Privacy Policy
Last updated: September 28, 2026
SECSift is operated by StableBread LLC ("we", "us"), an Ohio company. The service is built to need as little of your data as possible: reading filings requires no account, and the filings themselves are public SEC documents. This policy explains what we collect when you do more than read, where it goes, and what we deliberately avoid.
1. What we collect
- Account basics: When you sign in, our auth provider (Clerk) gives us your email, name, and avatar. If you sign in with Google, Google shares only your basic profile (email, name, picture). That is the whole profile. We never see your password.
- Your workspace: Filings you save, folders, notes and tags, flag corrections, Ask AI customizations, and (when signed in) your recently viewed filings. Stored in our database (Convex) so they sync across your devices.
- Billing: Subscriptions and credit purchases are processed by Stripe, with billing state managed by Autumn. Your card number goes to Stripe directly and is stored by Stripe so later purchases can charge it; we never see or store card numbers. We keep the billing state itself: your plan, credit balance, and purchase history.
- Product analytics: We use PostHog to understand how the product is used: pageviews, and a small set of events such as "a filing was opened" (the form type, never the ticker), "an export ran", or "a checkout started". Events are tied to your account id only, not your email or name. We deliberately do not record which companies you research in analytics: your reading list is your business.
- Session replay: PostHog may record how sessions interact with the interface so we can find where it confuses people. Everything you type and everything you author (searches, notes, Ask AI questions) is masked before it leaves your browser and never appears in a recording; the public filing text on screen does.
- Error reports: When something breaks, Sentry receives the technical error (stack trace, browser version, the failing request's shape). Request bodies are never attached, so filing text, notes, and prompts stay out of error reports.
- Local preferences: Reading settings, open tabs, and guest history live in your browser's local storage, not on our servers. Clearing site data removes them.
- Server logs: Our hosting providers (Vercel for the app, Railway for the filing engine) keep standard operational logs, including IP addresses, for security and debugging, retained briefly.
2. What we do not do
- No advertising, no ad trackers, no selling or renting your data. Ever.
- No training AI models on your private notes or questions.
- No recording of what you type. Inputs are masked in session replay.
- No tracking of which companies you research in analytics.
- No collection beyond what the features above need.
3. AI processing
When you use AI features (Sift, Ask AI, table reads), excerpts of the public SEC filing you are reading (and, for Ask AI, the passage you selected and the question you typed) are sent through our infrastructure to third-party AI model providers (via OpenRouter) to generate the response. Filings are public documents. Your private notes are never sent to AI providers, and we do not permit providers to train on these requests under our API terms.
4. SECSift for Chrome
The SECSift extension for Chrome is built the same way: it works without an account, and it needs as little of your data as it can.
- Without an account: The extension gets company and filing data straight from the SEC and sends SECSift nothing. Opening a link or a search from it visits SECSift like any other visit.
- What it reads on a page: On Twitter/X, Substack, Stocktwits, and EDGAR, it reads the cashtags, company symbols, and filing links on the page, in your browser, to add its buttons and pills. On any other site, it can read a page only after you open the extension there. It keeps none of it and sends none of it anywhere, except as described below.
- With an account connected: The extension talks to SECSift only for your account's features, and sends only what each one needs: the filing you are viewing on EDGAR, to show whether it is saved; the company you open in the side panel; the filing, your questions, and the notes you save in Ask a filing; and the alerts you read or remove. Saved filings, the filings you open in the side panel, chats, notes, and alerts are kept with your account like the rest of your workspace, and Ask a filing reaches AI providers as section 3 describes.
- The connect key: Connecting makes a random key in your browser. The extension keeps it in Chrome's storage, and we store only a fingerprint of it (a SHA-256 hash) with a random id for your browser. Select Disconnect in the extension and the key stops working.
- Stored in your browser: Your extension settings, a connected account's email address and plan, and a copy of the SEC's company list and filing lists so pages load fast. If you use Chrome sync, Chrome syncs the settings across your browsers. Removing the extension removes all of it.
- No tracking: The extension has no analytics and no ads, loads no code from anywhere else, and keeps no record of the pages you visit.
5. Cookies and similar storage
We use cookies and local storage for three things: keeping you signed in (Clerk), remembering your reading preferences, and analytics (PostHog). There are no third-party advertising cookies. Blocking analytics cookies with a browser extension does not break the app.
6. Who processes your data
We share data only with the processors that run the service, each bound by their own privacy terms: Clerk (authentication), Convex (database), Stripe and Autumn (payments), OpenRouter (AI model routing), PostHog (analytics), Sentry (error monitoring), and Vercel and Railway (hosting). We do not share your data with anyone else unless required by law.
7. Retention and deletion
Your workspace data is kept while your account exists. Delete individual notes or saved filings anytime in the app. Deleting your account (through Manage account) removes your sign-in profile; to have your remaining workspace data (saved filings, notes, history) erased from our systems, email us and we complete it within 30 days. Billing records are retained as required for tax and accounting. Analytics and error data age out on our providers' standard retention schedules.
8. Security
All traffic is encrypted in transit (HTTPS). Access to production systems is limited to account holders who operate the service. No system is perfectly secure; if a breach affects your data, we will notify you as the law requires.
9. Children
The service is not directed to children under 13, and we do not knowingly collect their data.
10. Your rights
You can access your notes and saved filings in the app at any time, correct your account details through Manage account, and delete your account. For a copy of your data, or for erasure of everything we hold about you, email us. We complete both within 30 days. Depending on where you live you may have additional rights (access, portability, erasure); we honor those the same way.
11. Changes
We may update this policy as the product evolves. Material changes will be reflected in the "Last updated" date above and, where significant, announced in the app.
12. Contact
Privacy questions or requests: open Contact from the account menu, or email fajasy@stablebread.com. Either reaches the same inbox and we reply to the address you write from.