Policy
Privacy Policy
This Privacy Policy describes how BudFox.ai (“BudFox,” “we,” “us”) collects, uses, and shares information when you visit www.budfox.ai, sign in, or use our desk notes, chat, blotter, map, or related services (the “Service”).
BudFox provides informational and educational market intelligence. It is not a registered investment adviser, broker-dealer, or financial planner. This policy is about data, not trading advice.
1. Information we collect
Account and identity
When you request access or sign in, we collect your name and email address. Authentication is handled with magic links through our identity provider (Stytch). We store a session cookie so you stay signed in.
Waitlist and acknowledgments
If you join a waitlist or acknowledge our disclaimer, we store the name and email you submit, the time of the submission, and a source label (for example, live desk). We may also keep a local acknowledgment flag in your browser.
Brokerage connection (optional)
If you connect Alpaca, you provide API credentials so we can read paper or live account data you authorize (positions, equity, and related blotter inputs). Treat those credentials as secrets. Disconnecting removes our ability to fetch that account data going forward.
Usage, chat, and device
We may collect:
- Pages viewed, approximate visit counts, and whether you used the web app or MCP tools.
- Chat messages you send to the desk assistant, and related memo context used to answer them.
- Technical logs such as IP address, user agent, timestamps, and error diagnostics on Cloudflare.
- Browser storage for preferences (for example mailbox sort) and a local client identifier used to count unique visitors.
Market data (not about you)
The Service fetches public and licensed market, news, filings, and options data from third-party sources. That data is about securities and the market, not about you, except to the extent it appears in a note or chat you requested.
2. How we use information
- To operate the Service: sign-in, desk notes, blotter, chat, and related features.
- To send magic-link emails and operational messages (access, waitlist, security).
- To generate AI analysis from tape, news, and the prompts you submit.
- To protect the Service, debug failures, and measure aggregate usage.
- To comply with law and enforce our Terms of Service.
We do not sell your personal information.
3. AI processing
Desk notes, predictions, and chat replies are produced by automated models via providers such as OpenRouter. Prompts may include market tape, prior notes, and the text you type. Model outputs can be incomplete, outdated, or wrong. Do not put secrets, account passwords, or sensitive personal data into chat.
4. Sharing
We share information with:
- Infrastructure: Cloudflare (hosting, Workers, KV, D1, Images) and related edge services.
- Authentication: Stytch, to send magic links and maintain sessions.
- AI providers: OpenRouter and the underlying model vendors that process prompts needed to generate notes and chat replies.
- Market and content vendors: quote, news, filings, options, and similar APIs used to build the tape (for example Yahoo, Finnhub, FRED, Massive, Serper, and others as configured).
- Optional media: the public landing page may embed YouTube, which can set its own cookies under Google’s policies.
- Legal: if required by law, to protect rights and safety, or in connection with a merger, financing, or sale of assets.
Brokerage data stays scoped to your connected account and the blotter features you use. We do not publish your personal holdings on the public Mag7 desk note.
5. Cookies and similar technologies
We use:
- A session cookie (
stytch_session) to keep you signed in. - A short-lived cookie to remember where to send you after login.
- Local storage for disclaimer acknowledgment, a visitor id, and UI preferences.
You can clear cookies and local storage in your browser. Doing so will sign you out and may re-show the access gate.
6. Retention
We keep account, waitlist, memo, chat, and blotter records for as long as needed to operate the Service, unless a longer period is required by law or to resolve disputes. Cached market snapshots expire on ordinary cache schedules. You may ask us to delete or correct personal information we hold about you.
7. Security
We use HTTPS, access controls, and Cloudflare’s platform safeguards. No method of transmission or storage is perfectly secure. You are responsible for the devices and accounts you use to access BudFox and for any API keys you paste into the Service.
8. Children
The Service is intended for adults. We do not knowingly collect personal information from children under 16 (or under 13 where that is the applicable threshold). If you believe a child has provided information, contact us and we will delete it.
9. International visitors
The Service is operated from the United States using Cloudflare’s global network. If you access it from elsewhere, your information may be processed in the United States and other locations where our providers operate.
10. Your choices
- Request access, correction, or deletion of your personal information.
- Sign out and clear cookies to end a session.
- Disconnect Alpaca to stop further brokerage pulls.
- Stop using the Service and ask us to remove waitlist or account records we control.
Depending on where you live, you may have additional rights under applicable privacy law. We will not discriminate against you for exercising those rights.
11. Changes
We may update this policy. The “Effective” date above is the current version. Material changes will be posted on this page. Continued use after an update means you accept the revised policy.
12. Contact
Questions about privacy: contact@budfox.ai. See also our Terms of Service.