Privacy Policy
Effective September 28, 2026
This policy explains what information Thaler collects, how it is used, who it is shared with, how long it is kept, and the choices you have. Thaler (“we”, “us”) is responsible for your information. Contact: support@thaler.sh.
Summary
- You can use most of Thaler without an account. Without one, your lists, notes and settings stay in your browser.
- With an account, we store your email address and what you create and save.
- Some things are public: your profile page, your stances, public circles and anything you share by link or put on your shelf.
- We use service providers to host Thaler, send email, keep logs and run AI features. We don’t sell your information, show ads, or track you on other websites.
- You can delete your account at any time under Account → Delete account.
1. What we collect
Account. Your email address. A handle (we create a random one; you can change it), and a display name and profile line if you add them. When you request a sign-in code, we store your email and a one-way hash of your IP address. For each signed-in device, we store a description of your browser and device (the user agent) and when it was last used. If you add a passkey, we store its public key and a name for the device.
What you create. Watchlists, pies (including any amount you enter to simulate an investment), screens, notes, clippings, posts, replies, comments, stances, circles and circle images, and your settings. Circle images are resized and their metadata is removed.
What you do on Thaler. The companies you follow, the circles you join, which posts and comments you’ve read, reports you make, and when you were last active.
Questions you ask. When you use Ask about the filings, we store your question, the company, the answer and what it cost to produce.
Chats with Thaler Agent. When you chat with Thaler Agent, we store your chats: your messages, the agent’s answers and the steps it took to find them, the companies they mention, each chat’s name, and what each answer cost to produce. To apply limits, we also count how many questions you ask each day and how many of your messages our moderation check refuses.
Apps you connect. When you connect an AI assistant or other app through the Thaler MCP app, we store the app’s name, the access you gave it and when it was last used. For each request it makes, we record the time, the tool used, whether it worked, the size of the response and the company or search term it was about. We don’t store the rest of the request.
API keys. If you create API keys, we store each key’s name, a one-way hash of the key (not the key itself), its last four characters, and when it was created, last used, expires or was revoked. For each minute in which a key is used, we record the endpoint, the response status, the number of requests, their size and how long they took. For each day, we record which kind of client made the requests: one of our SDKs and its version, or the family of program the user agent names (curl, a Python library, a browser), never the user agent itself. We don’t store the rest of the request. If GitHub finds one of your keys in public, it sends us the key and the address where it was found; we revoke the key, keep that address with it and email you. When you connect the Thaler CLI, it sends us the name your computer gives itself, its operating system and the CLI’s version with the request; the key you confirm is named for the computer.
Email and notifications. Your email settings and a record of the emails we’ve scheduled for you. If you turn on push notifications, we store the address your browser gives us for them and a description of your browser.
Listening. Which briefs you play, how far you listen and at what speed. If you aren’t signed in, we link this to a random ID stored in your browser.
Technical information. When you use Thaler, our servers receive your IP address, browser and device type, the page or address requested, the page you came from, and how quickly pages load. We use this to run and secure Thaler and to fix errors, and we keep it in server logs. We derive your country from your IP address. We don’t store your precise location.
Analytics. We use Vercel Web Analytics and Speed Insights to count visits and measure how fast pages load. They record the page, the referring site, your approximate location (country, region and city), browser, operating system, device type and page-load timings. They don’t use cookies. Visitors are counted using a code created from each request that changes every day, so you aren’t tracked from one day to the next. We don’t send sign-in, email-settings or app-connection pages to analytics, and we remove query strings from the addresses we send.
2. People named in SEC filings
Thaler republishes information from public filings on the SEC’s EDGAR system. This includes the names of company insiders (directors, officers and large shareholders), their roles, and the transactions and holdings they report, and the names of investment managers and their reported holdings. We use this information to provide company research. We show it as it appears in the filings. We don’t add information about these people from other sources.
If you are named in a filing and think we’ve shown something incorrectly, email support@thaler.sh. We will correct errors in how we processed the filing. We can’t change what the filing itself says; corrections to a filing must be made with the SEC.
3. How we use information
- To provide Thaler: your account, sign-in, saving and syncing what you create, circles, sharing, emails and notifications you’ve asked for, AI features and apps you connect.
- To keep Thaler secure and working: to prevent abuse, enforce limits, investigate problems and fix errors.
- To understand how Thaler is used and improve it, using analytics and logs.
- To handle reports, enforce our Terms of Service, and meet legal obligations.
We don’t use your information for advertising, and we don’t sell it or share it for cross-context behavioural advertising.
4. What is public
- Your profile page at thaler.sh/@your-handle can be seen by anyone and found by search engines. It shows your handle, display name, profile line, when you joined, your stances, items on your shelf, public circles you show on your profile, and the companies you follow. You can hide the companies you follow under Account.
- Stances always appear on your profile. Company pages also show how many people are bullish or bearish, and name up to six followers who show their follows on their profile.
- Public circles can be read by anyone, including their posts, replies, placed items and member list. Posts in invite-only circles can only be seen by members, and by us if a post is reported. If the owner makes a circle public, its earlier posts become public too.
- Shared items: items set to “Anyone with the link” can be seen by anyone who has the link. Items on your shelf appear on your profile. Comments on a shared research note can be seen by anyone who can see the note.
- Search: anyone can search Thaler for public circles, their posts, and people by handle or display name.
7. How long we keep information
| Information | How long |
|---|---|
| Your account, profile and settings | Until you delete your account |
| What you create | Until you delete it or your account. Deleted content disappears from Thaler straight away, and its text is erased from our database within 30 days |
| Replies you wrote in other people’s threads | Their text is deleted with your account; a “removed” placeholder stays so the thread still makes sense |
| Sign-in codes, with your email and hashed IP address | 30 days |
| Signed-in device records | Deleted when you sign out; otherwise 30 days after the session ends |
| Ask about the filings questions and answers | 90 days |
| Thaler Agent chats | Until you delete them or your account |
| Daily counts of Thaler Agent questions and refused messages | 2 days |
| Records of app (MCP) requests | 400 days. After you delete your account, they are kept without your identity |
| API keys | Until you revoke them or delete your account. A revoked or expired key’s record is deleted 90 days later |
| Records of API requests | 400 days, or until their key’s record is deleted. Deleted with your account |
| Requests to connect the Thaler CLI, with your computer’s name | 1 day after the request expires. A request expires after 10 minutes |
| Listening records | 400 days. After you delete your account, they are kept without your identity |
| Audio of your personal briefs | 90 days |
| Requests for Thaler Agent to read a filing | Kept with a random account number. After you delete your account, nothing links that number to you. The filing’s reading stays public |
| Email records | 30 days, at Thaler and at Resend |
| Server logs | 30 days at Axiom; up to 30 days at Vercel |
| Database backups | 12 months |
When you delete your account, we delete it straight away. This also deletes circles you own, including other members’ posts in them. Pages may stay in caches for up to an hour, and copies remain in backups until they expire. We don’t restore deleted accounts from backups.
8. Your choices
- Change your handle, display name and profile line under Account → Profile, and choose whether the companies you follow appear on your profile.
- Choose who can see each list, pie, screen and research note, and delete them at any time. Notes on a company are always private.
- Withdraw a stance, delete posts and replies, and leave circles.
- Turn emails on or off under Account or from the link in each email, and push notifications on the Your companies page.
- Disconnect apps under Account → Apps.
- Sign out of all devices under Account → Sign out everywhere.
- Delete your account under Account → Delete account.
You can also email support@thaler.sh to ask for a copy of your information, or to correct or delete it. We may need to confirm the request comes from you, usually by replying from your account’s email address. We will reply within 30 days. We won’t treat you differently for making a request.
9. If you are in the UK, the EU or Switzerland
Data protection laws in these places give you extra rights.
Legal bases. We rely on:
- contract, to provide your account and the features you use;
- legitimate interests, to keep Thaler secure, prevent abuse, keep logs, measure use with analytics, and publish information from public SEC filings for company research. We have weighed these interests against your rights. You can object to them;
- consent, for push notifications, which you can withdraw by turning them off;
- legal obligation, where the law requires us to keep or disclose information.
Your rights. You can ask to access, correct or delete your information, to restrict or object to how we use it, and to receive it in a portable format. Email support@thaler.sh. We will respond within one month, or tell you if we need longer.
Complaints. You can complain to us at support@thaler.sh; we will acknowledge your complaint within 30 days and tell you the outcome. You can also complain to your data protection authority: in the UK, the Information Commission (ICO) at ico.org.uk; in the EU, the authority in your country; in Switzerland, the FDPIC.
International transfers. Thaler is run from the United States. If you use it from elsewhere, your information is processed in the United States, where our service providers process it for us. Our contracts with them protect information from the UK, EU and Switzerland using the EU–US Data Privacy Framework and its UK and Swiss extensions, or the European Commission’s standard contractual clauses and the UK’s equivalent.
Automated decisions. We don’t make decisions about you using only automated means that have legal or similarly significant effects.
10. Security
We use HTTPS for all connections. Sign-in codes, session tokens and app tokens are stored only as hashes, and access to production systems is limited. No system is completely secure. If you think your account is at risk, sign out everywhere and email support@thaler.sh.
11. Children
Thaler is for people aged 18 and over. We don’t knowingly collect information from anyone under 18. If you believe a child has created an account, email support@thaler.sh and we will delete it.
12. Do Not Track
We don’t track you across other websites, so we treat all visitors the same whether or not their browser sends a Do Not Track or Global Privacy Control signal. Brandfetch, and websites that host images in filing documents, receive your IP address when your browser loads their content (see section 5). We don’t know whether they use it to follow activity across websites.
13. Changes to this policy
If we make a material change, we will tell you by email or on Thaler before it takes effect. The effective date at the top shows when this policy last changed.
14. Contact
Email support@thaler.sh.