Privacy Policy
What we collect, how it's used, and how to ask us to delete it.
Last updated: 2026-04-27
Data we collect
- Account data. Email address, plan tier, and onboarding preferences you provide on sign-up. Stored in our authentication provider (Supabase) and used to operate the service.
- Usage telemetry. Page views, feature interactions, and aggregated performance signals. We use PostHog for product analytics and Sentry for error tracking. Both are configured to drop request IP addresses (PostHog:
ip:false; Sentry:sendDefaultPii:false+ a beforeSend scrubber on forwarded-IP headers) so analytics and error events are not joined to a network identifier on the provider side. - AI-assisted analysis. Some features (e.g. White River thesis synthesis) call Anthropic's Claude API. The portfolio context, watched artists, and recent market data needed to generate the output are transmitted to Anthropic. Per Anthropic's commercial terms, prompts and outputs are not used to train their models.
- Billing data. Handled by Stripe. We store only the subscription ID, plan, and status — no card numbers ever touch our servers.
- User-generated content. Watchlist artists, portfolio holdings, custom alerts, and saved lot annotations are stored under your account and visible only to you.
How we use it
To operate the service, send transactional email (alerts you opt into, billing receipts, password resets), debug errors, and improve the product. We do not sell user data and do not share it with advertisers. Where AI features call third-party model providers (see “AI-assisted analysis” above), we use providers whose commercial terms prohibit training on customer inputs.
Subprocessors
- Supabase (authentication + database)
- Stripe (subscription billing)
- Resend (transactional email)
- Vercel (hosting)
- PostHog (product analytics)
- Sentry (error tracking)
- Anthropic (LLM provider for AI-assisted analysis features)
Controller & legal basis
The data controller is White River Research Inc. (placeholder — replace with the registered legal entity and principal place of business before launch). We process the data described above on the following GDPR Art. 6 lawful bases:
- Performance of contract (Art. 6(1)(b)) — account data, billing data, and user-generated content needed to provide the service.
- Legitimate interests (Art. 6(1)(f)) — error tracking, security monitoring, and abuse prevention. Balanced against the limited PII stored in error events (no IP, no behavioural profile).
- Consent (Art. 6(1)(a)) — product analytics (PostHog) and session-replay error capture (Sentry replay), opt-in via the cookie banner / cookie-settings page.
For users in the EU/UK, our representative under GDPR Art. 27 is [pending — appoint before EU/UK launch].
Your rights
Signed-in users can export or delete their data at any time from Account → Data & deletion. Export returns one JSON file containing your profile, portfolios, holdings, watchlist, alerts, subscription metadata, and API key metadata. Deletion cascades through the same surfaces, cancels your Stripe subscription, and removes your authentication record. Stripe retains billing records per its own retention schedule and our tax obligations; aggregated, de-identified analytics may be retained.
For correction requests, accounts created before self-serve was available, or any other questions, email privacy@whiteriverresearchgroup.com and we'll respond within five business days.