This Privacy Policy describes how Leadr Labs, Inc. ("we," "us," "our") collects, uses, and shares information when you use LEADR at leadrlabs.com (the "Service"). It also describes your rights under applicable privacy law.
If you are in the European Economic Area (EEA) or United Kingdom, additional disclosures under the GDPR apply (see Section 10). If you are a California resident, additional disclosures under the CCPA/CPRA apply (see Section 11).
Contents
1. Information We Collect
1a. Information you provide directly
Account information: name, email address, and authentication credentials collected via Clerk when you create an account or sign in with a third-party provider (Google, etc.).
Billing information: payment card details and billing address are collected by our payment provider at checkout and handled entirely on their systems. We never see, receive, or store your raw card number.
User-generated content: trade journal entries, notes, custom watchlists, alert configurations, and any other content you create within the Service.
Communications: emails or messages you send to our support address.
Launch-notification signups: if you ask us to tell you when paid plans launch, we collect the email address you enter and a record of your consent — the version of this Policy you agreed to, the date and time, the IP address the request came from, and your browser's user-agent string. You do not need an account to sign up, and we ask for nothing else. Nothing is sent to that address until you click a confirmation link we email you. See Section 5 for how long each of these is kept.
Brokerage/investment account data (optional): if you choose to connect a brokerage account, we receive — through SnapTrade, our licensed brokerage data-aggregation sub-processor — the institution name, a masked account number (last four digits only), your portfolio holdings (symbol, quantity, cost basis and price), and your transaction and trade activity history. You enter your brokerage credentials directly with SnapTrade's hosted connection portal; we never receive, see, or store your brokerage username or password. The connection is read-only: it can view your holdings and trade activity, but it cannot place trades or move money.
1b. Information collected automatically
Usage data: pages viewed, features accessed, search queries, click events, and session duration, collected via PostHog and Vercel Analytics.
Session recordings: PostHog session replay captures mouse movements, clicks, and scrolling behavior to help us identify usability problems. Sensitive inputs (passwords, card fields) are masked. You can opt out (see Section 8).
Device and browser data: IP address, browser type and version, operating system, referring URL, and screen resolution.
Error and performance data: crash reports, stack traces, and page and navigation timing collected via Sentry. Sentry captures the page URL, user ID, and browser environment when an error occurs, and a sampled portion of ordinary page loads for performance measurement.
Cookies and local storage: see Section 7.
1c. Data processed by AI features
When you use AI-generated features (such as the pre-market brief or AI-assisted analysis), the relevant market context and, where applicable, your watchlist or preferences are sent to Anthropic's API to generate a response. For free-text features (for example the in-app support assistant), the text you type is sent as written. We do not send your name, email, payment information, or raw journal entries to Anthropic — anything you type yourself into a free-text feature is the one exception, since it is sent exactly as you wrote it. Anthropic's API usage is governed by Anthropic's privacy policy at anthropic.com/legal/privacy.
2. How We Use Your Information
We use the information we collect to:
Create and maintain your account, authenticate your identity, and deliver the Service.
Process subscription payments and manage billing through Whop, our payment provider.
Personalize your experience: save watchlists, alerts, preferences, and journal entries.
Display your connected brokerage holdings and activity, and, at your election, import your executed fills into your trade journal.
Generate AI-assisted content (pre-market briefs, analytical summaries) using Anthropic's API.
Diagnose and fix errors using Sentry crash and performance reports.
Understand how the Service is used and improve features using PostHog and Vercel Analytics.
Generate and use aggregated or de-identified data derived from use of the Service (data that cannot reasonably be used to identify you) to operate, benchmark, and improve the Service, and for new-product development and marketing. A more specific, more restrictive commitment stated elsewhere in this Policy for a particular data category (for example, support-chat transcripts under Section 5) always controls over this general bullet for that category.
Send transactional emails: account confirmation, password reset, billing receipts, and service notices.
Send the launch notification you asked for: if you signed up to be told when paid plans launch, we email you once to confirm the address is yours, and after that only when there is a paid-plan launch to announce. This is separate from the transactional emails above; every message carries a one-click unsubscribe, and we stop as soon as you use it.
Enforce our Terms of Service and prevent fraud or abuse.
Comply with legal obligations.
De-identified data. Data is de-identified when it is aggregated or stripped of identifiers so that it cannot reasonably be used — alone or with other information we hold — to infer anything about, or be linked back to, you or your household. We keep it that way through:
A minimum-population floor before we publish any cross-user statistic: at least 5 distinct contributing users and 20 closed trades per statistic, or 7 users and 30 trades for outcome-bearing statistics.
No publication or disclosure of the underlying individual-level records.
No release of the counts or intermediate values that would let someone difference two successive publications back to an individual.
A standing commitment not to attempt reidentification, except where strictly necessary to test these safeguards or required by law.
The same commitments, contractually, on any third party we disclose de-identified data to — including a ban on that party attempting reidentification.
Our Terms of Service (Section 9) grants us the right to use and share data meeting this standard; this Section defines and governs the standard itself.
We do not use your personal information or your User Content to train any AI model, whether our own or a third party's, sell your data to advertisers, or share it for cross-context behavioral advertising. The one exception is the aggregate and de-identified data described above, which meets the de-identification standard set out in this Section and is not your User Content itself.
3. Data Shared with Third Parties
The table below lists the vendors involved in operating the Service and what each receives from us. Not every vendor receives personal data — see each row for specifics. Separately, we publish aggregate statistics derived from user activity as described in Section 2; those statistics are subject to the de-identification standard and commitments in Section 2.
Brokerage authorization, account identifiers, holdings and transaction history. Account numbers are masked (last four digits only) and your brokerage login credentials are never sent to or seen by us — you enter them directly with SnapTrade's own hosted connection portal.
—
Anthropic
AI-generated content (pre-market brief, analytical summaries, support assistant)
Market/ticker context and watchlist data sent per-request, and — for free-text features (support assistant, strategy builder) — the text you type. We do not send your name, email, payment data, or journal entries; anything you type yourself is sent as written.
AI observability — logging and tracing for the AI features listed above
A redacted subset only, not a mirror of what Anthropic receives: your Clerk user ID, and — per AI generation — a small set of non-identifying scalar fields (ticker, sector, direction, grade, confidence score, signals-aligned count, regime, setup type, days to next earnings). Free-text prompts, names, and account data are never sent to Langfuse. Separately, when our support-chat compliance safeguards block a reply, we also send Langfuse a copy of that event (your user ID and a coarse violation-tier label only — never the blocked message text) so the trip is alertable. Processed in the EU by default (our Langfuse instance's default region), not the US, unless we configure a US-region host.
Market-data source our scoring model is partly derived from (options flow, dark-pool prints, short-interest data)
None from you — this is a one-way data source. We pull market and options data from Unusual Whales server-side to compute our own derived scores; the Service displays that derived score, not Unusual Whales's raw feed, and we send Unusual Whales no personal or user data in either direction.
Distributed rate-limit counter (abuse and spam prevention for our API layer)
Your Clerk user ID (if signed in) or your IP address, used only as a short-lived counter key; no other personal data. These keys expire automatically within a couple of minutes. A separate per-user daily API quota counter — same identifier, different mechanism — is stored in Supabase (not this vendor) and expires within 24 hours; see the Supabase row above.
—
Other members. Certain features (for example, Collective Edge cohort statistics) show aggregate results computed across many members — win rates, average outcomes, and sector or regime breakdowns. Your closed trades contribute to these statistics. A statistic is published only when the group behind it meets our minimum-population floor (at least 5 distinct contributing members and 20 closed trades; 7 members and 30 trades for outcome statistics), and no individual trade, position, or account is ever shown to another member. To stop your trades from contributing, email hello@leadrlabs.com.
We do not sell or rent your personal data to third parties for their own marketing purposes.
We may disclose your information if required by law, subpoena, or court order, or if we believe in good faith that disclosure is necessary to protect our rights or the safety of others. In the event of a merger, acquisition, or sale of all or substantially all of our assets, user data may be transferred to the acquiring entity, subject to the same privacy commitments in this policy.
4. Data Storage and Security
User-generated content and account data are stored in Supabase in the United States (AWS us-east-2, Ohio). We do not currently offer EU data residency; transfers from the EEA/UK are addressed in Section 10.
We implement the following technical safeguards:
Encrypted connections: all traffic between your browser and our servers uses TLS (HTTPS). Plaintext HTTP connections are rejected.
Encrypted at rest: data stored in Supabase is encrypted at rest using AES-256.
Row-level security: database access policies ensure each user can read and write only their own records.
No plaintext passwords: authentication is handled entirely by Clerk. Your password is hashed and salted by Clerk and never transmitted to or stored by Leadr Labs, Inc..
Access controls: production data access is limited to authorized personnel only.
No method of transmission over the internet is 100% secure. We cannot guarantee absolute security, but we will notify affected users without undue delay in the event of a data breach that poses material risk, and will comply with applicable breach notification laws.
5. Data Retention
Account data: retained for the duration of your account plus 90 days after deletion to allow reactivation and resolve disputes.
User-generated content: retained until you delete it or your account is deleted.
Billing records: retained for 7 years as required by accounting and tax law.
Analytics data (PostHog): retained for up to 12 months, after which it is aggregated or deleted.
Error logs (Sentry): retained for 90 days by default.
AI request data (Anthropic): per-request context for our analytical AI features is not stored by us after the response is returned. Anthropic's own data retention policies apply to API logs on their infrastructure.
Support chat transcripts: if you use the in-app support assistant, the messages you send and the assistant's replies are retained for 90 days and then automatically deleted. We keep them so we can investigate a complaint about what the assistant said, and to detect and correct incorrect answers. They are not used to train any model and are not sold or shared for advertising.
Support compliance records: where our automated safeguards stop the support assistant from sending a reply, we keep a record of that event — the date, your account identifier, which safeguard triggered, and a one-way cryptographic hash of the blocked sentence rather than the sentence itself. Because these are the records that let us demonstrate the assistant did not give investment advice, they are retained indefinitely and are exempt from routine deletion.
Brokerage connection data (if you connect an account): your brokerage authorization and connection metadata are retained while your connection is active. If you disconnect, we immediately revoke the authorization at SnapTrade so it can no longer read your brokerage; we retain the connection identifier itself so you can reconnect without re-registering, until you delete your LEADR account, at which point it — along with any imported activity — is deleted at the end of the 90-day reactivation window described above. Transaction records you import into your trade journal are treated as your user-generated content and are retained until you delete them or your account.
Market data (Unusual Whales): options-flow, dark-pool, and short-interest data we pull from Unusual Whales to compute our own scores is processed transiently and is not retained as user data. No personal information is sent to Unusual Whales in either direction.
Launch-notification list: the address you give us is kept until you unsubscribe or ask us to delete it. If you never confirm it, the confirmation link stops working after 7 days and the unconfirmed record is kept until we clear it or you ask us to. If you unsubscribe, we keep a suppression record of your address indefinitely and deliberately — that record is what stops a later import from adding you back by mistake, and it is used for nothing else. The consent record described in Section 1a (the Policy version you agreed to, the date and time, the IP address, and your browser user-agent) is kept for the life of the record, because it is our evidence that you opted in.
Rate-limit counters (Upstash / Vercel KV and Supabase): your Clerk user ID (if signed in) or IP address is stored as a short-lived counter key used only to detect and block abusive request volume against our API, for no other purpose. The Upstash/Vercel KV counters expire within a couple of minutes; a separate per-user daily quota counter stored in Supabase expires within 24 hours. One of these counters caps how many confirmation emails a single mailbox can be sent in a day, to stop the signup form being used to flood someone else's inbox; its key is a one-way hash of the address, never the address itself, and it also expires within 24 hours.
To request deletion of your data before the standard retention period expires, email hello@leadrlabs.com with the subject line "Data Deletion Request."
6. Children's Privacy
The Service is intended for users 18 years of age and older. We do not knowingly collect personal data from anyone under 18. If you believe a minor has created an account or provided us with personal data, contact us at hello@leadrlabs.com and we will delete it promptly.
7. Cookies and Tracking
We use the following categories of cookies and local storage. We do not use third-party advertising cookies.
Strictly necessary: session authentication tokens set by Clerk (typically named __session and related Clerk cookies). Without these, you cannot stay logged in. These cannot be disabled without breaking the Service.
Functional: preferences such as theme settings, watchlist state, and UI layout stored in browser localStorage by the Service itself. No expiry date, cleared when you clear site data.
Analytics: PostHog sets a first-party cookie (ph_*) to persist a pseudonymous user ID across sessions and enable session replay. Vercel Analytics is cookieless and processes only aggregated data.
Managing cookies. You can control or delete cookies through your browser settings. Disabling analytics cookies (PostHog) does not affect your ability to use the Service; the strictly necessary Clerk cookies must remain enabled for authentication to work. To decline analytics and session recording, choose "Reject non-essential" or "Customize" in the cookie consent banner when it appears. Your choice applies immediately.
Do Not Track. If your browser sends a Do Not Track (DNT) signal, we automatically treat it as a rejection of all non-essential cookies — analytics and session replay are disabled and the cookie consent banner is not shown. This is the same outcome as choosing "Reject non-essential" yourself; you can still override it through the banner if you later choose to opt in.
Third-party tracking across sites. We do not permit third parties to collect personally identifiable information about your online activities across different websites through the Service, and we do not use third-party advertising or cross-site tracking cookies.
8. Your Rights and Choices
Regardless of where you live, you can:
Access and export: export a copy of your saved data (watchlists, journal entries, and trading-rule settings) at any time from your Account page using "Export All." For a complete copy of all personal data we hold, including any category not in that export, email us at hello@leadrlabs.com and we will respond within 30 days.
Clear local data: remove your locally-saved watchlist, journal, and trading-rule data at any time from your Account page (Clear Local Data). This clears only what's stored on this device; it does not delete your cloud account.
Delete your account — Free tier: use Delete My Account on your Account page's Data, Privacy & Connections tab. This immediately anonymizes your profile and gives you 90 days to change your mind (Reactivate My Account, same page); after that window your journal, watchlists, trade plans, rule settings, and saved preferences are permanently and automatically deleted, matching the retention period in Section 5.
Delete your account — paid Subscription: cancel your Subscription first, under Billing in your account settings. Cancellation takes effect at the end of your current billing period (Section 6 of our Terms), and Delete My Account becomes available once your account reverts to the Free tier — not immediately on clicking cancel. This sequencing protects you: it exists so a destructive account deletion never leaves a live Subscription still charging your card with no account left to manage or cancel it.
Brokerage connections: if you have connected a brokerage account through SnapTrade, deleting your LEADR account deletes our own record of that connection when your data is purged; it does not by itself revoke the connection at SnapTrade, so revoke it directly — at any time, whether or not you're deleting your account — from the Brokerage page.
What deletion doesn't reach: billing records are retained for 7 years as required by law, and support compliance records are retained as described in Section 5 — those hold a one-way hash of a blocked sentence rather than its text, and are the records that evidence what our support assistant did not say.
Can't sign in? Email us at hello@leadrlabs.com and we will process the deletion for you — including cancelling a paid Subscription first if you have one, so you're never left both locked out and still being charged.
Correct inaccurate data: update your name and email in account settings or contact us.
Opt out of analytics: decline usage analytics in the cookie consent banner when it appears, or by emailing hello@leadrlabs.com if you have already made a choice and want to change it. Opting out takes effect immediately; no account is required to decline in the banner itself.
Withdraw consent: where we rely on consent as a lawful basis, you may withdraw it at any time without affecting the lawfulness of prior processing.
We do not charge a fee for exercising these rights and will not discriminate against you for doing so.
9. External Links
The Service may link to third-party websites (financial data sources, news outlets, regulatory filings). We are not responsible for the privacy practices of those sites. Review their privacy policies before sharing personal information with them.
10. GDPR: EEA and UK Residents
If you are in the European Economic Area or United Kingdom, the following additional disclosures apply under the General Data Protection Regulation (GDPR) and UK GDPR.
Controller. Leadr Labs, Inc. is the data controller for personal data processed through the Service. We are established in the United States and do not actively target the EEA or UK market. Should our processing activities come to require an EU or UK representative under GDPR Article 27, we will appoint one and update this policy.
Lawful bases. We process your personal data under the following lawful bases:
Contract: processing necessary to provide the Service you signed up for (authentication, content storage, billing).
Legitimate interests: error monitoring, fraud prevention, and product analytics, where our interests do not override your rights.
Legal obligation: retention of billing records.
Legitimate interests (aggregate insight): generating aggregate, de-identified statistics from usage and trade-journal data to build new features and products and to describe the Service in our marketing. We have assessed this against your rights: the output is never used to make any decision about you individually, is published only above the minimum-population floor in Section 2, and you may object at any time under Article 21 by emailing hello@leadrlabs.com, in which case we will exclude your data from future aggregate computations.
International transfers. Your data is processed primarily in the United States, with one exception: our AI-observability subprocessor (Langfuse) is hosted in the EU by default, so the redacted trace data described in Section 3's Langfuse row is processed there rather than in the US, unless we configure a US-region host. Transfers from the EEA/UK to the US — and, for Langfuse, the transfer in the other direction — rely on Standard Contractual Clauses (SCCs) incorporated into our agreements with sub-processors (Supabase, Clerk, Whop, PostHog, Sentry, Vercel, Anthropic, Resend, Langfuse, SnapTrade, and the Upstash/Vercel KV rate-limiting store) where applicable. Unusual Whales supplies market data we use to compute our own scores and does not receive personal data from us, so no SCC applies to that relationship.
Your GDPR rights. You have the right to: access your personal data; rectify inaccurate data; request erasure ("right to be forgotten"); restrict processing; receive your data in a portable format; and object to processing based on legitimate interests. To exercise any of these rights, contact us at hello@leadrlabs.com. You also have the right to lodge a complaint with your national data protection authority (e.g., the ICO in the UK, your national DPA in the EEA).
Limit on erasure — support compliance records. The right to erasure is not absolute. Where our automated safeguards stop the support assistant from sending a reply, we retain the compliance record described in Section 5 even after an erasure request. We rely on Article 17(3)(e) GDPR (establishment, exercise or defence of legal claims): these records are what allow us to demonstrate that our assistant did not provide investment advice, and deleting them on request would remove the only evidence capable of answering that question. The record holds a one-way cryptographic hash of the blocked sentence, not its text, and no other content from your conversation. All other support data — including full transcripts — is erased on request.
We will respond to GDPR rights requests within 30 days, extendable by a further 60 days for complex requests (we will notify you of any extension).
11. CCPA/CPRA: California Residents
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) give you the following rights in addition to those described above:
Right to Know: you may request that we disclose the categories of personal information we have collected about you, the purposes for which we collected it, and the categories of third parties with whom we share it.
Right to Delete: you may request deletion of your personal information, subject to certain exceptions.
Right to Correct: you may request correction of inaccurate personal information.
Right to Opt Out of Sale/Sharing: we do not sell your personal information, and we do not share it for cross-context behavioral advertising. Our analytics provider (PostHog) processes data solely as our service provider under contract, not for its own purposes. You can decline analytics in the cookie consent banner when it appears, or by emailing hello@leadrlabs.com to change a choice you already made.
Right to Limit Use of Sensitive Personal Information: we do not use sensitive personal information beyond what is necessary to provide the Service.
Right to Non-Discrimination: we will not discriminate against you for exercising any of these rights.
To submit a CCPA/CPRA request, email hello@leadrlabs.com with the subject line "California Privacy Request." We will respond within 45 days, with one 45-day extension where reasonably necessary.
12. Other U.S. State Privacy Laws
If you are a resident of a U.S. state with a comprehensive consumer privacy law — including Virginia, Colorado, Connecticut, Utah, Delaware, Texas, and others as they take effect — you may have rights similar to those described in Section 11: to confirm whether we process your personal data and access it, to correct inaccuracies, to request deletion, to obtain a portable copy, and to opt out of targeted advertising, the sale of personal data, or profiling with legal or similarly significant effects. We do not currently sell personal data, use it for targeted advertising, or engage in such profiling; if that changes we will update this policy and provide the applicable opt-out mechanism before doing so. To exercise any state privacy right, or to appeal a decision we make on such a request, email hello@leadrlabs.com. We will respond within the period your state's law requires.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes we will update the effective date at the top of this page and, where reasonably practicable, notify you by email or in-app notice at least 14 days before changes take effect. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.
14. Contact and Data Deletion Requests
For privacy questions, data access requests, or data deletion requests: