Effective: May 1, 2026
1. Information We Collect
Account Information
When you create an account, we collect your name, email address, and password (stored as a bcrypt hash). If you use Google OAuth, we receive your Google profile name and email.
Usage Data
We collect data about how you use the platform, including screening activity, portfolio operations, and feature usage. This helps us improve the product and enforce rate limits.
Payment Information
Payment processing is handled entirely by Stripe. We never store credit card numbers, bank accounts, or other payment credentials on our servers. We receive confirmation of payment status from Stripe to manage your subscription.
2. How We Use Your Information
- To provide and operate the Remora platform
- To manage your account and subscription
- To send transactional emails (welcome, password reset, trial expiry notifications)
- To send morning briefing notifications you have opted into
- To enforce usage limits and prevent abuse
- To improve platform performance and features
3. Data Storage and Security
Your data is stored in a PostgreSQL database hosted on Supabase. All connections use TLS encryption. Passwords are hashed with bcrypt. JWT tokens expire after 60 minutes, and refresh tokens expire after 30 days.
API keys for MCP access are stored as unsalted SHA-256 hashes of a 256-bit randomly generated token. The plaintext key is shown once at creation and never stored.
4. Third-Party Services
We use the following third-party services:
- Stripe — payment processing and subscription management
- Resend — transactional email delivery
- Anthropic — AI features (the RemoraAI assistant and MCP tools); portfolio data and queries you submit are sent to Anthropic to generate responses
- Supabase — database hosting; account sign-in is handled by Remora's own JWT system, not Supabase Auth
- PostHog — product analytics, including autocaptured interface interactions and session replay of application pages; recordings are retained for 30 days
- Sentry — application error monitoring, server-side only; the browser Sentry DSN is empty, so no telemetry is sent from your browser to Sentry
- X (Twitter) Ads — advertising conversion measurement. A conversion pixel loads in your browser on our production pages and receives conversion events from the site; because it loads directly, X also receives your IP address and user agent. Your email address is SHA-256 hashed in your browser before it reaches the pixel, so the pixel receives a hash and never a plaintext address; the hashing fails closed — if your browser cannot hash it, the field is dropped rather than sent in the clear. Separately, our server sends conversion events to X's Conversions API carrying a SHA-256 hash of your email address, never a plaintext address
- TradingView — the embedded price chart on the screener; it receives the ticker symbol being charted and your browser's connection to it
- Polygon.io — market data (options chains, prices, Greeks)
- Google OAuth — optional sign-in method
- Google Fonts — web fonts loaded from
fonts.googleapis.com and fonts.gstatic.com on most pages; your browser connects to Google directly, so Google receives your IP address and user agent
- Railway — application hosting
Each service processes data according to their own privacy policies. We only share the minimum information required for each service to function.
5. Data Retention
Your account data, portfolios, and trade history are retained for as long as your account is active. After account deletion, data is removed within 30 days. Cancelled subscriptions retain data for 90 days before deletion.
6. Your Rights
- Access — You can view all your data through the platform at any time
- Export — Portfolio data can be exported via PDF reports
- Deletion — Contact us to request complete account and data deletion
- Correction — Update your profile information from the Account page
7. Cookies
We use localStorage for authentication tokens, theme preference, and report configuration. We also use third-party cookies and similar identifiers: PostHog sets them for product analytics and session replay, and the X (Twitter) advertising pixel sets them on our pages to measure ad conversions. We do not sell your data.
8. Changes to This Policy
We may update this policy as our service evolves. Material changes will be communicated via email to all registered users.
9. Contact
For privacy-related questions or data requests, contact us at support@heyremora.com.