Privacy Policy
Effective date: May 8, 2026
Last updated: Added Section 4a covering data sent to the Atlas AI provider, retention of chat history, and how to delete it.
This Privacy Policy explains what we collect, how we use it, and the rights you have over your data. By using HeatMap Finance you consent to the practices described here.
1.Information We Collect
Email address: Collected during account registration for authentication purposes. Required to create an account and receive service-related communications.
Usage data: We collect anonymized analytics data via PostHog, including page views, feature usage, and session recordings. This data helps us understand how the platform is used and where to improve.
Payment information: Payment details (credit card, billing address) are collected and processed entirely by Stripe. We do not store, access, or have visibility into your full payment card details at any time.
2.How We Use Your Information
Service operation: Your email is used for authentication, password resets, and account-related notifications.
Analytics and product improvement: Anonymized usage data helps us identify popular features, diagnose issues, and prioritize development.
Email communications: We may send service updates, security alerts, and product announcements. You can opt out of non-essential emails at any time via your account settings.
We do not sell, rent, or share your personal information with third parties for their marketing purposes.
3.Analytics
We use PostHog for product analytics, including page views, feature usage tracking, and session recordings.
Analytics data is anonymized by default. We do not identify individual users in analytics until they have logged in, at which point their session may be linked to their account for the purpose of understanding feature usage patterns.
Session recordings capture page interactions (clicks, scrolls, navigation) but automatically redact sensitive input fields such as passwords and payment forms.
You can opt out of analytics tracking in your account settings.
4.Third-Party Services
Stripe: Handles all payment processing. Subject to Stripe's Privacy Policy (https://stripe.com/privacy).
Supabase: Provides database hosting and authentication infrastructure. Subject to Supabase's Privacy Policy (https://supabase.com/privacy).
PostHog: Provides product analytics and session recording. Subject to PostHog's Privacy Policy (https://posthog.com/privacy).
Financial Modeling Prep (FMP): Provides market data (ETF and stock prices, performance, AUM). No personal user data is shared with FMP.
Anthropic: Powers AI-assisted features (Atlas). Queries are processed without associating them to your identity. Subject to Anthropic's Privacy Policy (https://www.anthropic.com/privacy). See Section 4a below for the specific data we send and how long we retain it.
4a.Atlas AI Tool: Data Handling
What we send. When you use Atlas, the following are transmitted to our AI provider (Anthropic, PBC) for processing: (1) your message text; (2) recent ticker mentions extracted from your conversation; (3) your portfolio holdings if you have linked or imported them; (4) your watchlist tickers; (5) recently-viewed tickers; and (6) a short string describing the page you opened Atlas from. Your email, account ID, and any unrelated personal data are not sent.
Retention. Atlas conversations and individual messages are stored in our atlas_conversations and atlas_messages tables, scoped to your user account by row-level security. Anthropic's retention is governed by their commercial terms; we do not control how Anthropic logs or trains future models on inference traffic.
Your control. You can delete any individual Atlas conversation from the conversation list. You can wipe all your Atlas history by deleting your account (per Section 6). To request a one-time export or deletion of your Atlas data without closing your account, contact support@heatmapfinance.com.
Anonymous demo usage. The /public/atlas-demo surface is rate-limited per IP; messages from anonymous users are processed by Anthropic but not persisted in our database.
Acceptance. The first time you open any Atlas surface, an acknowledgement explains the educational-only nature of the tool and you must explicitly accept the disclaimer to continue. See the Terms of Service Section 8a for the full set of clauses you accept.
5.Cookies & Local Storage
HeatMap Finance does not use cookies for tracking or advertising.
We use browser localStorage to store your preferences (theme selection, sidebar state) and an httpOnly cookie for your authenticated session. Preference data stays on your device and is not transmitted to any server except as needed for authentication.
Because we do not use tracking cookies, no cookie consent banner is required.
6.Data Retention
Account data (email, profile, portfolios, watchlists) is retained for as long as your account is active.
Analytics data is retained for a maximum of 12 months, after which it is automatically purged.
When you delete your account, all associated personal data will be permanently deleted within 30 days. Some anonymized, aggregated analytics data may be retained as it cannot be linked back to your identity.
7.Your Rights (PIPEDA)
Under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable Canadian privacy legislation, you have the right to:
Access: Request a copy of the personal information we hold about you.
Correction: Request that we correct any inaccurate or incomplete personal information.
Deletion: Request that we delete your personal information and close your account.
Withdrawal of consent: Withdraw consent for non-essential data processing at any time.
To exercise any of these rights, contact us at support@heatmapfinance.com. We will respond to your request within 30 days.
8.Security
Authentication is handled by Supabase Auth with bcrypt password hashing. Passwords are never stored in plain text.
All data in transit is encrypted via HTTPS/TLS. API keys and secrets are stored server-side and are never exposed in client-side code.
We conduct regular reviews of our security practices and dependencies. If you discover a security vulnerability, please report it to support@heatmapfinance.com.
9.Children
HeatMap Finance is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13.
If we become aware that we have collected personal information from a child under 13, we will take steps to delete that information promptly.
10.Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date.
For material changes, we will provide notice via email or a prominent in-app notification at least 30 days before the changes take effect.
11.Contact
If you have questions or concerns about this Privacy Policy or your personal data, contact us at support@heatmapfinance.com.
See also: Terms of Service