Privacy Policy
Last updated: June 5, 2026
This Privacy Policy explains what Legend AI ("we", "us") collects, how we use it, and the choices you have. By using the Service you agree to this Policy.
1. Information we collect
- Account data: your email, name (optional), and a securely hashed password. We never store your password in plain text.
- Content you create: watchlists, trade-log entries, notes, settings, and AI chat messages.
- Billing data: subscription status and a customer identifier from our payment processor, Stripe. We do not collect or store your full card number β Stripe handles payment details directly.
- Usage & device data: log data such as IP address, browser type, pages visited, and timestamps, used for security, abuse prevention, and improving the Service.
- Cookies: a session cookie to keep you logged in. We do not sell your data or use third-party advertising trackers.
2. How we use your information
- To provide and operate the Service (authentication, scans, watchlists, alerts).
- To process subscriptions and send transactional and product emails.
- To power AI features you choose to use.
- To secure the Service, prevent abuse, debug, and provide support.
- To comply with legal obligations.
3. Service providers we share data with
We share the minimum necessary data with trusted processors who act on our behalf:
- Stripe β payment processing and subscription management.
- Resend β transactional and product email delivery.
- Anthropic β powers AI chat features when you use them (your prompts are sent to generate a response).
- Railway β application hosting and database infrastructure.
We do not sell your personal information.
4. Email preferences
You can opt out of non-essential (product/digest) emails at any time via your settings or the unsubscribe link in those emails. We may still send essential account and billing notices.
5. Data retention
We keep account and content data while your account is active and as needed to provide the Service. We may retain limited billing and log records as required for security, accounting, and legal compliance. You may request deletion of your account and associated personal data (see below).
6. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. To exercise these rights, contact us and we will respond within a reasonable time.
7. Security
We use industry-standard measures including encrypted transport (HTTPS), hashed passwords, scoped access controls, and reputable infrastructure providers. No method of transmission or storage is 100% secure, but we work to protect your data.
8. Children
The Service is not directed to anyone under 18, and we do not knowingly collect data from children.
9. International users
We operate in the United States. If you access the Service from elsewhere, your data may be processed in the United States.
10. Changes to this Policy
We may update this Policy from time to time. Material changes will be posted here with an updated date.
11. Contact
Questions or data requests? Contact us.