Legal

Privacy Policy

Last updated: March 18, 2026

AstralLedger ("we", "us", "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use the AstralLedger platform ("the Service").

1. Information We Collect

1.1 Information You Provide

Data TypeDetailsPurpose
Account InformationName, email address, passwordAuthentication and account management
Profile DataDisplay name, avatar URL, preferencesPersonalization
Brokerage Connection DataPlaid-linked account identifiers and server-side access tokens needed to retrieve authorized brokerage dataPortfolio data retrieval and account connection management

1.2 Information We Collect Automatically

Data TypeDetailsPurpose
Portfolio DataHoldings, positions, transaction historyAnalytics, AI coaching, risk assessment
AI ConversationsCoach chat messages and responsesConversation continuity, service improvement
Price AlertsSymbols, target prices, trigger statusAlert delivery
Investment GoalsGoal names, amounts, target datesGoal tracking features
Session DataLogin timestamps, session tokensAuthentication and security

1.3 Information from Third Parties

2. How We Use Your Information

We do not sell, rent, or trade your personal information to third parties for marketing purposes.

3. Legal Basis for Processing (GDPR)

If you are in the European Economic Area (EEA), our legal bases for processing your data are:

4. Data Storage & Security

5. Data Sharing

We share your data only with the following service providers, strictly for operating the Service:

ProviderPurposeData Shared
SupabaseDatabase and authenticationAccount info, portfolio data, conversations
OpenAIAI coaching enginePortfolio summaries and chat messages (anonymized)
GoogleOAuth sign-inAuthentication tokens only

We do not share your data with advertisers, data brokers, or any parties not listed above.

6. Your Rights

Under GDPR, CCPA, and other applicable laws, you have the following rights:

7. Data Retention

8. Cookies

We use only essential cookies required for the Service to function:

CookiePurposeDuration
sessionAuthentication and session management7 days

We do not use tracking cookies, analytics cookies, or third-party advertising cookies.

9. Children's Privacy

The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected data from a child under 18, we will promptly delete it.

10. International Data Transfers

Your data may be processed in the United States or other jurisdictions where our service providers operate. We ensure appropriate safeguards are in place for international transfers in compliance with GDPR and other applicable laws.

11. California Privacy Rights (CCPA)

If you are a California resident, you have the right to:

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service. The "Last updated" date at the top indicates when this policy was last revised.

13. Contact Us

For privacy-related questions, data requests, or concerns: