Privacy policy
What Compass collects, why, who processes it and the rights you have. Last updated October 1, 2026.
1. Data controller
The controller of your personal data is Charles Bébin, a private individual acting in a non-professional capacity under the name BebinC. For any privacy question or request, write to contact@bebinc.com. This policy is written to meet the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA).
2. Data we collect
Account data
- Email address and name, for sign-in, account management and the emails you ask for (alerts).
- Sign-in data managed by Clerk: password hash, passkeys, connected Google or Apple accounts, two-step verification and sessions. We never see your password.
Your content and settings
- Watchlist, research notes (thesis, stance, price target, conviction, horizon, tags, catalysts, target history), valuation models, comparables, saved screens, alerts, paper portfolio trades and notifications.
- Preferences: density, colour vision, gain and loss colours, language.
- Stored in our Neon Postgres database under your account id; other users cannot read it. A note you share with a public link can be read by anyone with the link until you turn sharing off.
Technical data
- IP address and request metadata, processed by our hosting (Vercel) and sign-in provider (Clerk) for security and abuse prevention.
- Usage counts for AI features (how many summaries you requested each day), to enforce daily limits.
What we do not collect
- Payment or bank details.
- Advertising trackers, or data sold to anyone.
- Sensitive personal data (health, biometrics and similar).
3. How and why we use it
- To provide the Service: sign-in, storing your content, alerts and notifications (performance of a contract, GDPR art. 6(1)(b)).
- To send the emails you turn on, such as price and earnings alerts (performance of a contract).
- To prevent abuse, scraping and unauthorised access (legitimate interests, art. 6(1)(f)).
- To answer your requests (legitimate interests).
- To meet legal obligations (art. 6(1)(c)).
We do not use your data for automated decisions or profiling with legal or similarly significant effects.
4. Processors
We share personal data only with these providers, and only as far as needed:
- Clerk: sign-in and account management for every BebinC product.
- Neon: Postgres database hosting.
- Vercel: application hosting and delivery.
- Resend: sending the alert emails you turn on.
Market data providers (SEC EDGAR, Yahoo Finance, Finnhub, Tiingo, FRED, Polymarket) are called from our servers and never receive your identity. Company logos are loaded by your browser from logo.dev, which can see your IP address and the tickers shown, but not your account. AI filing summaries send only the text of public filings to Mistral (and Groq as a backup), never your personal data or notes.
5. Cookies and local storage
- Clerk session cookies, strictly necessary to keep you signed in across BebinC products.
- A cookie that remembers whether you collapsed the sidebar.
- Browser storage for recently opened tickers and whether single-key shortcuts are on, on your device only.
We use no advertising or cross-site tracking cookies.
6. Retention
- Account data and your content: kept while your account is active. When you delete your account, everything is erased after a 30-day grace period during which you can cancel.
- Deleted notes stay restorable for a day, then are erased.
- Server logs: kept by Vercel and Clerk under their own retention policies, typically 30 days or less.
7. Security
- Encryption in transit (TLS) everywhere.
- Sign-in handled by Clerk, with passkeys and two-step verification available.
- API keys kept in server environment variables, never sent to browsers.
- Every database query is limited to the signed-in account.
No system is perfectly secure. If a breach affects your rights, we will notify you and the authorities as the law requires (within 72 hours to the supervisory authority under the GDPR).
8. International transfers
Our providers may process data outside the European Economic Area, notably in the United States. Transfers rely on their Standard Contractual Clauses and data processing agreements, or on the EU-US Data Privacy Framework where they participate in it.
9. Your rights (EU and EEA)
- Access (art. 15): get a copy of your data.
- Rectification (art. 16): correct it.
- Erasure (art. 17): delete your account and data.
- Restriction (art. 18) and objection (art. 21).
- Portability (art. 20): export your content as CSV and JSON from Settings, Data.
- Withdraw consent at any time where processing relies on it.
- Complain to your data protection authority (in France, the CNIL).
To exercise a right, use Settings or write to contact@bebinc.com. We answer within 30 days.
10. Your rights (California)
- Right to know what personal information we collect and how we use it.
- Right to delete and to correct your personal information.
- We do not sell or share personal information for cross-context behavioural advertising, so there is nothing to opt out of.
- You will not be treated differently for exercising these rights.
11. Children
The Service is not meant for anyone under 16, and we do not knowingly collect their data. If you think a child has given us data, contact us and we will delete it.
12. Changes
We may update this policy. Material changes are announced by updating the date above and, where appropriate, by email or a notice in the Service.