Home/Privacy Policy
LEGAL//updated Jul 18, 2026

Privacy Policy

How Earnings Feed collects, uses, and safeguards your information across the public site, dashboard, and APIs.

Privacy Policy

Transparency about data practices is foundational to how we ship Earnings Feed. This policy explains how we handle the personal information we touch and the choices available to every user and customer.

Scope & effective date

This notice covers:

  • Visits to earningsfeed.com and any subdomains.
  • Use of the authenticated dashboard and any APIs or alerts you enable.
  • Use of the Earnings Feed browser extension.
  • Customer support and other direct communications related to the service.

It applies to data processed on and after July 19, 2026.

Browser extension

The Earnings Feed browser extension replaces the new-tab page with public SEC filing data retrieved from earningsfeed.com.

  • The extension provides a limited anonymous preview. When that preview is exhausted, a free Earnings Feed account is required to continue receiving fresh filings.
  • It uses Clerk to synchronize an existing Earnings Feed website session by accessing authentication cookies only on the first-party Clerk host, clerk.earningsfeed.com. It sends a short-lived Clerk session token to earningsfeed.com with authenticated feed requests. The extension does not receive or store your password.
  • It does not read or collect browsing history, page content, bookmarks, downloads, or form entries.
  • To measure distribution and improve the feed's reliability, it sends a narrow set of first-party product events to earningsfeed.com: install or update, new-tab open, signed-in state, feed success or failure category, anonymous-limit state, theme changes, and deliberate clicks on extension controls or filing cards. Events include extension version, browser family, response duration, item count, and cache state. They use a random installation ID and do not include browsing history, visited-site URLs, filing titles, company names, search terms, page contents, passwords, email addresses, or session replay. earningsfeed.com forwards these schema-limited events to our PostHog project; no PostHog SDK, autocapture, advertising, session recording, or remotely hosted analytics code runs inside the extension. Firefox treats this technical-and-interaction collection as optional; the extension checks Firefox's built-in permission and sends no telemetry if the user declines or disables it.
  • It stores the selected light, dark, or system theme preference, a random installation ID, a recent cache of public filing records, and the cache timestamp in the browser's extension storage. This makes subsequent new tabs useful while fresh data loads, lets the extension identify stale cached results, and supports aggregate install and retention measurement.
  • It connects to earningsfeed.com to retrieve the filings feed and company images, and to clerk.earningsfeed.com for account-session synchronization. Like ordinary visits to the website, those HTTPS requests may create short-lived security and operational server logs such as timestamps, IP addresses, user-agent information, requested URLs, account identifiers for authenticated requests, and errors.

Removing the extension deletes its locally stored preference, installation ID, and public-data cache according to the browser's behavior. The rest of this policy applies when the extension requests content or records schema-limited product events through earningsfeed.com, or synchronizes an account through clerk.earningsfeed.com.

Our use of information received through the extension complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. We use extension data only to provide, maintain, secure, or improve the extension's disclosed SEC-filings feed and account-session features. We do not use or transfer it for personalized advertising, credit decisions, or sale to data brokers.

Information we collect

We collect four broad categories of information:

  • Account and workspace details. Name, email address, profile image, authentication identifiers from Clerk (including last sign-in timestamp and associated metadata), billing information processed by Stripe if you subscribe to paid tiers, and API keys (stored as SHA-256 hashes with display prefixes).

  • Usage and device signals. Log data such as timestamps, IP region, browser/OS metadata, feature toggles used, and diagnostic events. Session recordings (captured via PostHog) include screen interactions, clicks, page navigation, mouse movements, and form inputs (password fields are masked). Error logs include error messages, stack traces, affected URLs, and (for authenticated users) user identifiers. Browser cookies and local storage for authentication, analytics, and preference management. We use this to detect abuse, measure latency, improve reliability, and diagnose technical issues.

  • Customer content. Watchlist configurations with custom labels, alert preferences (frequency, form types, enabled state), email preferences and opt-out choices, API key names and usage records, feedback submissions (category, message, page context, browser information), and support communications you choose to share. You control what is stored in your workspace.

  • Public market data.
    SEC filings and other public records. These may reference individuals (e.g., insiders in Form 4s), but they are already public when we ingest them and are treated as market data, not private account data.

How we use information

We use the information described above to:

  • Deliver and maintain the product.
    Provision your dashboard, run saved feeds, power search and watchlists, generate alerts, and provide customer support.

  • Improve and research product performance.
    Analyze aggregated usage patterns to benchmark reliability, tune ingestion pipelines, and guide roadmap priorities.

  • Security, fraud prevention, and compliance.
    Monitor for abuse, enforce rate limits, investigate incidents, and satisfy lawful requests where required.

  • Communications. Send service notices, onboarding emails (welcome messages, feature highlights, upgrade information), billing updates, and (where permitted) opt-in marketing or educational content. You can manage email preferences and opt out of drip campaign emails at any time.

We do not use your account information to run third‑party advertising campaigns.

When we share data

We share personal data only in these situations:

  • Service providers. Third-party vendors who process data on our behalf under contract, including: Clerk (authentication and user management), Stripe (payment processing), Cloudflare (email delivery, DNS, edge security, and object storage), PlanetScale (database hosting), PostHog (product analytics and session recording), Sentry (application error monitoring), and Yahoo Finance (stock price data for watchlist features). They may only use your information to provide services to us.

  • Customer-directed access.
    Admins and collaborators you invite into your workspace can view configuration and content you or they choose to share.

  • Legal or safety requirements.
    We may disclose relevant logs or account data if we receive a valid legal request, need to enforce our terms, or must protect the service and our users from abuse or harm.

  • Business transfers.
    If we explore or complete a merger, financing, or acquisition, data may be shared under confidentiality. This policy (or its successor) will continue to govern your information.

We do not sell your personal information.

Your choices & rights

You have controls over how your data is used:

  • Account and communications. Update profile fields in the product. Manage marketing email preferences via in‑message links; we may still send essential service or security notices.

  • API access and keys. Generate, view, and revoke API keys from your dashboard. Monitor your API usage and rate limits. API keys are stored as one-way SHA-256 hashes for security.

  • Data rights (region-dependent).
    Depending on your jurisdiction (for example, California, EU/EEA, UK, Switzerland), you may be able to request:

    • Access to the personal data we hold about you.
    • Correction of inaccurate or incomplete data.
    • Deletion of your personal data, subject to legal and operational requirements.
    • Portability of certain information in a structured, commonly used format.
    • Restriction of processing in some circumstances.
    • Objection to certain processing based on legitimate interests.

To exercise these rights, contact us using the email at the end of this policy. We may need to verify your identity before responding.

You can opt out of marketing at any time and may object to certain processing by contacting us with your reasons.

Security & retention

We use appropriate technical and organizational measures to protect your data, including:

  • Encryption in transit (HTTPS/TLS) and at rest for core data stores.
  • Least‑privilege access controls and logging of administrative actions.
  • Monitoring for abuse and anomalous system behavior.
  • One-way hashing (SHA-256) of API keys with prefixes for user identification without exposing full keys.

Information tied to an active workspace is retained for the life of the account, as needed to provide the service and for legitimate business purposes (for example, security and legal compliance). Backups roll off on a scheduled basis (typically within 30 days) unless law or dispute resolution requires longer retention.

Data retention by service providers

  • PostHog analytics and session recordings are retained according to PostHog's data retention policy (up to 7 years for analytics data).
  • Clerk authentication data is retained for the life of your account.
  • Stripe billing records are retained for 7 years to meet tax and compliance requirements.
  • Sentry error and performance data is retained according to the configured Sentry retention policy.
  • Application database backups roll off within 30 days.

Cookies and tracking technologies

We use cookies and similar technologies (including browser local storage) for:

  • Authentication (Clerk) – To keep you logged in and maintain your session.
  • Analytics (PostHog) – To understand product usage, performance, and user experience through session recordings and interaction tracking.
  • Preference storage (local storage) – To save your settings such as timestamp display format locally on your device.
  • Session management (Next.js) – To maintain your session state across requests.

You can control cookies through your browser settings. Disabling certain cookies may affect authentication and functionality. Session recordings can be reviewed or deleted upon request by contacting [email protected].

International transfers

Our systems are primarily hosted in U.S. regions, which means your information may be processed outside your home jurisdiction.

When we transfer personal data across borders, we use appropriate safeguards (such as Standard Contractual Clauses or equivalent mechanisms) where required by applicable law. If your jurisdiction requires additional terms—like a Data Processing Addendum—reach out and we will provide the paperwork.

Updates

We may revise this notice when product or legal requirements change.

  • The updated date at the top of this page shows when changes last took effect.
  • For material changes, we will provide additional notice—such as an in‑product banner or email—before they become effective where required.

If you continue to use Earnings Feed after updates take effect, that use is considered acceptance of the revised policy.

Contact

Questions, data rights requests, Data Processing Addendum requests, or regulatory inquiries:

Email: [email protected]

Include your organization, workspace name, and the jurisdiction whose laws apply so we can respond efficiently.