGISTERED ADDRESS], Spain) is the controller of your personal data.
- Contact: privacy@mktkeel.com
- Person accountable for privacy: [PRIVACY OFFICER: name, title]
What we collect
- Account: your email address and an account ID created by our sign-in provider. Your password is held, encrypted, by that provider; we never see it.
- What you do in MarketKeel:
- your conversations, with the answers and the market data used to produce them;
- answers our screening withheld;
- your watchlist, alerts and settings, the AI model used, and counts of your requests.
- Billing: your plan, its status and dates, the amounts charged, and the customer ID of our payment provider, Stripe. Stripe collects your card details and billing address; we never receive the full card number.
- Email preferences: whether you turned on the daily digest, and the address it goes to.
- Technical data: your IP address, browser type and the time of each request, in our server logs.
We don’t collect your name (except when you withdraw from a purchase), your portfolio or any brokerage details. We don’t use analytics or advertising trackers, and we do not sell your personal data or share it for advertising.
Why we use it, and our legal basis (EU/UK)
| Purpose | Data | Legal basis |
|---|---|---|
| Run your account and the Service, answer your questions, send alerts | Account, activity | Contract (Art 6(1)(b) GDPR) |
| Take payments, keep accounting and tax records | Billing | Contract; legal obligation (Art 6(1)(c)) |
| Send the daily digest | Email, watchlist | Consent: you turn it on, and you can turn it off any time (Art 6(1)(a)) |
| Send service emails (verification codes, receipts, important changes) | Contract; legal obligation | |
| Keep the Service secure, prevent abuse and fraud, enforce limits | Technical data, request counts | Legitimate interests (Art 6(1)(f)) |
| Handle a withdrawal from a purchase, and keep it as evidence | Name, account, what was bought and refunded | Legal obligation; legal claims |
| Screen answers, and keep withheld answers to show we don’t give investment advice | Activity | Legitimate interests; legal claims |
How the AI works with your data
- Your messages and recent conversation are sent to AI models to produce an answer. The models run on Amazon Web Services (Amazon Bedrock). They are made by Anthropic, Amazon, Meta and OpenAI, but those companies do not receive your data.
- AWS does not use your messages or answers to train models, and neither do we.
- A separate model reads each question to decide whether it is in scope. For example, a question asking for personal advice gets a general answer instead. This does not produce legal or similarly significant effects on you.
Who receives your data
- Amazon Web Services (hosting, sign-in, database, email, AI models), as our processor.
- Stripe (payments). Stripe is our processor, and an independent controller for its own fraud prevention and legal duties; see stripe.com/privacy.
- Our market-data provider receives the ticker symbols and search terms you enter, but not who you are.
- Authorities or courts, when the law requires it.
- A buyer of our business, if one exists; we would tell you first.
International transfers
Our servers are in the United States (AWS, us-east-1). To answer quickly, AWS may process an AI request in another AWS region worldwide. Data stored at rest stays in the US.
Transfers out of the EU and UK rely on the EU–US Data Privacy Framework and its UK extension, under which AWS and Stripe are certified, and on the European Commission’s Standard Contractual Clauses (with the UK Addendum) in our agreements with them. If you live in Canada, your information is processed outside Canada and may be accessible to authorities there under local law.
How long we keep it
| Data | Kept for |
|---|---|
| Account, conversations (including withheld answers), watchlist, settings, request counts | Until you delete your account |
| Alerts and digest records | 90 days |
| Server logs (no messages, no email addresses) | 30 days |
| Web-server access logs (IP address, browser) | 14 days |
| Backups | Up to 35 days after deletion |
| Withdrawals (your name, the purchase, the refund), even after you delete your account | 5 years |
| Payment and invoice records (held by Stripe) | As long as tax and accounting law requires, generally 6 years in Spain |
| Addresses that bounced or complained (email suppression list) | As long as needed to avoid emailing them |
Some records that contain only your account ID and no other details expire within 90 days of deletion.
Your rights
- Everywhere:
- Get a copy of your data in Settings › Account › Download my data.
- Delete everything in Settings › Account › Delete account.
- Correct your data, or anything else: email privacy@mktkeel.com.
- EU and UK: you can access, correct, delete, restrict, move (portability) or object to the use of your data, and withdraw consent at any time. You can complain to the Spanish Agencia Española de Protección de Datos (aepd.es), the UK Information Commissioner’s Office (ico.org.uk), or the authority where you live.
- Canada: you can access and correct your information and withdraw consent. You can complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca).
- United States: depending on your state, you can ask to know, access, correct, delete or port your personal information. Email privacy@mktkeel.com.
- If we refuse, you can appeal by replying with “Appeal” in the subject.
- We don’t sell personal information or share it for cross-context behavioural advertising, and we won’t treat you differently for using your rights.
- In the last 12 months we have collected: identifiers (email, account ID, IP address), commercial information (plans and purchases) and internet activity (use of the Service), from you, your device and Stripe, for the purposes above.
- We don’t track you across other sites, so browser “Do Not Track” and Global Privacy Control signals change nothing.
Cookies and similar storage
We use only storage that the Service needs to work, so we don’t ask for consent. If we ever add anything else, we will ask first.
| Name | Type | What it does | How long |
|---|---|---|---|
finai.auth | Local storage | Keeps you signed in | Until you sign out, at most 30 days |
finai.auth.flow | Session storage | Secures the sign-in step | Until you close the tab |
| Sign-in page cookies (AWS Cognito) | Cookie | Keep the sign-in page working | The sign-in session |
finai.checkout.pending | Session storage | Resumes a payment after a redirect | Until you close the tab |
finai.model, finai.palette, theme, sidebar_state | Local storage / cookie | Remember the model and display options you chose | Until cleared; sidebar_state 7 days |
Stripe cookies (e.g. __stripe_mid, __stripe_sid) | Cookie | Prevent fraud on the payment form | Up to 1 year; see stripe.com/cookie-settings |
Children
MarketKeel is for adults (18+). We don’t knowingly collect data from anyone younger. If we learn we have, we delete it.
Security
Data is encrypted in transit and at rest, access is limited to what each part of the Service needs, and we don’t log message content. If a breach puts you at risk, we will tell you and the authorities as the law requires.
Changes
If we change this policy in a way that matters, we will tell you by email or in the app before it takes effect.