$ cat privacy

Privacy policy

Last updated 2026-08-12. Strong Ticker is a trade name of Negative Split Software LLC, in Washington State, USA — the company responsible for the personal data described here.

The short version

Your journal is private. We do not sell your data, we do not advertise, and we do not read your entries except in the narrow circumstances listed below. We collect the least we can get away with, and you can delete all of it.

What we collect and why

Identity and access. When you sign up we store your email address and, if you provide one, your name. Sign-in is handled by Clerk; we do not store passwords and never see them. We use your email to identify your account, to reply when you contact us, and to send review reminders if you have those switched on.

What you write. Positions, entries, conviction scores, falsifiers, trades and tags. This is the product — it is stored so we can show it back to you. It is visible to you, and to anyone you deliberately give a share link to.

Billing. If you subscribe, payment is processed by Stripe through Clerk. Card details go to Stripe directly and never reach our servers. We can see that a subscription exists and what plan it is on.

Website interactions. We use Vercel Web Analytics to count page views. It is cookieless and sets no cross-site identifier, so it cannot follow you to other sites. Our hosting provider also keeps request logs that include IP addresses, for a limited period set by their own retention schedule. That is ordinary for any web service, and it is how abuse gets investigated.

Telling a person from a script. One feature does more than count: the ticker lookup that fills in a company name for you sends characteristics of your browser to Vercel, which uses them to judge whether a real person asked. It runs on that one action and nowhere else on the site. It is there because that lookup costs us money on every call and a script can spend it faster than people can. It sets no cookie and is not used to recognize you, here or anywhere else.

Cookies. Two kinds, both first-party and neither shared with anyone. The session cookies Clerk needs to keep you signed in; and, if you arrive from a link carrying campaign parameters, a cookie holding only that campaign name and the page you landed on, so that a later sign-up can be attributed to whatever introduced you. It expires after 30 days, contains no identifier for you, and cannot follow you to another site. There are no advertising cookies and nothing that tracks you across the web.

In Europe and the UK you do not get the second one. The law there asks for consent before anything is stored on your device that you did not ask for, so rather than put a banner in front of you, we skip the cookie.

Correspondence. If you email us, we keep the email so the conversation makes sense next time.

Who else processes it

We use these companies to run the service. They only ever receive what they need to do their job.

WhoForWhat reaches them
ClerkAccounts and sign-inEmail address, name, authentication events
Stripe (via Clerk)PaymentsCard details, which go to Stripe directly and never reach us
NeonDatabaseEverything you write: positions, entries, trades, tags
VercelHosting, page-view analytics, and bot detectionIP address at request time, pages visited, and browser characteristics used to tell a person from a script on the ticker lookup. No cookies, no cross-site identifier
ResendSending emailEmail address, and the reminder content sent to you
TiingoMarket prices and company namesTicker symbols only. Never anything about you
SentryError trackingStack traces and request metadata when something breaks. Never what you wrote — request bodies are stripped before anything is sent

We do not sell your personal information, and we do not share it with anyone for advertising.

When we would look at your data

We do not read your journal out of curiosity. A human here would only access your content when:

  • you ask us to, because you need help with something
  • we are investigating a bug or an outage and your account is genuinely implicated
  • the law requires it — and if we are permitted to tell you, we will
  • we have reason to believe an account is being used to break the law or harm someone

Sharing something on purpose

A share link makes one position readable by anyone who has the link. It is unlisted rather than secret: we ask search engines not to index it, but a link you paste somewhere public is public.

Your trade sizes are excluded unless you explicitly turn them on for that link. Revoking a link takes effect immediately.

Your rights over your data

Wherever you live, you can ask us for a copy of what we hold, ask us to correct it, or ask us to delete it — email support@strongticker.com. We do not require you to be in a particular country to exercise these; it seems wrong to offer rights by postcode.

If you are in California, this includes the rights to know, to delete, to correct, and to opt out of sale or sharing. We have nothing to opt out of, because we do not sell or share personal information, and we do not discriminate against anyone for asking.

Deleting your account

Deleting a position deletes its entries and trades. Deleting your account deletes everything you wrote, along with your share links. Copies may persist in our database provider’s backups after deletion, until those backups age out under their retention schedule.

Daily closing prices are not deleted, because they are facts about companies rather than facts about you — a ticker, a date and a number, with no connection to any person.

How long we keep things

We keep what you write for as long as your account exists. If you stop paying, nothing is deleted — your journal stays readable and you simply cannot add new positions beyond the free allowance. Request logs are retained by our hosting provider under their own schedule and then discarded.

Where it lives

Negative Split Software LLC is in the United States, and the service and its database are hosted in the United States. If you are elsewhere, using Strong Ticker means your data is transferred here and processed under US law.

Security

Everything is served over HTTPS. Every database query is scoped to the account making it, and there is an automated check that asserts one account cannot read another’s data. Passwords are handled by Clerk and never reach us; card details are handled by Stripe and never reach us.

No service is perfectly secure and anyone claiming otherwise is selling something. If you find a vulnerability, please email support@strongticker.com and we will take it seriously.

Changes

If we change this materially, we will update the date at the top and, for anything that meaningfully affects you, email account holders. Questions go to support@strongticker.com.

Adapted from the Basecamp open-source policies, used under CC BY 4.0. See also our terms of service.