Skip to content

Privacy policy

1. Who is responsible for your data?

InsiderTell is provided by Uneven Bits ApS, CVR no. DK30487842, Dybbølsgade 39, 2. th., 1721 København V, Denmark ("we", "us"). We are the data controller for the personal data described here. All processing follows the EU General Data Protection Regulation (GDPR) and Danish data protection law.

2. What data do we process?

Account data. Your name and email address; your password as a hash, or the identifier of your Google account if you sign in with Google; the workspaces you belong to, with each member's name, email address and role; invitations you send (the invitee's email address); payment and billing details, handled by Stripe (we don't store card data); technical data such as IP address, browser type and the session cookie that keeps you signed in; and usage data such as log files, actions in the dashboard and your messages to support.

Your settings and work in the product. Watchlists, alert settings, trade plans and notes you write, saved filters, and API keys you create (stored as a hash). This is your data; we process it only to provide the service to you.

Visits to insidertell.com. Our web server logs requests (IP address, page, time, browser) to keep the site running and secure. insidertell.com sets no advertising or analytics cookies. When you're signed in to the dashboard, its session cookie is also sent to insidertell.com because it's set for the whole insidertell.com domain; it's strictly necessary and used only to keep you signed in.

Public filing data about other people. The product shows data from public SEC filings (Form 4 and related forms), which name the officers, directors and large shareholders of US public companies and the trades they report. This data is published by the SEC under US securities law and is processed by us as public information in the public interest of transparent markets and for our legitimate interest in providing the service. We add nothing about these people beyond what the filings and public prices contain. If you are named in a filing and have a concern, write to [email protected]; we can't remove what the SEC publishes, but we will look at anything we have added or computed.

3. Why do we process it?

We process account data to provide and administer InsiderTell: to create and maintain your account, process payments and invoices, send service emails (email verification, password resets, and the alerts and digests you've switched on), provide support, protect the service against abuse, meet legal requirements, and improve the product.

  • Contract (Article 6(1)(b) GDPR): what's needed to provide the service you signed up for, including alerts and digests you switch on yourself.
  • Legal obligation (Article 6(1)(c)): what we must keep under bookkeeping and tax law.
  • Legitimate interests (Article 6(1)(f)): running, securing and developing the service, including limits on sign-in attempts and API use, and showing public filing data, as long as your interests don't outweigh ours.
  • Consent (Article 6(1)(a)): cookies that aren't strictly necessary, if we add any, are only set after you agree. You can withdraw consent at any time.

5. How long do we keep it?

  • Account data: for as long as you have an account, including after a paid plan has ended. When you ask us to delete your account, we delete its data within 30 days, unless the law requires us to keep it (for example, the five-year bookkeeping requirement for invoices).
  • Log files and technical data: up to 30 days.
  • Backups: kept for up to 30 days, so deleted data can remain in backups for up to 30 days before it's overwritten.
  • Public filing data: indefinitely; it is the product's history.

6. Who do we share it with?

We use these sub-processors to provide InsiderTell:

Sub-processor Location What they do
Contabo, or Hetzner if we move or add servers EU Hosting of our servers. Our databases run on these servers, operated by us.
Cloudflare EU and USA DNS, network delivery and security for insidertell.com and its subdomains, and storage of raw filings and backups (R2, EU jurisdiction).
Anthropic USA and Ireland Claude writes the optional explanation of a signal for paid users. Receives the signal's public data, not account data.
Brevo EU Sending service emails, alerts and digests.
Stripe EU and USA Payments and invoices.
Sentry EU Error monitoring. Error reports can contain extracts of the data being processed when the error happened.
Google EU and USA Sign-in with Google, when you choose it.

We don't sell personal data. We share it with authorities only when the law requires.

7. Transfers outside the EU

Where a sub-processor processes data in the USA, the transfer rests on the EU-US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's standard contractual clauses.

8. Your rights

You can ask for access to the personal data we hold about you, have it corrected or deleted, restrict or object to processing, and receive the data you gave us in a portable format. Write to [email protected]. You can also complain to Datatilsynet, the Danish Data Protection Agency (datatilsynet.dk).

9. Cookies

insidertell.com and the dashboard use only strictly necessary cookies: the session cookie that keeps you signed in. No analytics or advertising cookies are set. If that changes, we will ask first.

10. Security

Data is encrypted in transit (TLS) and stored on servers in the EU with access limited to the people who run the service. Passwords are stored as bcrypt hashes; API keys and email links as SHA-256 hashes.

11. Changes

We may update this policy as the product changes. The date at the top says when. Material changes are announced by email to account holders.