Skip to main content

Privacy Policy

Last updated: August 16, 2026

1. Scope and Data Controller

This Privacy Policy explains how Equibles ("we", "us", or "our") collects, uses, shares, and protects personal data when you use equibles.com, ALVIS, the Equibles MCP server, our REST APIs, and related services (collectively, the "Service").

Equibles is the controller of the personal data described in this Policy unless another notice says otherwise. You can contact us at support [at] equibles [dot] com.

2. Personal Data We Collect

Category Examples Source
Account and identity Email address, name, internal account identifier, authentication and login records, Google profile details when you choose Google sign-in, passkey public-credential data and labels, and onboarding answers such as role and referral source. You, your browser or authenticator, and Google when selected.
Customer Content ALVIS prompts and responses, conversation history, workspaces, reports, workflows, web data feeds and encrypted site connections, portfolios and their watchlists, feedback, problem reports, support messages, and attachments. You and people who collaborate with you through the Service.
API and MCP activity API-key identifiers, tool or endpoint names, request arguments for the most recent MCP calls, usage counts, timestamps, response status, duration, and response size. Generated when your account, API key, or connected client uses the Service.
Subscription and billing Plan, subscription status and dates, Stripe customer and subscription identifiers, invoices, billing country, and limited payment-method details such as card brand, last four digits, and expiry. You and Stripe. Equibles does not receive or store full payment-card numbers.
Technical, usage, and security IP address, browser and device details, operating system, pages and features used, sign-in and website-access timestamps, cookie identifiers, fraud and rate-limit signals, and server logs. The IP address your account was created from and the one you most recently signed in from are stored on the account record itself, together with the address range each belongs to, so that duplicate and abusive accounts can be identified. Generated by your browser, device, network, and our systems.
Communications Email preferences, messages sent to or from us, delivery and support history, and whether a tracked link in a product announcement was clicked. You, our email provider, and our email links.
Optional browser analytics Page views, clicks, scrolling, heatmaps, performance measurements, browser errors, and session recordings after you accept analytics, plus whether a registration, checkout or purchase happened. Generated by PostHog, Google Analytics and the Reddit advertising pixel in your browser with your consent.

3. Why We Process Personal Data

Purpose Legal basis
Create and authenticate accounts; provide website, ALVIS, API, MCP, support, and subscription functionality; enforce plan allowances; and respond to service requests. Performance of our contract with you and steps taken at your request before entering a contract.
Process subscriptions, payments, invoices, refunds, and accounting records. Performance of our contract and compliance with tax, accounting, and other legal obligations.
Secure the Service, prevent fraud and abuse, investigate errors, maintain audit records, and establish or defend legal claims. Our legitimate interests in operating a secure and reliable service, compliance with legal obligations, and legal claims.
Measure backend account, API, and MCP activity; diagnose reliability; understand feature use; and improve the Service. Our legitimate interests in operating and improving the Service, balanced against the limited data used and your right to object.
Run PostHog browser analytics and session recording, enable Google Analytics storage, and measure advertising conversions and build website visitor audiences for follow-up ads on Reddit. Your consent, which you can withdraw at any time.
Send authentication, security, billing, support, service, research-digest, and product communications. Performance of our contract, our legitimate interests in communicating with customers, and consent where applicable law requires it.

When we rely on legitimate interests, we consider the purpose, necessity, amount and sensitivity of the data, safeguards, and your reasonable expectations. You may object as described in Section 11.

4. AI Processing and Customer Content

When you use ALVIS or another AI feature, we process your prompt, conversation context, relevant Service data, and generated response. We may send that material to a configured AI model provider so it can generate the requested output. Customer Content may also be stored in conversation and audit records so you can resume work, collaborate, receive support, and so we can investigate misuse or failures.

Do not submit special-category personal data, confidential information, personal data about another person, or regulated information unless you are authorized to have Equibles and its providers process it. AI output may reproduce information contained in your prompt or context.

5. Browser Analytics, Session Recording, and Cookies

Optional browser analytics

PostHog browser analytics and session recording remain off until you accept the Analytics category. If you accept, PostHog collects page views, clicks, scrolling, heatmaps, performance data, browser errors, and session recordings. All form and input values are masked at capture time, but recordings can include other content displayed on the pages you visit.

When you are signed in, PostHog browser activity is associated with your internal account identifier. The same PostHog person profile may contain your email address and plan because limited account events add those details from our backend. PostHog is hosted in the European Union for this Service.

Google Analytics uses Consent Mode with analytics storage denied by default. It does not set analytics cookies unless you accept Analytics; Google may receive limited consent-status and cookieless measurement signals before a choice.

The Reddit advertising pixel measures website visits and conversions and helps us show follow-up Equibles ads on Reddit to previous visitors, including excluding visitors who have already converted. Reddit's script is not loaded at all until you accept the Analytics category, and it is never loaded for a visitor who rejects before loading. Withdrawing consent stops further events from our integration. When running, it receives page and referrer URLs, browser identifiers, registration, checkout and purchase events, and purchase amounts. Reddit may match these signals to a Reddit user for advertising. It never receives your email address, your name or your account identifier. This is an advertising cookie, and accepting the Analytics category is what permits it.

Backend operational analytics

Your browser choice does not disable records that are necessary to operate your account or measure backend API and MCP activity. We may send limited backend events to PostHog containing an internal account identifier, email, plan, tool or endpoint, surface, response status, duration, and response size. We do not send API or MCP request arguments or response bodies to PostHog. These backend events do not activate browser tracking or session recording.

Cookie and local-storage choices

Necessary cookies support authentication, security, sessions, anonymous usage limits, and privacy choices. Requested functionality may also store interface preferences, such as selected screener columns. Optional analytics identifiers are stored only after consent.

Category Names Purpose Typical duration
Necessary Portal.Identity, Portal.External, Portal.Session, Portal.Antiforgery Authentication, temporary sign-in state, sessions, and form security. Session to 90 days
Necessary cc_cookie, alvis-free-run Privacy choices and the anonymous ALVIS allowance. 6 months and 30 days
Requested functionality screener_cols and interface local-storage keys Remember settings you select. Up to 1 year or until cleared
Analytics ph_* PostHog visitor, session, analytics, and recording continuity. Up to 1 year
Analytics _ga, _ga_* Google Analytics visitor and session measurement. Up to 2 years
Analytics _rdt_uuid Reddit ad attribution and follow-up advertising to previous visitors. Up to 90 days

You can accept, reject, or later withdraw optional analytics through . Withdrawal stops future browser capture and clears analytics cookies where supported; it does not invalidate processing performed before withdrawal.

6. Communications and Email Tracking

We send messages needed to authenticate and secure your account, provide the Service, respond to support, administer billing, and deliver subscriptions you request. We may also send product announcements or research communications where permitted. You can use the preference or unsubscribe link in eligible emails; essential account, security, billing, and support messages cannot be disabled while relevant.

Links in product-announcement emails may include a recipient-specific token. If you open such a link, we record the first click time and click count and may record an associated PostHog backend event. We use this information to measure communication effectiveness and avoid unnecessary messages.

7. How We Share Personal Data

We do not sell personal data. We disclose it only as needed for the purposes in this Policy, including to:

  • Stripe, which processes checkout, subscriptions, payment methods, and invoices;
  • Google, when you choose Google sign-in and, with the browser choices described above, for Google Analytics;
  • PostHog EU Cloud, which processes optional browser analytics and limited backend product and reliability events;
  • Reddit, which receives advertising conversion events from your browser if you accept the Analytics category;
  • AI model providers, which process prompts, context, tool results, and generated output needed to provide AI features;
  • email, hosting, infrastructure, security, and support providers, which help us operate and communicate;
  • professional advisers and authorities when reasonably necessary for legal obligations, claims, fraud, security, or enforcement; and
  • a buyer, investor, or successor in a merger, financing, reorganization, or transfer of all or part of the business, subject to appropriate confidentiality and legal safeguards.

Providers acting as processors may use personal data only under our instructions and contract, except where they act as independent controllers under applicable law.

8. International Transfers

We primarily operate from Portugal and use providers that may process data in the European Economic Area and other countries. When personal data is transferred outside the EEA to a country without an adequacy decision, we rely on an approved transfer mechanism such as the European Commission's Standard Contractual Clauses and, where appropriate, supplementary safeguards. Contact us to request more information about the relevant mechanism.

9. Retention

We keep personal data only for as long as needed for the purposes described above:

  • Account, profile, authentication, subscription, and workspace records are generally retained while the account is active and then deleted, anonymized, or restricted after a verified closure or erasure request, subject to the exceptions below.
  • Billing, invoice, transaction, consent, and tax records are retained for the period required by applicable accounting, tax, consumer, and limitation laws.
  • The raw argument history for MCP tools is bounded to the most recent 100 calls per client; daily and aggregate usage records may be retained longer for quotas, reliability, business records, and trend analysis.
  • Deleting a conversation or workspace removes it from normal user-facing access, but underlying messages and audit rows may remain for support, security, abuse investigation, and legal claims until no longer necessary or an applicable erasure request is completed.
  • The sign-up and most recent sign-in IP addresses stored on the account record are retained while the account is active and removed with it; the most recent sign-in address is overwritten each time you sign in.
  • Support and email records are retained while needed to resolve the matter, honor preferences, document communications, and establish or defend claims.
  • PostHog event data is generally retained for up to 12 months and session recordings for approximately one month under our current service configuration; provider and project settings may shorten those periods.
  • Backups are overwritten through the ordinary backup cycle. Data isolated in a backup is not returned to active systems unless needed for disaster recovery.

We may retain information longer when required by law, a legal hold, security needs, or an active dispute. Data that has been irreversibly anonymized so it no longer relates to an identifiable person may be retained without a fixed period.

10. Security

We use technical and organizational safeguards designed for the nature of the data and risk, including HTTPS, access controls, passwordless authentication, protected credentials, audit records, rate limits, and security monitoring. No system is completely secure, and we cannot guarantee that unauthorized access or loss will never occur. You are responsible for protecting your email account, devices, passkeys, and API keys.

11. Your Data-Protection Rights

Subject to applicable conditions and exceptions, you may:

  • access personal data we hold about you and obtain a copy;
  • rectify inaccurate or incomplete personal data;
  • erase personal data;
  • restrict processing in certain circumstances;
  • receive or transmit portable data where the right applies;
  • object to processing based on legitimate interests and object at any time to direct marketing;
  • withdraw consent at any time without affecting earlier lawful processing; and
  • complain to Portugal's Comissão Nacional de Proteção de Dados (CNPD) or the competent authority where you live or work.

Send a request to support [at] equibles [dot] com. We may need to verify your identity and clarify the request. We will respond without undue delay and normally within one month; where the law permits an extension for a complex or numerous request, we will explain the extension. You can contact the CNPD through cnpd.pt.

12. Automated Decisions

We use automated systems to apply quotas, detect abuse, prioritize security review, and generate AI output. We do not use personal data to make solely automated decisions that produce legal or similarly significant effects about you. Contact us if you believe an automated restriction was applied incorrectly.

13. Children

The Service is intended for adults and is not directed to anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided personal data, contact us so we can investigate and delete it where required.

14. Changes to This Policy

We may update this Policy when our practices, providers, Service, or legal obligations change. We will post the updated Policy with a revised date. If a change materially affects your rights or how we use personal data, we will provide additional notice or request consent where applicable law requires it.

15. Contact

Privacy questions, rights requests, and complaints may be sent to support [at] equibles [dot] com.

Equibles