Legal
Last updated: 27 August 2026
This page explains what we collect when you use FinSight, why we collect it, who we share it with, and what rights you have over it. We aimed for plain language rather than legalese.
Data controller: Finsight — Kadıköy, İstanbul, Türkiye.
For anything privacy related you can reach us at develop@insightcoreai.com.
Account details: your email address, display name, birth year and base-currency preference. When you sign in with Google or another identity provider, the user identifier that provider hands us. If you registered with an email and password, an irreversible hash of that password — the password itself is never stored anywhere.
Usage data: the portfolios you create, the transactions you enter (date, quantity, price, fees and any notes you write), your watchlists, your answers to the risk-profile questionnaire, your language and theme preferences, and which assets you view analysis for.
Technical data: your IP address, browser and device information, the device identifier issued to refresh your session, and error logs.
WhatsApp channel: if you link your account to WhatsApp, your phone number and the text of the messages you send the bot. None of this exists if you never use the channel.
Subscription: your customer and subscription identifiers at our payment provider. Card details never reach us; only the payment provider handles them.
To create your account, keep you signed in and protect that session.
To compute your portfolio and produce analysis and cards — this is the product itself.
To manage your subscription and usage limits.
To find bugs, measure performance and prevent abuse.
To understand which parts of the product get used. We do this in aggregate, not per person.
We do not sell your data and we do not open it to third parties for advertising. The processors below handle only what running the product requires:
Anthropic — writes the copy for analysis cards. What we send is market data and template parameters; your identity travels as an irreversible hash, never in the clear.
Vercel — application hosting and server logs.
Timescale — database hosting.
PostHog (European Union servers) — product usage analytics.
Sentry — error and performance monitoring.
Polar — subscriptions and payments.
Google and Logto — authentication, only at the moment you sign in.
Meta (WhatsApp Business Platform) — only if you use the WhatsApp channel, to deliver your messages.
One boundary worth stating plainly: your portfolio, transactions and positions never leave for WhatsApp. The bot answers from public market data only.
We may also disclose data to authorities where the law requires it.
We keep account and portfolio data for as long as your account is open.
Session refresh records are invalidated when they expire or when you sign out.
Server and error logs are deleted after 90 days.
The WhatsApp message log is kept for 12 months; once you remove the link, no new entries are created.
When you delete your account, your personal data is erased within 30 days.
Invoicing and accounting records are retained for the period the law prescribes.
To learn what data we hold about you and request a copy.
To have inaccurate or incomplete data corrected.
To have it erased.
To object to processing and withdraw consent you have given.
Writing to develop@insightcoreai.com is enough to exercise any of these. You can also delete portfolio, transaction and watchlist data yourself inside the app, and remove the WhatsApp link from Settings in one tap.
We use the cookies needed to keep you signed in; sign-in does not work without them.
For product analytics we use PostHog, with data held on its European Union servers. The purpose is understanding which screens get used. We do not run advertising trackers and we set no third-party ad cookies.
All connections are encrypted with TLS.
Passwords are hashed with a memory-hard algorithm (Argon2id) plus an additional secret held server-side; they never appear in any response, log or query output.
Session refresh keys are stored as hashes rather than raw values and are bound to a device.
The application reaches the database with least-privilege credentials only.
No system is flawless. If you spot a security problem, please tell us.
FinSight is not directed at anyone under 18, and we do not knowingly collect data from people below that age.
FinSight provides data and neutral commentary. It does not give investment advice, does not trade on your behalf and promises no returns. Your decisions remain yours.
We may update this policy from time to time. When something material changes we update the date above and, where needed, tell you separately.
For questions, requests and complaints: develop@insightcoreai.com