Privacy policy
Last updated September 2026
What we collect
Your email address and a hash of your password when you sign up. What you set up in the app: your watchlist and notes, your saved scans, your alert rules and the history of the alerts that fired for you.
For each signed-in session we record the browser type and the full IP address the request arrived from, so that you can tell your own devices apart and revoke any you do not recognize. The sessions page shows that address partially masked; the full value is what we hold, and it is what appears in your own data export. Signing out of a session, or revoking it from the sessions page, deletes its record straight away; a session that simply expires is cleared the next time that browser contacts us.
If you subscribe, Stripe collects your payment details directly. We receive only a customer reference and your subscription status, never your card number.
Free trial records
A free trial is meant to be one per person. To enforce that we keep a small ledger, separate from your account: a one-way hash of your email address (never the address itself), the random id from the device cookie described below, and the IP address the sign-up came from. A later sign-up that matches an entry gets an account without a second trial.
Where you came from
If the link you arrived on carried campaign tags (the utm_source, utm_medium, utm_campaign, utm_content and utm_term parameters you can see in the address bar), or if it was a member's share link, we keep those values in a first-party cookie named mm_attr for 30 days and record them on your account if you go on to sign up. What is stored is the campaign tags themselves, the page you landed on, the domain that sent you (for example the search engine or social site, never the full address you came from), and the code of the member who referred you, if there was one. Nothing else: no advertising identifier, no profile, and no script from anyone else. It is kept for as long as the account is, it is used to work out which of our own links brought people here and to credit the member who shared one, and it is never sold or shared with advertisers. Deleting your account deletes it.
Page use
We measure our own pages. When you leave a page the browser sends us the path (for example /pricing), how many seconds the page was open, and whether the screen is phone, tablet or desktop size. Nothing else: no query string, no referrer, no scroll or click tracking, and no script from anyone else. Pages are recorded for signed-out visitors too, in which case the record carries no identity at all; when you are signed in it is linked to your account, so our support team can see which pages you used. These records are kept for 90 days and then deleted.
Admin records
When a member of our team looks at or changes an account through the support tools, we write a permanent entry recording who did it, which account it concerned, what was done and the full IP address it was done from. That log is deliberately append-only: it exists so that any access to your data can be accounted for afterwards, so we do not delete from it.
What we do not do
We do not sell or share personal data with advertisers. We do not run third-party analytics, advertising trackers or social media pixels. We do not store card numbers.
Cookies
We set three, all first-party. The two below are HttpOnly and are not readable by any script on the page; the third is the mm_attr cookie described under "Where you came from", which the sign-up form has to read, and which holds only the campaign tags that were already in your own address bar.
The session cookie, named __Host-mm_session (mm_session on a plain http development server), keeps you signed in. It holds a random token rather than anything that identifies you, and signing out deletes it.
The device cookie, named mm_device, is a random id set when you sign up or sign in. It lasts up to 400 days and does one job: it remembers that a free trial has been started in this browser, so the same browser cannot start another one. It is not linked to your browsing, it is not shared with anyone, and it carries nothing about you.
Retention
Account data is kept while the account exists. Sessions expire after 30 days of inactivity, or 90 days after they were created, whichever comes first; sessions for our own admin accounts expire after 12 hours of inactivity. Page use records are kept for 90 days. Cached headlines are kept for a week.
You can ask us to delete your account, and you can delete it yourself from the profile page. That removes the account itself and, with it, your watchlist, saved scans, alert rules, alert history, push subscriptions and sessions. The page use records described above still carry the account id until they age out on the 90 day schedule. Two things deliberately survive deletion. The trial ledger entry above keeps its hashed email, device id and sign-up IP, so that deleting an account is not a way to start a fresh free trial. Admin log entries about the account keep the account id and the email address as it was at the time, because a record of who accessed what is not useful if it can be erased. Neither one lets us reconstruct the account, and neither is used for anything else.
You can download everything we hold about your account as JSON at any time, from the profile page.
Security
Passwords are hashed with Argon2id, traffic is encrypted in transit, and secrets are kept in a managed secrets store rather than in code.
Contact
Privacy requests: privacy at the domain this site is served from.