Privacy Policy
Last updated: July 20, 2026
SECSift is operated by StableBread LLC ("we", "us"), an Ohio company. The service is built to need as little of your data as possible: reading filings requires no account, and the filings themselves are public SEC documents. This policy explains what we collect when you do more than read, where it goes, and what we deliberately avoid.
1. What we collect
- Account basics: when you sign in, our auth provider (Clerk) gives us your email, name, and avatar. If you sign in with Google, Google shares only your basic profile (email, name, picture). That is the whole profile. We never see your password.
- Your workspace: filings you save, folders, notes and tags, flag corrections, Ask AI customizations, and (when signed in) your recently viewed filings. Stored in our database (Convex) so they sync across your devices.
- Billing: subscriptions and credit purchases are processed by Stripe, with billing state managed by Autumn. Your card number goes to Stripe directly and is stored by Stripe so later purchases can charge it; we never see or store card numbers. We keep the billing state itself: your plan, credit balance, and purchase history.
- Product analytics: we use PostHog to understand how the product is used: pageviews, and a small set of events such as "a filing was opened" (the form type, never the ticker), "an export ran", or "a checkout started". Events are tied to your account id only, not your email or name. We deliberately do not record which companies you research in analytics: your reading list is your business.
- Session replay: PostHog may record how sessions interact with the interface so we can find where it confuses people. Everything you type and everything you author (searches, notes, Ask AI questions) is masked before it leaves your browser and never appears in a recording; the public filing text on screen does.
- Error reports: when something breaks, Sentry receives the technical error (stack trace, browser version, the failing request's shape). Request bodies are never attached, so filing text, notes, and prompts stay out of error reports.
- Local preferences: reading settings, open tabs, and guest history live in your browser's local storage, not on our servers. Clearing site data removes them.
- Server logs: our hosting providers (Vercel for the app, Railway for the filing engine) keep standard operational logs, including IP addresses, for security and debugging, retained briefly.
2. What we do not do
- No advertising, no ad trackers, no selling or renting your data. Ever.
- No training AI models on your private notes or questions.
- No recording of what you type. Inputs are masked in session replay.
- No tracking of which companies you research in analytics.
- No collection beyond what the features above need.
3. AI processing
When you use AI features (Sift, Ask AI, table reads), excerpts of the public SEC filing you are reading (and, for Ask AI, the passage you selected and the question you typed) are sent through our infrastructure to third-party AI model providers (via OpenRouter) to generate the response. Filings are public documents. Your private notes are never sent to AI providers, and we do not permit providers to train on these requests under our API terms.
4. Cookies and similar storage
We use cookies and local storage for three things: keeping you signed in (Clerk), remembering your reading preferences, and analytics (PostHog). There are no third-party advertising cookies. Blocking analytics cookies with a browser extension does not break the app.
5. Who processes your data
We share data only with the processors that run the service, each bound by their own privacy terms: Clerk (authentication), Convex (database), Stripe and Autumn (payments), OpenRouter (AI model routing), PostHog (analytics), Sentry (error monitoring), and Vercel and Railway (hosting). We do not share your data with anyone else unless required by law.
6. Retention and deletion
Your workspace data is kept while your account exists. Delete individual notes or saved filings anytime in the app. Deleting your account (through Manage account) removes your sign-in profile; to have your remaining workspace data (saved filings, notes, history) erased from our systems, email us and we complete it within 30 days. Billing records are retained as required for tax and accounting. Analytics and error data age out on our providers' standard retention schedules.
7. Security
All traffic is encrypted in transit (HTTPS). Access to production systems is limited to account holders who operate the service. No system is perfectly secure; if a breach affects your data, we will notify you as the law requires.
8. Children
The service is not directed to children under 13, and we do not knowingly collect their data.
9. Your rights
You can access your notes and saved filings in the app at any time, correct your account details through Manage account, and delete your account. For a copy of your data, or for erasure of everything we hold about you, email us. We complete both within 30 days. Depending on where you live you may have additional rights (access, portability, erasure); we honor those the same way.
10. Changes
We may update this policy as the product evolves. Material changes will be reflected in the "Last updated" date above and, where significant, announced in the app.
11. Contact
Privacy questions or requests: open Contact from the account menu, or email fajasy@stablebread.com. Either reaches the same inbox and we reply to the address you write from.