Legal
Privacy Policy
1. What we collect
Account data: the email address and password (stored as an Argon2id hash, never in plain text) you sign up with. Content you enter: watchlists, portfolio holdings, and saved views you create. Session data: a session cookie and, if you enable two-factor authentication, a "trust this device" cookie — both essential to keep you signed in and are never used for tracking. Usage analytics: anonymous, first-party events (e.g. signup, login, feature usage) identified by an HMAC-hashed actor, not your name or email — used only to understand how the product is used. That anonymization applies specifically to those usage-analytics events; separately, we also keep operational access logs recording your username, IP address, browser user-agent, and the pages/API endpoints you request, used for security, abuse prevention, and debugging. We do not use third-party advertising or tracking cookies, and we do not sell your data to anyone.
2. How we use it
To provide the service (log you in, show your watchlists/portfolio, process billing), to communicate with you about your account, and to improve the product using the anonymous usage analytics described above.
3. Who we share it with
Stripe processes payments and holds your billing details — Sideravia never sees your full card number. Our market-data providers supply the prices/fundamentals shown on the site; they never receive your account or portfolio data. We also use a third-party IP geolocation service to determine the approximate city/region/country of login attempts, for security purposes; only the IP address is sent to this service. Backblaze B2 stores encrypted off-site backups of your account, waitlist, portfolio, and preference data, in the United States (region us-east-005) — an international transfer of your data for EU/Swiss users. That data is encrypted before it ever leaves our servers, so Backblaze receives only ciphertext it cannot read; the key needed to decrypt it lives only on the operator's own device, never on Backblaze's servers or ours. We don't share your data with anyone else beyond what's described above.
4. Cookies
Sideravia uses exactly two cookies, both strictly necessary for the service to work: a session cookie (keeps you signed in) and a "trust this device" cookie (skips repeat two-factor prompts on a device you've marked as trusted, valid for a limited period). Neither is used for tracking or advertising, and no third-party cookies are set by this site.
5. Your rights
If you're in the EU, you have rights under GDPR to access, correct, export, or delete your data. If you're in Switzerland, equivalent rights apply under the Swiss Federal Act on Data Protection (FADP). You can export your data or delete your account any time from your account settings. Deletion disables access immediately and permanently removes your personal data after a 7-day grace period; some billing records may be retained briefly where legally required.
6. Data retention
We keep your account data for as long as your account is active. When you delete your account, access is disabled immediately and your personal data is permanently removed after the 7-day grace period described above (during which you can email support to undo the deletion); some billing records may be retained briefly where required for legal/financial compliance.
When you delete your account we erase it from our live systems immediately and destroy the encryption key for your data, so it can no longer be read. Encrypted backups made before that point cannot be altered — they are held in tamper-proof storage — and age out automatically under our backup retention schedule, up to 30 days later.
7. Contact
Questions about this policy or a data request? Reach us via the contact page.