LEADR← Back to app

Privacy Policy

Effective August 7, 2026 · Ignacius Holdings LLC

This Privacy Policy describes how Ignacius Holdings LLC ("we," "us," "our") collects, uses, and shares information when you use LEADR at leadrlabs.com (the "Service"). It also describes your rights under applicable privacy law.

If you are in the European Economic Area (EEA) or United Kingdom, additional disclosures under the GDPR apply (see Section 10). If you are a California resident, additional disclosures under the CCPA/CPRA apply (see Section 11).


1. Information We Collect

1a. Information you provide directly

  • Account information: name, email address, and authentication credentials collected via Clerk when you create an account or sign in with a third-party provider (Google, etc.).
  • Billing information: payment card details and billing address are collected by our payment provider at checkout and handled entirely on their systems. We never see, receive, or store your raw card number.
  • User-generated content: trade journal entries, notes, custom watchlists, alert configurations, and any other content you create within the Service.
  • Communications: emails or messages you send to our support address.
  • Brokerage/investment account data (optional): if you choose to connect a brokerage account, we receive — through a licensed brokerage data-aggregation provider acting as our sub-processor — the institution name, a masked account number (last four digits only), your portfolio holdings (symbol, quantity, cost basis and price), and your transaction and trade activity history. You enter your brokerage credentials directly with that provider's hosted connection portal; we never receive, see, or store your brokerage username or password, and the connection is read-only — it cannot place trades or move money.

1b. Information collected automatically

  • Usage data: pages viewed, features accessed, search queries, click events, and session duration, collected via PostHog and Vercel Analytics.
  • Session recordings: PostHog session replay captures mouse movements, clicks, and scrolling behavior to help us identify usability problems. Sensitive inputs (passwords, card fields) are masked. You can opt out (see Section 8).
  • Device and browser data: IP address, browser type and version, operating system, referring URL, and screen resolution.
  • Error and performance data: crash reports, stack traces, and request timing collected via Sentry. Sentry captures the URL, user ID, and browser environment at the time of an error.
  • Cookies and local storage: see Section 7.

1c. Data processed by AI features

When you use AI-generated features (such as the pre-market brief or AI-assisted analysis), the relevant market context and, where applicable, your watchlist or preferences are sent to Anthropic's API to generate a response. For free-text features (for example the in-app support assistant), the text you type is sent as written. We do not send your name, email, payment information, or raw journal entries to Anthropic — anything you type yourself into a free-text feature is the one exception, since it is sent exactly as you wrote it. Anthropic's API usage is governed by Anthropic's privacy policy at anthropic.com/legal/privacy.


2. How We Use Your Information

We use the information we collect to:

  • Create and maintain your account, authenticate your identity, and deliver the Service.
  • Process subscription payments and manage billing through Whop, our payment provider.
  • Personalize your experience: save watchlists, alerts, preferences, and journal entries.
  • Display your connected brokerage holdings and activity, and, at your election, import your executed fills into your trade journal.
  • Generate AI-assisted content (pre-market briefs, analytical summaries) using Anthropic's API.
  • Diagnose and fix errors using Sentry crash and performance reports.
  • Understand how the Service is used and improve features using PostHog and Vercel Analytics.
  • Generate and use aggregated or de-identified data derived from use of the Service (data that cannot reasonably be used to identify you) to operate, benchmark, and improve the Service, and for new-product development and marketing. A more specific, more restrictive commitment stated elsewhere in this Policy for a particular data category (for example, support-chat transcripts under Section 5) always controls over this general bullet for that category.
  • Send transactional emails: account confirmation, password reset, billing receipts, and service notices.
  • Enforce our Terms of Service and prevent fraud or abuse.
  • Comply with legal obligations.

De-identified data. Data is de-identified when it has been aggregated or stripped of identifiers such that it cannot reasonably be used, alone or in combination with other information we hold, to infer information about, or otherwise be linked to, you or your household. We take the following measures to keep it that way: cross-user statistics are published only for groups meeting a minimum-population floor (currently at least 5 distinct contributing users and 20 closed trades per statistic, and 7 users and 30 trades for outcome-bearing statistics); we do not publish or disclose the underlying individual-level records; and we do not release the counts or intermediate values that would permit differencing between successive publications. We publicly commit to maintain and use this data solely in de-identified form, and we will not attempt to reidentify it, except where reidentification is strictly necessary to test the effectiveness of these measures or is required by law. Where we disclose de-identified data to any third party, we contractually obligate that recipient to the same commitments and prohibit onward reidentification. Our Terms of Service (Section 9) grants us the right to use and share data meeting this standard; this Section defines and governs the standard itself.

We do not use your personal information or your User Content to train any AI model, whether our own or a third party's, sell your data to advertisers, or share it for cross-context behavioral advertising. The one exception is the aggregate and de-identified data described above, which meets the de-identification standard set out in this Section and is not your User Content itself.


3. Data Shared with Third Parties

We share personal data with the vendors needed to operate the Service, identified in the table below. Separately, we publish aggregate statistics derived from user activity as described in Section 2; those statistics are subject to the de-identification standard and commitments in Section 2.

VendorPurposeData receivedPolicy
ClerkAuthentication and user identityEmail address, name, OAuth tokens, session metadataPrivacy policy
SupabaseDatabase and backend (US region)All user-generated content: watchlists, alerts, journal entries, preferences, and account metadataPrivacy policy
WhopPayment processingEmail, billing address, payment card (handled by the processor; we never receive raw card data)Privacy policy
PostHogProduct analytics and session replayIP address, browser/device info, page views, click events, session recordings (sensitive inputs masked)Privacy policy
SentryError monitoringIP address, browser info, URL at time of error, user ID, stack tracePrivacy policy
VercelHosting and edge analyticsIP address, request logs, page view counts (aggregated)Privacy policy
Brokerage data-aggregation providerRead-only brokerage account connectivity (optional feature)Brokerage authorization, account identifiers, holdings and transaction history
AnthropicAI-generated content (pre-market brief, analytical summaries, support assistant)Market/ticker context and watchlist data sent per-request, and — for free-text features (support assistant, strategy builder) — the text you type. We do not send your name, email, payment data, or journal entries; anything you type yourself is sent as written.Privacy policy

Other members. Certain features (for example, Collective Edge cohort statistics) show aggregate results computed across many members — win rates, average outcomes, and sector or regime breakdowns. Your closed trades contribute to these statistics. A statistic is published only when the group behind it meets our minimum-population floor (at least 5 distinct contributing members and 20 closed trades; 7 members and 30 trades for outcome statistics), and no individual trade, position, or account is ever shown to another member. To stop your trades from contributing, email hello@leadrlabs.com.

We do not sell or rent your personal data to third parties for their own marketing purposes.

We may disclose your information if required by law, subpoena, or court order, or if we believe in good faith that disclosure is necessary to protect our rights or the safety of others. In the event of a merger, acquisition, or sale of all or substantially all of our assets, user data may be transferred to the acquiring entity, subject to the same privacy commitments in this policy.


4. Data Storage and Security

User-generated content and account data are stored in Supabase in the United States (AWS us-east-2, Ohio). We do not currently offer EU data residency; transfers from the EEA/UK are addressed in Section 10.

We implement the following technical safeguards:

  • Encrypted connections: all traffic between your browser and our servers uses TLS (HTTPS). Plaintext HTTP connections are rejected.
  • Encrypted at rest: data stored in Supabase is encrypted at rest using AES-256.
  • Row-level security: database access policies ensure each user can read and write only their own records.
  • No plaintext passwords: authentication is handled entirely by Clerk. Your password is hashed and salted by Clerk and never transmitted to or stored by Ignacius Holdings LLC.
  • Access controls: production data access is limited to authorized personnel only.

No method of transmission over the internet is 100% secure. We cannot guarantee absolute security, but we will notify affected users without undue delay in the event of a data breach that poses material risk, and will comply with applicable breach notification laws.


5. Data Retention

  • Account data: retained for the duration of your account plus 90 days after deletion to allow reactivation and resolve disputes.
  • User-generated content: retained until you delete it or your account is deleted.
  • Billing records: retained for 7 years as required by accounting and tax law.
  • Analytics data (PostHog): retained for up to 12 months, after which it is aggregated or deleted.
  • Error logs (Sentry): retained for 90 days by default.
  • AI request data (Anthropic): per-request context for our analytical AI features is not stored by us after the response is returned. Anthropic's own data retention policies apply to API logs on their infrastructure.
  • Support chat transcripts: if you use the in-app support assistant, the messages you send and the assistant's replies are retained for 90 days and then automatically deleted. We keep them so we can investigate a complaint about what the assistant said, and to detect and correct incorrect answers. They are not used to train any model and are not sold or shared for advertising.
  • Support compliance records: where our automated safeguards stop the support assistant from sending a reply, we keep a record of that event — the date, your account identifier, which safeguard triggered, and a one-way cryptographic hash of the blocked sentence rather than the sentence itself. Because these are the records that let us demonstrate the assistant did not give investment advice, they are retained indefinitely and are exempt from routine deletion.
  • Brokerage connection data (if you connect an account): your brokerage authorization and connection metadata are retained until you disconnect the account or delete your LEADR account, and are deleted within 30 days of either. Transaction records you import into your trade journal are treated as your user-generated content and are retained until you delete them or your account.

To request deletion of your data before the standard retention period expires, email hello@leadrlabs.com with the subject line "Data Deletion Request."


6. Children's Privacy

The Service is intended for users 18 years of age and older. We do not knowingly collect personal data from anyone under 18. If you believe a minor has created an account or provided us with personal data, contact us at hello@leadrlabs.com and we will delete it promptly.


7. Cookies and Tracking

We use the following categories of cookies and local storage. We do not use third-party advertising cookies.

  • Strictly necessary: session authentication tokens set by Clerk (typically named __session and related Clerk cookies). Without these, you cannot stay logged in. These cannot be disabled without breaking the Service.
  • Functional: preferences such as theme settings, watchlist state, and UI layout stored in browser localStorage by the Service itself. No expiry date, cleared when you clear site data.
  • Analytics: PostHog sets a first-party cookie (ph_*) to persist a pseudonymous user ID across sessions and enable session replay. Vercel Analytics is cookieless and processes only aggregated data.

Managing cookies. You can control or delete cookies through your browser settings. Disabling analytics cookies (PostHog) does not affect your ability to use the Service; the strictly necessary Clerk cookies must remain enabled for authentication to work. To decline analytics and session recording, choose "Reject non-essential" or "Customize" in the cookie consent banner when it appears. Your choice applies immediately.

Do Not Track. If your browser sends a Do Not Track (DNT) signal, we automatically treat it as a rejection of all non-essential cookies — analytics and session replay are disabled and the cookie consent banner is not shown. This is the same outcome as choosing "Reject non-essential" yourself; you can still override it through the banner if you later choose to opt in.

Third-party tracking across sites. We do not permit third parties to collect personally identifiable information about your online activities across different websites through the Service, and we do not use third-party advertising or cross-site tracking cookies.


8. Your Rights and Choices

Regardless of where you live, you can:

  • Access and export: export a copy of your saved data (watchlists, journal entries, and trading-rule settings) at any time from your Account page using "Export All." For a complete copy of all personal data we hold, including any category not in that export, email us at hello@leadrlabs.com and we will respond within 30 days.
  • Delete your data: clear your locally-saved watchlist, journal, and trading-rule data at any time from your Account page (Clear Local Data). To permanently delete your account and all associated cloud data, email us at hello@leadrlabs.com and we will complete deletion within 30 days. If you have connected a brokerage account, deleting your LEADR account also revokes that connection at our data-aggregation provider, so no further data can be read from your brokerage; you can revoke the connection at any time without deleting your account, from the Brokerage page. Billing records are retained as required by law, and support compliance records are retained as described in Section 5 — those hold a one-way hash of a blocked sentence rather than its text, and are the records that evidence what our support assistant did not say.
  • Correct inaccurate data: update your name and email in account settings or contact us.
  • Opt out of analytics: decline usage analytics in the cookie consent banner when it appears, or by emailing hello@leadrlabs.com if you have already made a choice and want to change it. Opting out takes effect immediately; no account is required to decline in the banner itself.
  • Withdraw consent: where we rely on consent as a lawful basis, you may withdraw it at any time without affecting the lawfulness of prior processing.

We do not charge a fee for exercising these rights and will not discriminate against you for doing so.


9. External Links

The Service may link to third-party websites (financial data sources, news outlets, regulatory filings). We are not responsible for the privacy practices of those sites. Review their privacy policies before sharing personal information with them.


10. GDPR: EEA and UK Residents

If you are in the European Economic Area or United Kingdom, the following additional disclosures apply under the General Data Protection Regulation (GDPR) and UK GDPR.

Controller. Ignacius Holdings LLC is the data controller for personal data processed through the Service. We are established in the United States and do not actively target the EEA or UK market. Should our processing activities come to require an EU or UK representative under GDPR Article 27, we will appoint one and update this policy.

Lawful bases. We process your personal data under the following lawful bases:

  • Contract: processing necessary to provide the Service you signed up for (authentication, content storage, billing).
  • Legitimate interests: error monitoring, fraud prevention, and product analytics, where our interests do not override your rights.
  • Legal obligation: retention of billing records.
  • Legitimate interests (aggregate insight): generating aggregate, de-identified statistics from usage and trade-journal data to build new features and products and to describe the Service in our marketing. We have assessed this against your rights: the output is never used to make any decision about you individually, is published only above the minimum-population floor in Section 2, and you may object at any time under Article 21 by emailing hello@leadrlabs.com, in which case we will exclude your data from future aggregate computations.

International transfers. Your data is processed in the United States. Transfers from the EEA/UK to the US rely on Standard Contractual Clauses (SCCs) incorporated into our agreements with sub-processors (Supabase, Clerk, Whop, PostHog, Sentry, Vercel, and Anthropic) where applicable.

Your GDPR rights. You have the right to: access your personal data; rectify inaccurate data; request erasure ("right to be forgotten"); restrict processing; receive your data in a portable format; and object to processing based on legitimate interests. To exercise any of these rights, contact us at hello@leadrlabs.com. You also have the right to lodge a complaint with your national data protection authority (e.g., the ICO in the UK, your national DPA in the EEA).

Limit on erasure — support compliance records. The right to erasure is not absolute. Where our automated safeguards stop the support assistant from sending a reply, we retain the compliance record described in Section 5 even after an erasure request. We rely on Article 17(3)(e) GDPR (establishment, exercise or defence of legal claims): these records are what allow us to demonstrate that our assistant did not provide investment advice, and deleting them on request would remove the only evidence capable of answering that question. The record holds a one-way cryptographic hash of the blocked sentence, not its text, and no other content from your conversation. All other support data — including full transcripts — is erased on request.

We will respond to GDPR rights requests within 30 days, extendable by a further 60 days for complex requests (we will notify you of any extension).


11. CCPA/CPRA: California Residents

If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) give you the following rights in addition to those described above:

  • Right to Know: you may request that we disclose the categories of personal information we have collected about you, the purposes for which we collected it, and the categories of third parties with whom we share it.
  • Right to Delete: you may request deletion of your personal information, subject to certain exceptions.
  • Right to Correct: you may request correction of inaccurate personal information.
  • Right to Opt Out of Sale/Sharing: we do not sell your personal information, and we do not share it for cross-context behavioral advertising. Our analytics provider (PostHog) processes data solely as our service provider under contract, not for its own purposes. You can decline analytics in the cookie consent banner when it appears, or by emailing hello@leadrlabs.com to change a choice you already made.
  • Right to Limit Use of Sensitive Personal Information: we do not use sensitive personal information beyond what is necessary to provide the Service.
  • Right to Non-Discrimination: we will not discriminate against you for exercising any of these rights.

To submit a CCPA/CPRA request, email hello@leadrlabs.com with the subject line "California Privacy Request." We will respond within 45 days, with one 45-day extension where reasonably necessary.


12. Other U.S. State Privacy Laws

If you are a resident of a U.S. state with a comprehensive consumer privacy law — including Virginia, Colorado, Connecticut, Utah, Delaware, Texas, and others as they take effect — you may have rights similar to those described in Section 11: to confirm whether we process your personal data and access it, to correct inaccuracies, to request deletion, to obtain a portable copy, and to opt out of targeted advertising, the sale of personal data, or profiling with legal or similarly significant effects. We do not currently sell personal data, use it for targeted advertising, or engage in such profiling; if that changes we will update this policy and provide the applicable opt-out mechanism before doing so. To exercise any state privacy right, or to appeal a decision we make on such a request, email hello@leadrlabs.com. We will respond within the period your state's law requires.


13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes we will update the effective date at the top of this page and, where reasonably practicable, notify you by email or in-app notice at least 14 days before changes take effect. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.


14. Contact and Data Deletion Requests

For privacy questions, data access requests, or data deletion requests:

Email: hello@leadrlabs.com

Mail: Ignacius Holdings LLC: postal address available on request by email.

We aim to acknowledge all requests within 5 business days and resolve them within 30 days (or the applicable legal deadline if shorter).

© 2026 LEADR · leadrlabs.com · Effective August 7, 2026