Privacy
Version 3 · 23 September 2026 · Legal review pending
Data used
INSIDER9+ (https://www.insider9.com) stores language preferences in the browser. Preferences, alerts and personal positions are associated with the authenticated account. The administrator area requires a ChatGPT identity and server-side authorisation. Passwords are not included in public code.
Google sign-in
If you choose to sign in with Google, INSIDER9+ may receive your name, email address, account identifier and basic profile information required to create and authenticate your account. This information is used to manage your account and session and associate your preferences, alerts, My Portfolio and private account features.
Sign-in uses only the openid, email and profile scopes. It does not request access to Gmail, emails, Google Drive, files, Google Calendar, contacts or other private content in Google services.
Purposes and access
Data supports requested features, access security and, when configured and enabled, alert delivery. Personal positions are private and associated with the authenticated account; they are not used to produce personal recommendations. Signing out removes access to the portfolio in that browser. Administrator positions require server-side authentication and authorisation. Do not enter sensitive personal information in public editorial fields.
Providers and retention
The service uses Sites hosting and Cloudflare infrastructure. When configured, email delivery uses Resend and the authorised recipient. Google sessions expire after seven days, visitor sessions after one year and elevated administrator sessions after eight hours. Session expiry does not automatically erase associated records. Functional data remains until removed or until a retention policy is established. The email provider may process delivery metadata.
Control and rights
You can remove open positions and change or disable preferences in their respective areas. Completed sales preserve their recorded history and results. Clearing cookies ends local session access but does not delete server records. The data controller’s identity and contact, legal bases, final retention periods, transfers and procedures for access, correction and erasure requests await formalisation and review before commercial launch. This page is a development draft, not a completed compliance declaration.
