Privacy Policy
Last Updated: September 4, 2026
1. Introduction
Welcome to DailyIQ ("we," "our," or "us"). This policy explains what information we collect when you use our website at dailyiq.me (the "Service"), why we collect it, who we share it with, and how long we keep it. It describes our actual practices, not a generic template.
Most of DailyIQ works without an account. Signing in, building a portfolio, setting alerts, connecting a brokerage, or subscribing each adds the specific data described below — nothing more.
2. Information We Collect
2.1 Account Information
- Email address — required for every account; used as your login identifier and for account email.
- Password — for email/password accounts only. We store a bcrypt hash, never the password itself, and cannot recover it.
- Name and profile picture — supplied by you at signup or by Google when you sign in with Google.
- Sign-in provider and Google account identifier — so we can match you to the right account on return visits.
- Email verification and password reset tokens — short-lived, single-purpose tokens with expiry timestamps.
- Account type and timestamps — whether the account is a standard or administrative account, plus created/updated times.
If you begin signup but never verify your email, your email address, name and password hash are held in a pending-signup record until the verification link expires.
2.2 Subscription and Billing
- Stripe customer identifier, subscription status, and plan are stored on your account record.
- We never receive or store your card number, CVC, or bank details. Payment details are entered directly with Stripe and are processed on Stripe's systems.
2.3 Portfolio, Watchlist and Alerts
- Portfolio accounts and holdings — account names and types you create, plus each position's symbol, quantity and average cost.
- Transactions — buys, sells, cash movements, quantities, prices and dates you record.
- Journal notes — any free-text notes you attach to a portfolio account and date.
- Alert configurations — the symbols, alert types, conditions, thresholds, timeframes and strategies you set, along with when each alert last triggered.
- Email alert delivery records — the recipient address and the alerts sent to it, so we can avoid duplicate sends.
Some interface preferences — watchlist and screener column layouts, chart settings, display toggles — are stored only in your browser's local storage on your own device and are never transmitted to us.
2.4 Connected Brokerage Accounts (optional)
If you choose to connect a brokerage account (currently Questrade), we store, strictly to power the features you asked for:
- OAuth access and refresh tokens, encrypted at rest, plus their expiry and the API server assigned to you. We do not receive or store your brokerage username or password.
- Account identifiers and types (for example TFSA, RRSP, margin) and their status.
- Positions — symbol, quantity, market value, average entry price, cost basis and profit/loss.
- Balances — cash, market value, total equity and buying power, per currency.
- Transaction history — trade and settlement dates, action, symbol, quantity, price, commission, net amount and description.
This is sensitive financial information. You can disconnect a brokerage connection at any time, and you can ask us to delete the synced data (see Section 8).
2.5 API Keys
If you generate an API key, we store a short non-secret prefix, a SHA-256 hash of the key, the key's name, the account it belongs to, and its creation and last-used timestamps. The full key is shown to you once and never stored.
2.6 Information Collected Automatically
- IP address — used to rate-limit signups, password resets and API requests, to protect the Service from abuse, and to estimate a display currency on our pricing page.
- Approximate country — derived from your IP by a third-party lookup service solely to show pricing in a local currency. Your actual charge and currency are determined by Stripe at checkout.
- Device and browser information — browser type, operating system and similar request metadata.
- Usage data — pages visited, features used and time on site, collected through analytics only where you have consented (see Section 4).
- First-party product events — we record our own lightweight usage events (event type, page path, the symbol being viewed, the referring website's domain, and a session identifier) to understand which features are used. We do not store the full referring URL, only its domain, and page paths are recorded without their query strings. If you have consented to analytics, these also carry a pseudonymous visitor identifier: a one-way hash of your IP address and browser, re-salted every day so it cannot be used to follow you across days. Without consent, no visitor identifier and no account identifier is recorded — only anonymous counts.
- Live-price viewing sessions — when you view a live-quoting page, your browser sends a randomly generated identifier and the symbol you are viewing, so our price service knows which symbols to stream. These records are not linked to your account and expire within minutes.
- Rate-limit counters — attempt counts keyed to an email address or IP address for sensitive actions such as signup and password reset.
2.7 Communications
If you email us, we receive your email address and the contents of your message, and retain them as part of our correspondence.
3. Cookies and Local Storage
We use a small number of first-party cookies:
di_session— a signed, httpOnly session token that keeps you logged in. Expires after 30 days.oauth_state— a short-lived (10 minute) httpOnly token used to prevent cross-site request forgery during Google sign-in.diq_cookie_consent— records your analytics and advertising consent choice for one year, so we do not ask again on every visit.
We also use your browser's local storage to remember interface preferences (chart state, screener and watchlist layouts, display toggles) and your consent choice. Local storage stays on your device.
Google Analytics and Google AdSense may set their own cookies, but only after you grant consent. Until then, Google Consent Mode is set to denied and no analytics or advertising storage is used. You can change your choice at any time by clearing our cookie and local storage for this site, and you can configure your browser to refuse cookies entirely — the core Service, other than staying logged in, continues to work.
4. How We Use Your Information
- Authenticate you, keep you signed in, and secure your account
- Provide the features you use — portfolios, watchlists, alerts, screeners and brokerage sync
- Send transactional email you asked for: verification, password resets, and the alerts you configured
- Process subscriptions and manage billing through Stripe
- Enforce rate limits and detect or prevent abuse, fraud and unauthorized access
- Display an estimated local price on our pricing page
- Understand aggregate usage and improve the Service, where you have consented to analytics
- Comply with legal obligations
We do not sell your personal information, and we do not use your portfolio, brokerage or watchlist data to train models or to build advertising profiles.
5. Automated Processing and AI-Generated Content
Most editorial and analytical content on DailyIQ — company summaries, news sentiment, earnings write-ups — is generated from public market data by automated systems, including third-party AI models. That process involves no personal information.
One feature is an exception: if you use portfolio impact summaries, the ticker symbols, position sizes and portfolio weights in that account are sent to our AI provider (OpenRouter) to generate the summary text. Your name, email address, account identifiers and brokerage credentials are never included. If you would rather no portfolio information leave our systems, do not use portfolio impact summaries.
6. Third-Party Services
The following third parties process data on our behalf or receive data when you use certain features:
- Google (Sign-In): authentication. We receive your email, name, profile picture and Google account identifier. Subject to Google's Privacy Policy.
- Google Analytics 4: aggregate usage analytics, loaded only after you consent.
- Google AdSense: advertising, loaded only after you consent. Ad personalization follows your consent choice.
- Google Gmail API: used to deliver our transactional and alert email to your address.
- Stripe: payment processing and subscription management. Stripe collects your payment details directly. See Stripe's Privacy Policy.
- Questrade: only if you connect a brokerage account. Data flows from Questrade to us under the authorization you grant, and can be revoked at Questrade or by disconnecting here.
- OpenRouter: AI text generation, including the portfolio impact summaries described in Section 5.
- ipwho.is: receives your IP address to return an approximate country for pricing display.
- open.er-api.com: currency exchange rates. Receives no personal information.
We also ingest market data from providers including Interactive Brokers, Yahoo Finance, Finnhub, FRED and public regulatory filings. These providers receive no information about you.
7. Data Sharing
We do not sell your personal information. We share it only:
- With the service providers listed in Section 6, for the purposes described there
- To comply with legal requirements or respond to lawful requests
- To protect our rights, privacy, safety or property, or those of our users
- In connection with a merger, acquisition or sale of assets, in which case we will give notice before your information becomes subject to a different policy
8. Data Retention
- Account, portfolio, alert and brokerage data is kept for as long as your account is active. When you request deletion it is destroyed 30 days later, at which point it is unrecoverable.
- A record that a deletion happened is retained after the purge, as proof the request was honoured. It holds your user identifier, the request and completion dates and a one-way hash of your email address — never the address itself.
- Unverified pending signups and verification and password-reset tokens expire and become unusable within their short validity windows.
- OAuth state cookies expire after 10 minutes; live-price viewing records expire within minutes of you leaving the page.
- Rate-limit counters are retained only as long as needed to enforce the relevant window.
- Billing records may be retained by Stripe and by us as required by tax and accounting law, even after account deletion.
9. Your Rights and Choices
Depending on where you live, you may have the right to:
- Access the personal information we hold about you, and receive a copy of it
- Correct inaccurate or incomplete information
- Delete your account and associated personal information
- Object to or restrict certain processing, and withdraw consent at any time
- Lodge a complaint with your local data protection authority
You can exercise access and erasure yourself, from your account settings:
- Download My Data gives you a JSON file containing everything described in Section 2 — profile, portfolios, transactions, journal notes, alerts and any connected brokerage data. Secrets (password hash, API key hashes, brokerage tokens) are excluded by design.
- Delete My Account schedules permanent deletion of your account and all of the above. Deletion takes effect after a 30-day grace period, during which you can cancel it from the same page; we email you when it is scheduled so that a request you did not make can be stopped. Alert emails stop and API keys are revoked immediately, and any active subscription is set to end at the current billing period so you are not charged again.
You can also change most profile information, disconnect a brokerage connection, revoke individual API keys, and delete portfolio accounts and alerts directly in the app. If you would rather we action a request for you, email the address in Section 14.
You can withdraw analytics and advertising consent by clearing this site's cookies and local storage, which restores the pre-consent state.
10. Data Security
Passwords are stored as bcrypt hashes and API keys as SHA-256 hashes — neither is recoverable from our systems. Brokerage OAuth tokens are encrypted at rest. Session cookies are httpOnly, signed, and marked Secure and SameSite in production. Traffic to the Service is served over HTTPS. Sensitive administrative endpoints require a separate internal token, and sensitive actions are rate-limited.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you as required by applicable law.
11. International Data Transfers
DailyIQ is operated from Canada, and our service providers operate in the United States and other jurisdictions. If you access the Service from outside these regions, your information will be transferred to and processed in them, which may have different data protection laws than your own.
12. Children's Privacy
Our Service is not directed to individuals under 13, and we do not knowingly collect personal information from them. If we learn that we have collected personal information from a child under 13, we will delete it.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page and revise the "Last Updated" date. Material changes affecting how we use your information will be communicated to account holders by email.
14. Contact Us
For privacy questions, access, correction, export or deletion requests, contact us at:
Email: dailyiqme@gmail.com