Skip to content

Privacy Policy

Data Controller

Stoa operates globally with an Israel-based founder. The identity of the data controller and any EU representative will be specified in the final Privacy Policy after counsel review.

Information We Collect

  • Account data: email, display name, profile information at signup
  • Marketing preference: whether you asked to receive product and research emails (off unless you opt in)
  • Identity and payout data: PayPal onboarding signals (payments receivable, email confirmation)
  • Content: published reports, locked calls, debate threads, and related metadata
  • Usage data: session tokens, preferences, subscription and purchase history
  • Technical data: IP address and request logs at the infrastructure layer (Vercel)

How We Use Information

We use personal data to operate the marketplace, authenticate users, process payments, grade locked calls, display public track records, enforce fact-checking and disclosure requirements, and comply with legal obligations.

We send product and research emails only if you opt in at sign-up, sign-in, or in Settings. You can withdraw that consent at any time. Transactional mail (sign-in, receipts, required notices) is separate and is not marketing.

[Pending legal draft — counsel to map processing activities to GDPR Articles 6 and 9 bases, including contract performance, legitimate interests, and consent where applicable.]

Marketing emails use consent (GDPR Article 6(1)(a)). They are optional, off by default, and not bundled into the required Terms or Privacy acceptance.

Marketing Emails

If you tick the marketing box at sign-up or sign-in, or turn it on in Settings, Stoa may email you about new research, product updates, and invitations. This is separate from required account mail.

Consent is recorded against a versioned notice. Withdrawing it in Settings stops future marketing mail. It does not delete your account, change required legal consents, or erase the audit row that you previously opted in.

  • Off unless you opt in. Creating an account does not imply marketing consent.
  • Withdraw anytime in Settings, or use the unsubscribe link in a marketing email.
  • We do not sell email lists.

Sharing & Subprocessors

We share data with service providers who process it on our behalf. See our Subprocessors page for the current list, including PayPal, Supabase, AI providers, market data sources, Cloudflare, and Vercel.

Retention

Locked calls and published research are retained permanently as part of the public accountability record. Identity verification data retention periods are subject to counsel sign-off.

Your Rights

Depending on your jurisdiction, you may have rights to access, correct, export, or delete personal data. You can export your account data from Settings.

You can withdraw marketing-email consent at any time in Settings. That withdrawal does not affect the required Terms of Service or Privacy Policy acceptance.

Erasure vs. immutable ledger: GDPR Article 17 gives EU individuals a right to erasure. Stoa's core product promise is that locked calls (linked to analyst identity for track-record accountability) cannot be deleted. The proposed engineering approach — pending legal sign-off — is to pseudonymize personally identifying fields in profiles (name, avatar, bio, email) on verified deletion requests while leaving locked reports, claims, and MOAT score snapshots intact under an anonymized handle. The public ledger entry survives; the link to real-world identity does not.

  • Does Article 17(3) provide an exemption for publicly verifiable analyst records?
  • Is pseudonymization adequate, or must records become aggregate-only after a retention period?
  • Does treatment differ for EU analysts (public track record) vs. EU investors (subscribers)?

International Transfers

Data may be processed in the United States, Israel, and other locations where our subprocessors operate. Cross-border transfer mechanisms will be documented in the final Privacy Policy.

Children

Stoa is not directed at users under 18. We do not knowingly collect data from minors.

Contact & DPO

Privacy requests: privacy@stoa.app. A Data Protection Officer contact will be added if required after counsel review.