PRIVACY
What we know about you, and what we don’t
Most of this terminal runs on your own Mac, talking to sources with keys you hold yourself. That is a design decision rather than a policy, and it is most of the privacy story.
- Your API keys stay on your Mac. They are never sent to us.
- Requests for market data go from your Mac to whoever publishes the figure. They do not pass through us, so there is nothing for us to log.
- There is no analytics, no telemetry and no crash reporting in the app. It does not report what you look at, because nothing in it is built to.
- If you sign in, we hold your email address and the things you make: portfolios, watchlists, layouts, alerts, notes and messages. That is the whole list.
- You can delete all of it, and the account itself, from inside the app.
The rest of this page is the same thing said precisely.
When you add a key in Settings, it is written into a file inside the app’s own folder in your Mac’s Application Support directory, with permissions that let only your macOS user account read it.
It is not sent to us. It is not backed up to us. There is no copy of it in your account, and no path in the app that would send one.
Two smaller properties of the same design are worth stating. A saved key is never shown back to you in full: Settings displays the last four characters, which is enough to tell one key from another and not enough to be one. And no key ships inside the download: the file is created on your own machine the first time you save something, so a copy of the app carries nobody’s credentials.
To remove every key at once, delete that file. Settings will show you where it is. Deleting the app’s folder does the same thing.
When a panel loads a figure, the request goes from your Mac straight to whoever publishes it: Cboe, Yahoo Finance, SEC EDGAR, FINRA, the Federal Reserve, the IMF, or a source you connected yourself.
It does not pass through a server of ours, because there is not one in that path. The part of the app that fetches data runs on your machine, beside the window. So we do not know which symbols you look at, which panels you open, or when you open them, and that is not a promise not to look, it is that there is nothing to look at. Results are cached on your Mac and go when you delete the app’s folder.
The sources themselves do see the request, which means your IP address and whatever your key identifies you as. What they do with it is covered by their own privacy notices, not this one, and it is worth reading them for any source you connect.
There is none in the app. No product analytics, no usage events, no session recording, no crash reporter, no advertising or tracking code of any kind. Nothing counts your sessions or reports which features you used.
This site has none either, and it sets no cookies, which is why there is no cookie banner on it.
One thing is kept in your browser, and only after you buy: the reference Stripe gives your purchase, so that the Download button works on your next visit without making you sign in. It is the same reference that was in your address bar when you paid, it is never sent anywhere except to us when you press Download, and it is not used to count or follow anything. Clearing your browsing data removes it, and the only effect is that the Download button goes back to pointing at the pricing page.
For completeness, here are the only two things the app fetches that are not market data or your own account:
- Update checks. When update checking is on, the app asks the place releases are published whether a newer version exists. That request carries no account, no key and nothing about what you were doing. You can turn it off in the app.
- Company logos. When a panel shows a company’s logo, the image is fetched and cached on your Mac.
Signing in is free and optional, and a great deal of the terminal works without it. It exists so that your own work reaches your other Macs, and so that messaging works.
If you do sign in, this is everything your account holds:
- your email address and sign-in credentials, held by Supabase, the company that runs our database and sign-in;
- a profile: a handle, a display name, an optional picture, an availability status and when you were last seen;
- your portfolios, and the transactions and positions inside them;
- your watchlists;
- your saved screen layouts;
- your alerts;
- your notes, including any chart point a note is pinned to;
- the rooms you are in, who else is in them, and the messages;
- a directory entry and contact details, if you choose to publish them.
That is the complete list of what an account holds. Your purchase is recorded separately, because it is not part of your account and does not disappear with it; section 06 says what is in it. Each of the things above is scoped to you by the database itself, which checks on every read and every write that the row belongs to the account asking for it. That check is in the database rather than in the app, which is what makes it hold even if a mistake were made in the app.
The directory is off by default and you opt in field by field. Publishing your job title is a separate decision from publishing your desk phone number, and one tick box covering both would force the more exposed answer on somebody who wanted the less exposed one. Untick a field and it stops being published.
Payment is handled by Stripe. Card details are entered on Stripe’s own payment form and never reach us. We do not see, store or process a card number, an expiry date or a security code at any point, and there is nowhere in our systems that one could go. Stripe holds the payment itself under its own privacy policy, as a business in its own right rather than on our instructions.
What comes back to us is your email address, the amount and currency you paid, whether the payment succeeded, and the reference numbers Stripe uses to identify it. We keep that as your purchase record, and it is what lets us send you the download, recognise you when you reinstall, and refund you if something goes wrong.
Your purchase is not part of your account. It is held against the email address you paid with, so that somebody who deletes their account and signs up again has still bought the product rather than having to buy it twice. That means it survives account deletion, which is the one thing on this page that does. Section 10 says how long it is kept, and you can ask us to remove it.
Because one purchase covers a limited number of Macs, the app has to be able to count them. It identifies each Mac by a one-way digest rather than by anything readable: the machine identifier itself is never stored, and the same Mac under a different purchase produces an unrelated digest, so the record cannot be used to follow a machine around. Alongside it we keep the app and macOS version, which is what makes a support question answerable.
If you are in the EU, the EEA, the UK or Switzerland, the General Data Protection Regulation requires us to name a lawful basis for each use. These are ours.
- Your account and everything in it. Performance of the contract between us, Article 6(1)(b). Without it there is no sign-in and nothing to sync.
- Your purchase record. The same basis while we are supplying you, and afterwards a legal obligation, Article 6(1)(c), because tax and accounting law requires the record to be kept.
- Keeping the service running and preventing abuse. Our legitimate interests, Article 6(1)(f). We have weighed this against your interests and it covers only what is needed to keep the thing working and secure.
- Your directory listing and published contact details. Your consent, Article 6(1)(a), given per field and withdrawable at any time by unticking it.
We do not profile you, and nothing about you is decided by an automated process. We do not use your data to train anything.
Wherever you live, you can ask us to show you what we hold about you, correct it, delete it, or send it to you in a form you can take elsewhere. You can object to a use that rests on our legitimate interests, ask us to pause a use while a question is open, and withdraw a consent at any time.
In the EU, the EEA, the UK and Switzerland, those are your rights under the GDPR, and you also have the right to complain to your national data protection authority. We would rather you came to us first, but you do not have to.
In California, under the CCPA as amended by the CPRA, you have the right to know what is collected and why, to delete it, to correct it, and to opt out of its sale or sharing. There is nothing to opt out of: we do not sell personal information and we do not share it for cross-context behavioural advertising. We never have. You will not be charged a different price or given a worse service for exercising any right on this page.
The quickest of these needs nobody’s help and no waiting, which is the next section.
There is a working delete inside the app and it does what it says. Open the messaging panel by typing MSG, press Profile, then Delete my account. You confirm by typing a phrase, and then:
- everything listed in section 05 is removed, and your sign-in goes with it, so the account no longer exists;
- the app checks afterwards, category by category, that it is genuinely gone, and names anything still standing rather than showing you a success screen over a half-deleted account;
- rooms you opened survive without you. That is deliberate. A shared room used to disappear along with whoever created it, taking every other participant’s messages, and one person exercising a right to erasure must not erase other people’s. Your own messages go. The room stays for the people still in it.
It takes effect immediately and it cannot be undone. There is no recovery window, so export anything you want to keep first. If you would rather ask us to do it than press the button, you can.
The one thing it does not remove is your purchase record, for the reason section 06 gives: it is held against the address you paid with rather than against the account, so that deleting an account never costs you the product you bought. Ask us and we will remove that too, as far as the law lets us keep nothing.
Your account data is kept while your account exists and goes when you delete it, which is immediate rather than staged.
Purchase records are kept for as long as tax and accounting law requires, which is typically several years, and for as long as the licence they represent is usable. A purchase record is an email address, a payment, and the count of Macs described in section 06. It contains nothing from inside the app: not a portfolio, not a watchlist, not a message.
Anything on your Mac stays there until you remove it, and we have no way to reach it.
Our database and sign-in are run by Supabase, and payment by Stripe. Both are established businesses that process data on our behalf under contract, and both may hold data outside the country you are in.
Where data leaves the EEA, the UK or Switzerland, the transfer is covered by the European Commission’s standard contractual clauses, and the UK addendum where it applies, in the terms those companies operate under.
Your API keys, your cached data and everything else on your Mac stay on your Mac, wherever in the world you are.
The terminal is not for children. Do not use it or create an account if you are under 16, or under whatever higher age your country sets for agreeing to something like this. We do not knowingly hold data about a child, and if we learn that we are, we will delete it.
When this notice changes, the date at the top of the page changes with it. If a change matters, meaning we begin holding something new or using something differently, we will say so in the app the next time you open it rather than relying on you to re-read this page.
Last updated 14 August 2026. The terms cover what you are buying and what the numbers on screen are and are not.