Privacy
What we hold, and what we will never do with it
You are about to tell a piece of software how much money you have, what you own, what you are afraid of, and what you are saving for. That deserves a policy written to be read, not written to be survived.
Last updated 5 September 2026
Your portfolio and your conversations are never used to train a model, never sold, never rented, and never handed to an advertiser. Not ours, not anyone's.
You can export everything in one click, and erase everything in one more.
The four commitments
- No training. Nothing you say to the advisor, and nothing about your holdings, is used to train or fine-tune any model, by us or by a provider we use.
- No selling, no sharing for advertising. We have no advertising business. There is no version of Corvexsa that makes money from knowing what you own.
- No reading over your shoulder. Nobody at Corvexsa browses client conversations. There is no internal tool for it, and the audit log inside your account is the same log we have.
- No hostage-taking. Export and erasure are buttons in the app, not an email request with a waiting period.
What we collect
| What | Why | How long |
|---|---|---|
| Email address and sign-in method | To know it is you. Held by Firebase Authentication, not in our own store. | Until you delete your account |
| Your holdings, cash and cost basis | The thing the advisor reasons about | Until you disconnect or erase |
| Your profile: risk tolerance, horizon, goals, sector preferences | So advice is about your situation rather than a generic one | Until you change or erase it |
| Your conversations with the advisor | So it remembers what you have already discussed | Until you erase them |
| Analyses and alerts produced for you | So you can see what changed and why | Until you erase them |
| Broker API credentials | To read your holdings. Encrypted with AES-256-GCM, never returned to any browser | Until you disconnect |
| Your access log | So you can see everything that touched your account | Last 250 events |
| Payment status | To know which plan you are on. Card details are held by Stripe and never reach us | As long as tax law requires |
What we deliberately do not collect
- Your password. Sign-in is handled by Firebase. We never receive one.
- Your card number. Payments go directly to Stripe. We see a plan status and the last four digits.
- Your trade, dividend or transaction history. We refuse broker keys that grant it.
- Your location. No geolocation, no IP addresses stored. The device tags in your access log are one-way hashes salted per account, which is enough to spot a device you do not recognise and not enough to place you anywhere.
- Third-party analytics. There is no Google Analytics, no Meta pixel, no session recorder, and no advertising tag on this product. The browser policy on every page names the only four addresses the app is permitted to contact.
What the AI provider sees
The advisor is a language model. To answer usefully it has to be shown something, so here is exactly what it is shown and what it is not.
- It sees: your holdings and their weights, your cash, your sector allocation, your stated risk profile, horizon, goals and preferred sectors, the conversation so far, and real market data.
- It does not see: your name, your email address, your account ID, your broker credentials, your payment details, or anything that identifies you as a person. This is enforced in code, not by policy: identifying fields are stripped from the prompt before it is built.
- On the free plan, it never leaves us at all. Free conversations are answered by a model Corvexsa runs on its own hardware. No third-party AI provider receives them.
- On paid plans, the request goes to Anthropic's API. Anthropic's commercial terms state that inputs and outputs are not used to train their models. They retain limited data for safety purposes on their own schedule.
- The market data provider is never told about you. We ask it about a ticker symbol. It has no way to know which client asked, or whether anyone did.
Who processes your data
A short list, kept short on purpose. Every one of these is a company that would have to be involved for the product to function at all.
| Processor | What they do | What they receive |
|---|---|---|
| Netlify | Hosting, serverless functions, storage | Everything we store, encrypted in transit; broker credentials only in encrypted form |
| Google (Firebase Authentication) | Sign-in and identity | Your email address and authentication method |
| Anthropic | The advisor model, paid plans only | Your holdings and conversation, with identifying fields removed |
| Corvexsa's own model host | The advisor model, free plan | The same, and it goes no further than our own hardware |
| Stripe | Payments | Your card details, directly. We never hold them |
| Finnhub | Market prices and company data | Ticker symbols only, never tied to an account |
| Cloudflare | DNS and the encrypted tunnel to our model host | Network routing only |
If this list changes, it changes here first, and existing clients are told before it takes effect.
Your rights, and the buttons that honour them
- See everything. Settings, then Security, then Download my data. It is a single file, with a plain-language description of every record. Your broker credentials are deliberately excluded: writing a live credential into a downloaded file creates a copy neither of us controls.
- Erase everything. Settings, then Security, then Erase my account. You type a confirmation phrase, and every record we hold is deleted immediately. You get a receipt listing what went, and an honest note about what still sits at Firebase and Stripe.
- Correct anything. Your profile, goals and preferences are editable in the app at any time.
- Cut us off. Revoke the API key in Trading 212 and Corvexsa stops reading immediately, without asking us first.
- Read your own access log. Every sign-in, every broker read, every blocked write, every export.
We honour these rights for everyone, regardless of where you live. It is simpler than working out who is entitled to what, and it is the version we would want.
Security
Summarised here, described properly on the security page, which also lets you run a live proof that Corvexsa cannot trade.
- Broker credentials are encrypted at rest with AES-256-GCM and bound to your account, so a record cannot be moved between accounts.
- Every stored record is scoped to one account ID, and every endpoint verifies your session before reading one.
- Broker API keys with more permissions than we need are refused, not stored.
- Everything is served over HTTPS with strict transport security, and the app is not permitted to be embedded in another site.
- We have not been independently audited and do not hold SOC 2 or ISO 27001. When that changes we will say so here, with a date.
Children
Corvexsa is not for anyone under 18, and we do not knowingly hold data about a minor. If you believe we do, write to privacy@corvexsa.com and it will be deleted.
Where your data lives
Our hosting and storage providers operate globally, so your data may be processed outside the country you live in. Where that involves a transfer that needs a legal basis, our providers rely on standard contractual clauses. We do not move data anywhere for a reason other than running the product.
If this policy changes
Material changes are announced in the app before they take effect, and the date at the top of this page moves. We will not quietly widen what we do with your data and rely on you not re-reading a policy.
Contact
Corvexsa is operated by Trainis FZE-LLC, a company registered in the United Arab Emirates, which is the controller of the data described on this page.
Privacy questions and requests: privacy@corvexsa.com. Security reports: security@corvexsa.com. A person reads both.