Skip to content

Privacy Policy

Effective September 28, 2026

This policy explains what information Thaler collects, how it is used, who it is shared with, how long it is kept, and the choices you have. Thaler (“we”, “us”) is responsible for your information. Contact: support@thaler.sh.

Summary

  • You can use most of Thaler without an account. Without one, your lists, notes and settings stay in your browser.
  • With an account, we store your email address and what you create and save.
  • Some things are public: your profile page, your stances, public circles and anything you share by link or put on your shelf.
  • We use service providers to host Thaler, send email, keep logs and run AI features. We don’t sell your information, show ads, or track you on other websites.
  • You can delete your account at any time under Account → Delete account.

1. What we collect

Account. Your email address. A handle (we create a random one; you can change it), and a display name and profile line if you add them. When you request a sign-in code, we store your email and a one-way hash of your IP address. For each signed-in device, we store a description of your browser and device (the user agent) and when it was last used. If you add a passkey, we store its public key and a name for the device.

What you create. Watchlists, pies (including any amount you enter to simulate an investment), screens, notes, clippings, posts, replies, comments, stances, circles and circle images, and your settings. Circle images are resized and their metadata is removed.

What you do on Thaler. The companies you follow, the circles you join, which posts and comments you’ve read, reports you make, and when you were last active.

Questions you ask. When you use Ask about the filings, we store your question, the company, the answer and what it cost to produce.

Chats with Thaler Agent. When you chat with Thaler Agent, we store your chats: your messages, the agent’s answers and the steps it took to find them, the companies they mention, each chat’s name, and what each answer cost to produce. To apply limits, we also count how many questions you ask each day and how many of your messages our moderation check refuses.

Apps you connect. When you connect an AI assistant or other app through the Thaler MCP app, we store the app’s name, the access you gave it and when it was last used. For each request it makes, we record the time, the tool used, whether it worked, the size of the response and the company or search term it was about. We don’t store the rest of the request.

API keys. If you create API keys, we store each key’s name, a one-way hash of the key (not the key itself), its last four characters, and when it was created, last used, expires or was revoked. For each minute in which a key is used, we record the endpoint, the response status, the number of requests, their size and how long they took. For each day, we record which kind of client made the requests: one of our SDKs and its version, or the family of program the user agent names (curl, a Python library, a browser), never the user agent itself. We don’t store the rest of the request. If GitHub finds one of your keys in public, it sends us the key and the address where it was found; we revoke the key, keep that address with it and email you. When you connect the Thaler CLI, it sends us the name your computer gives itself, its operating system and the CLI’s version with the request; the key you confirm is named for the computer.

Email and notifications. Your email settings and a record of the emails we’ve scheduled for you. If you turn on push notifications, we store the address your browser gives us for them and a description of your browser.

Listening. Which briefs you play, how far you listen and at what speed. If you aren’t signed in, we link this to a random ID stored in your browser.

Technical information. When you use Thaler, our servers receive your IP address, browser and device type, the page or address requested, the page you came from, and how quickly pages load. We use this to run and secure Thaler and to fix errors, and we keep it in server logs. We derive your country from your IP address. We don’t store your precise location.

Analytics. We use Vercel Web Analytics and Speed Insights to count visits and measure how fast pages load. They record the page, the referring site, your approximate location (country, region and city), browser, operating system, device type and page-load timings. They don’t use cookies. Visitors are counted using a code created from each request that changes every day, so you aren’t tracked from one day to the next. We don’t send sign-in, email-settings or app-connection pages to analytics, and we remove query strings from the addresses we send.

2. People named in SEC filings

Thaler republishes information from public filings on the SEC’s EDGAR system. This includes the names of company insiders (directors, officers and large shareholders), their roles, and the transactions and holdings they report, and the names of investment managers and their reported holdings. We use this information to provide company research. We show it as it appears in the filings. We don’t add information about these people from other sources.

If you are named in a filing and think we’ve shown something incorrectly, email support@thaler.sh. We will correct errors in how we processed the filing. We can’t change what the filing itself says; corrections to a filing must be made with the SEC.

3. How we use information

  • To provide Thaler: your account, sign-in, saving and syncing what you create, circles, sharing, emails and notifications you’ve asked for, AI features and apps you connect.
  • To keep Thaler secure and working: to prevent abuse, enforce limits, investigate problems and fix errors.
  • To understand how Thaler is used and improve it, using analytics and logs.
  • To handle reports, enforce our Terms of Service, and meet legal obligations.

We don’t use your information for advertising, and we don’t sell it or share it for cross-context behavioural advertising.

4. What is public

  • Your profile page at thaler.sh/@your-handle can be seen by anyone and found by search engines. It shows your handle, display name, profile line, when you joined, your stances, items on your shelf, public circles you show on your profile, and the companies you follow. You can hide the companies you follow under Account.
  • Stances always appear on your profile. Company pages also show how many people are bullish or bearish, and name up to six followers who show their follows on their profile.
  • Public circles can be read by anyone, including their posts, replies, placed items and member list. Posts in invite-only circles can only be seen by members, and by us if a post is reported. If the owner makes a circle public, its earlier posts become public too.
  • Shared items: items set to “Anyone with the link” can be seen by anyone who has the link. Items on your shelf appear on your profile. Comments on a shared research note can be seen by anyone who can see the note.
  • Search: anyone can search Thaler for public circles, their posts, and people by handle or display name.

5. Who we share information with

Service providers. These companies process information for us to run Thaler. They may only use it to provide their services to us.

ProviderWhat forWhat they receiveWhere
VercelHosting the website, analyticsAll requests to thaler.sh, including IP address and browserUnited States, through a global network
PlanetScaleDatabaseEverything in your accountUnited States
RailwayData services, the API, audio generation and storage, backupsYour user ID, requests to the API (including IP address), the text of your personal audio briefs, database backupsUnited States
AxiomServer logsIP address, browser, pages requested, errorsUnited States
ResendSending emailYour email address and the content of emails we send youUnited States
OpenAIAI featuresThe text of your Ask about the filings questions and the filing passages used to answer them; your Thaler Agent messages, the earlier messages in the same chat and the data the agent looks up to answer them; brief scripts. If Thaler Agent looks at your desk to answer, what it finds there, such as your handle, display name and the companies you follow. Not your email or user IDUnited States

OpenAI doesn’t use this data to train its models. It keeps it for up to 30 days to monitor for abuse, unless it must keep it longer by law or to prevent harm.

Services your browser contacts directly.

  • Brandfetch provides company logos. When a page shows a logo, your browser requests it from Brandfetch, which receives your IP address, browser details, the company and the site you are on (thaler.sh).
  • The SEC and other websites: when you open a filing document, images in it may load from sec.gov or from other websites the filer linked to. Those sites receive your IP address and browser details.
  • Push services: if you turn on push notifications, notifications are delivered through your browser’s push service (for example Google, Apple, Mozilla or Microsoft). The content of each notification is encrypted so that the push service can’t read it.

People and apps you choose. Apps you connect through the MCP app receive the information you let them access, such as your lists, notes, follows and circles. We give apps your handle and display name, not your email address. If you add your podcast feed to a podcast app, that app receives your briefs. Other circle members and people you share with see what you share with them.

Other cases. We may disclose information if the law requires it, to protect the rights and safety of users or others, or to investigate abuse. If Thaler is transferred to someone else, your information would transfer with it and this policy would continue to apply to it.

6. Cookies and storage on your device

We use three cookies, all set by Thaler and all needed for sign-in:

CookieWhat forHow long
thaler_sessionKeeps you signed in90 days, or until you sign out
thaler_challengeLinks a sign-in code to your browser10 minutes
thaler_passkeyCompletes a passkey sign-in or setup5 minutes

Thaler also stores information in your browser’s local storage: your lists, pies, screens, notes and clippings (so you can use Thaler without an account), your email address while you’re signed in, unsent post drafts, recently opened pages and commands, display preferences, and, if you listen while signed out, a random listening ID. Signing out removes your email address from your browser. To remove everything else, clear this site’s data in your browser.

We don’t use advertising or cross-site tracking cookies, and analytics doesn’t use cookies.

7. How long we keep information

InformationHow long
Your account, profile and settingsUntil you delete your account
What you createUntil you delete it or your account. Deleted content disappears from Thaler straight away, and its text is erased from our database within 30 days
Replies you wrote in other people’s threadsTheir text is deleted with your account; a “removed” placeholder stays so the thread still makes sense
Sign-in codes, with your email and hashed IP address30 days
Signed-in device recordsDeleted when you sign out; otherwise 30 days after the session ends
Ask about the filings questions and answers90 days
Thaler Agent chatsUntil you delete them or your account
Daily counts of Thaler Agent questions and refused messages2 days
Records of app (MCP) requests400 days. After you delete your account, they are kept without your identity
API keysUntil you revoke them or delete your account. A revoked or expired key’s record is deleted 90 days later
Records of API requests400 days, or until their key’s record is deleted. Deleted with your account
Requests to connect the Thaler CLI, with your computer’s name1 day after the request expires. A request expires after 10 minutes
Listening records400 days. After you delete your account, they are kept without your identity
Audio of your personal briefs90 days
Requests for Thaler Agent to read a filingKept with a random account number. After you delete your account, nothing links that number to you. The filing’s reading stays public
Email records30 days, at Thaler and at Resend
Server logs30 days at Axiom; up to 30 days at Vercel
Database backups12 months

When you delete your account, we delete it straight away. This also deletes circles you own, including other members’ posts in them. Pages may stay in caches for up to an hour, and copies remain in backups until they expire. We don’t restore deleted accounts from backups.

8. Your choices

  • Change your handle, display name and profile line under Account → Profile, and choose whether the companies you follow appear on your profile.
  • Choose who can see each list, pie, screen and research note, and delete them at any time. Notes on a company are always private.
  • Withdraw a stance, delete posts and replies, and leave circles.
  • Turn emails on or off under Account or from the link in each email, and push notifications on the Your companies page.
  • Disconnect apps under Account → Apps.
  • Sign out of all devices under Account → Sign out everywhere.
  • Delete your account under Account → Delete account.

You can also email support@thaler.sh to ask for a copy of your information, or to correct or delete it. We may need to confirm the request comes from you, usually by replying from your account’s email address. We will reply within 30 days. We won’t treat you differently for making a request.

9. If you are in the UK, the EU or Switzerland

Data protection laws in these places give you extra rights.

Legal bases. We rely on:

  • contract, to provide your account and the features you use;
  • legitimate interests, to keep Thaler secure, prevent abuse, keep logs, measure use with analytics, and publish information from public SEC filings for company research. We have weighed these interests against your rights. You can object to them;
  • consent, for push notifications, which you can withdraw by turning them off;
  • legal obligation, where the law requires us to keep or disclose information.

Your rights. You can ask to access, correct or delete your information, to restrict or object to how we use it, and to receive it in a portable format. Email support@thaler.sh. We will respond within one month, or tell you if we need longer.

Complaints. You can complain to us at support@thaler.sh; we will acknowledge your complaint within 30 days and tell you the outcome. You can also complain to your data protection authority: in the UK, the Information Commission (ICO) at ico.org.uk; in the EU, the authority in your country; in Switzerland, the FDPIC.

International transfers. Thaler is run from the United States. If you use it from elsewhere, your information is processed in the United States, where our service providers process it for us. Our contracts with them protect information from the UK, EU and Switzerland using the EU–US Data Privacy Framework and its UK and Swiss extensions, or the European Commission’s standard contractual clauses and the UK’s equivalent.

Automated decisions. We don’t make decisions about you using only automated means that have legal or similarly significant effects.

10. Security

We use HTTPS for all connections. Sign-in codes, session tokens and app tokens are stored only as hashes, and access to production systems is limited. No system is completely secure. If you think your account is at risk, sign out everywhere and email support@thaler.sh.

11. Children

Thaler is for people aged 18 and over. We don’t knowingly collect information from anyone under 18. If you believe a child has created an account, email support@thaler.sh and we will delete it.

12. Do Not Track

We don’t track you across other websites, so we treat all visitors the same whether or not their browser sends a Do Not Track or Global Privacy Control signal. Brandfetch, and websites that host images in filing documents, receive your IP address when your browser loads their content (see section 5). We don’t know whether they use it to follow activity across websites.

13. Changes to this policy

If we make a material change, we will tell you by email or on Thaler before it takes effect. The effective date at the top shows when this policy last changed.

14. Contact

Email support@thaler.sh.