Privacy Policy
Last updated: July 30, 2026.
Short version: we don't have accounts, we don't sell data, and we collect about as little as a web product can while still knowing whether anyone visits. The long version is below.
1. What we collect
The Service has no user accounts, no sign-up, and no payment flow — there is nothing to attach a stored profile to. What we do collect:
- Aggregate, anonymous usage analytics(Vercel Web Analytics): page views, referring site, country/region (city-level, not precise location), and device type. It is cookieless — no persistent identifier follows you across days or across other sites, and we don't store your IP address. A visitor is represented by a hash that resets every 24 hours, so we can see “how many people visited yesterday,” never “this specific person visited on these five days.”
- What you type into search. Ticker and company-name searches are processed to return results and are not stored as a personal profile tied to you.
- Server logs, in the ordinary way any web host keeps them briefly for operating and securing the Service (abuse detection, debugging) — not mined, profiled, or sold.
2. What we don't collect
- No advertising trackers, ad-network pixels, or cross-site tracking of any kind.
- No sale or “sharing” (as CCPA/CPRA defines that term, for cross-context behavioral advertising) of any personal information, to anyone, ever.
- No persistent device fingerprint or cross-session identifier.
- No email address, name, or account — because there's no account to attach one to.
3. Third-party sources your queries reach
To answer a search or render a report, our servers query SEC EDGAR, Yahoo Finance, and Google News on your behalf — you never contact these services directly, but the content of your query (e.g., the ticker you searched) does reach them as part of fulfilling the request. We don't send them anything beyond what's needed to answer that one request, and none of them receive it framed as coming from a particular identified person, since we don't know who you are either.
4. Cookies & tracking technologies
The Service sets no analytics or advertising cookies. Your browser may still use ordinary local storage for interface preferences (like light/dark theme) — that stays on your device and is never transmitted to us.
5. Data retention & security
Aggregate analytics are retained in summarized form for product improvement and are not linked back to an individual. We take reasonable technical measures to protect the Service (see our analytics provider's own security practices for that layer), but no online service can guarantee absolute security.
6. Children's privacy
The Service is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact us and we'll address it.
7. California residents (CCPA/CPRA)
California's CCPA/CPRA applies to businesses that meet at least one statutory threshold — roughly $26.6M in annual gross revenue, or buying/selling/sharing the personal information of 100,000+ California consumers or households a year, or deriving most of their revenue from selling personal information. We don't meet any of these today. We're disclosing this plainly rather than claiming coverage we're not yet subject to — but we extend the practical substance of CCPA rights (know, delete, correct, opt out of sale/sharing) to every visitor anyway, in §9 below, regardless of whether the statute currently reaches us. We do not sell or share personal information as those terms are defined by CPRA.
8. EEA/UK residents (GDPR)
GDPR has no size threshold — it can apply based on whether a service targets or monitors people in the EU/UK, regardless of company size. We don't market to or price in currencies for the EU/UK specifically, and our analytics is aggregate and cookieless rather than behavioral profiling, which weighs against the “monitoring” trigger — but the Service is globally reachable, so we can't rule out EU/UK visitors. Our lawful basis for the limited processing described in §1 is legitimate interest in understanding aggregate, anonymous usage — never profiling or automated decision-making about an identified individual. EEA/UK visitors have the same rights described in §9.
9. Your rights, regardless of location
Whoever and wherever you are, you can ask us to:
- Tell you what categories of information we hold that relate to you (see §1 — in practice, very little, since nothing is tied to an identity);
- Delete anything we hold that's reasonably identifiable to you;
- Confirm we don't sell or share your information — we don't, to anyone.
Email hello@lawful.fyito make any of these requests. Because we don't maintain accounts or persistent identifiers, most requests will resolve quickly simply because there is little to find.
10. If a mobile app ever ships
The Service is a website today. If we ever ship a native iOS or Android app, its Apple “App Privacy” label and Google Play “Data Safety” section will be completed to accurately mirror the practices on this page at that time, and this policy will be updated to reflect anything the app collects that the website doesn't (for example, push-notification tokens, if that feature ever exists).
11. Changes & contact
We may update this policy as the Service changes; the “Last updated” date above will reflect that. Material changes will be reflected here before they take effect. Questions or requests: hello@lawful.fyi. See also our Terms of Service.