Privacy Policy
The short version
Introduction. This Privacy Policy explains how [LEGAL ENTITY NAME] ("Investeam," "we," "us") collects, uses, and shares personal data when you use investeam.io (the "Service"). We are the data controller. Investeam is a global, English-first service with Hebrew support; this policy meets the EU/EEA GDPR, the Israeli Protection of Privacy Law (as amended, incl. Amendment 13), and the CCPA as amended by the CPRA. If any translation conflicts with the English version, the English version governs, except where local law requires the local-language version to prevail.
What we collect
| Category | What it is | Source |
|---|---|---|
| Mandate / query text | The free-form investment question and any answers you type. May reveal your financial situation, holdings, interests, goals. | You, directly |
| Session state | The structured brief, clarifying Q&A, committee plan, findings, status, timestamps. | Generated by the Service |
| Product feedback | An optional rating (a like/dislike or a 1–5 star score) and free-text comment you volunteer on an AI response — a brief, a committee finding, or a debrief. You can change or clear it at any time. | You, directly |
| Account / identity data | Email; if you sign in with Google, the identity info Google returns (name, email, Google account ID, profile image). Auth via Firebase Authentication. | You / Google |
| Technical data | IP, device/browser type, log data; local-storage/sessionStorage values to keep your place in a flow. |
Automatic |
We do not intentionally collect special-category data. Please do not enter payment-card numbers, government IDs, passwords, or other people's personal data into the mandate field or the feedback comment.
Why we process it
| Purpose | Lawful basis |
|---|---|
| Turn your question into a mandate and run the AI analysis/committee | Performance of a contract (Art. 6(1)(b)) |
| Record optional feedback you volunteer, to improve the Service | Legitimate interests (Art. 6(1)(f)); you can withdraw it at any time by clearing it |
| Maintain your account and authenticate you | Performance of a contract (Art. 6(1)(b)) |
| Keep the Service secure, prevent abuse, debug, comply with law | Legitimate interests (Art. 6(1)(f)) / legal obligation (Art. 6(1)(c)) |
| Improve the Service (aggregate/analytics) | Legitimate interests (Art. 6(1)(f)); neither we nor our AI provider use your input or output to train models — see Who we share it with |
| Measuring and improving analysis quality (calibration of committee outcomes) | Legitimate interests (Art. 6(1)(f)) |
Under the Israeli PPL, processing is on the basis of your consent, given when you submit input after notice at collection. Under CCPA/CPRA we do not sell or share (cross-context behavioral advertising) your personal data.
AI and automated processing
Your input is processed by an AI system, orchestrated through our pipeline, that generates the mandate, questions, and findings. This output is informational only, is not a decision producing legal or similarly significant effects about you, and is not personalized investment advice (see Terms §"Not investment advice"). Output can contain errors. We do not use it for automated decisions about eligibility, credit, employment, or legal status.
Who we share it with
- Google Cloud Platform — hosting and data storage (app on Cloud Run; session data in Firestore; async jobs use Cloud Tasks / Pub/Sub; secrets in Secret Manager). Processed under the Google Cloud DPA.
- Firebase Authentication (Google) — account sign-in incl. Google OAuth.
- A third-party AI model provider (Google — Gemini API) — the AI model generating your analysis. Your input and the generated output are sent to it. We call the provider on our paid-tier account, under the provider's paid-services API terms and a Data Processing Addendum, so the provider does not use prompts or responses to train or improve its models. This protection comes from our account status with the provider, so it applies to every Investeam user regardless of your Investeam plan — free and paying alike. The provider may log prompts and responses for a limited period (currently up to about 55 days) solely to detect and prevent abuse and maintain safety and security — content flagged by its safety systems may be reviewed by authorized provider personnel — and for any legally required disclosures. [CONFIRM provider naming vs. GDPR Art. 13 recipient-disclosure with legal — §5.]
We do not sell your data. We disclose only to these processors, to authorities where legally required, and to a successor in a merger/acquisition (with notice).
Granularity: this policy names the three providers who receive your data — Google Cloud Platform, Firebase Authentication, and Google (Gemini API) — together with the categories of processing they perform (hosting, storage, auth, AI generation), satisfying the recipient-disclosure duty under GDPR Art. 13(1)(e) and the CCPA/CPRA. Enumerating specific GCP products (Firestore, Cloud Tasks, Cloud Run, Secret Manager) is good practice but not strictly required in the user-facing policy; ARCHITECTURE.md stays the source of truth for that product-level detail.
Where your data goes
Providers (Google) may process data outside your country, including in the US. For EU/EEA or Israeli individuals, transfers are protected by Standard Contractual Clauses and the Google Cloud DPA safeguards, plus any adequacy mechanism (e.g. EU–US Data Privacy Framework where certified). Request a copy of safeguards via the contact below.
How long we keep it
We keep your account data (email, tier) for as long as your account exists. When you delete your account (see Your rights), we erase it.
We keep your analysis data — mandate text, session state, committee outputs, synthesis analyses, and your plain-language debrief together with its audit record (the committee's statements, its findings, and the red-team's challenge, kept so you can download the analysis as a document) — for as long as you have an account, so your history stays available to you. We do not auto-delete it on a fixed schedule. You stay in control: deleting your account (see Your rights) erases every brief, orchestration, committee execution, and synthesis analysis you created, in one request; or you can ask us to action a deletion for you at contact@investeam.io.
One exception, which we would rather state than let you discover. That automatic deletion does not yet reach your debriefs and their audit records. We are building that in. Until it ships, we delete them by hand: email contact@investeam.io and we will erase them along with everything else, within the time applicable law requires. Nothing else is held back this way.
A file you have downloaded is yours. If you download an audit record, that document leaves our systems entirely. Deleting your account removes our copy; it cannot reach a file already saved to your device or forwarded by you to someone else.
Calibration record. To measure and improve the quality of our analysis over time, we keep a permanent, internal record of each committee's outcome — the committee's own findings, the instruments and market identifiers the analysis was about, and the participating committee members — together with 3-, 6-, and 12-month outcome scores. This record is internal only and, in any bulk view or export, is de-identified: it carries no account identifier and no free-text you wrote. If you delete your account, this record is deleted along with your other data.
We may retain data longer where required to comply with a legal obligation, resolve a dispute, or enforce our agreements — and only for the specific records affected.
Your rights
Depending on where you live, you have the following rights over your personal data: access; rectification/correction; erasure/deletion; portability (GDPR); restriction/objection; withdraw consent; and the CCPA/CPRA rights (know, delete, correct, opt out of sale/sharing — we do neither — limit use of sensitive PI; no discrimination for exercising).
You can delete your account and all associated data via a signed-in DELETE /api/v1/auth/me request; this erases your Firebase Auth identity, your profile, and every brief, orchestration, committee execution, and synthesis analysis you created, in one call. It does not yet reach your debriefs and their audit records — email contact@investeam.io and we will erase those too (see How long we keep it). A self-service settings screen is on the way; until then, if you would rather have us action the deletion for you (or to exercise any other right — access, portability, rectification, restriction, or CCPA/CPRA rights), email contact@investeam.io and we will act on your request as required by applicable law. Your first request in a reasonable period is free; we may need to verify your identity before we act.
Contact us
Email contact@investeam.io. EU/EEA: complain to your supervisory authority; Israel: the Privacy Protection Authority; California: the CPPA. [Name EU rep / DPO if appointed — §5.]
Cookies and local storage
We use sessionStorage/local storage to keep your place in a flow; Firebase Auth uses cookies/tokens to keep you signed in. Strictly necessary to operate the Service. No advertising/cross-site tracking cookies. [Analytics cookies later → EU cookie-consent required.]
Children
Not directed to and not for anyone under 18 (recommended for an investment product). We don't knowingly collect minors' data; if we learn we have, we delete it.
Changes to this policy
We may update; new "Last updated" date, prominent notice for material changes. Continued use after the effective date = acceptance.