Privacy Policy
This policy explains how InsideEdge ("we", "us") collects, uses, and protects your personal data when you use our website and service. InsideEdge is operated by InsideEdge as an individual sole trader based in the United Kingdom. You can reach us any time at support@insideedge.io.
Who we are & how to contact us
We are the data controller for the personal data described here. For any privacy question, or to exercise any of the rights set out below, email support@insideedge.io. We aim to respond within one month, as UK GDPR requires.
What data we collect
- Account data. Our authentication provider, Clerk, holds your email address, your name and profile image if you provide one, and — if you use social sign-in — the provider you signed in with and the basic profile it returns. We identify you by the user ID Clerk issues.
- Billing data. Pro subscriptions are handled by Stripe, which collects your card details and billing address on its own hosted checkout page. We never see or store your card number. Against your account we store only your Stripe customer ID, subscription ID, subscription status, and the date the current period ends — enough to know whether your Pro access is on or off.
- Your settings and lists. Your watchlist, the filers and politicians you follow, your alert preferences, your display currency, and whether you are on Pro. These are stored against your account with Clerk. Signed out, your watchlist and follows stay in your browser only.
- Technical data. Our hosts (Vercel and Fly.io) log the usual request information — IP address, user agent, the pages and API routes requested, timestamps — to serve the site and defend it against abuse.
- Error diagnostics. We use Sentry to catch errors. A report contains the page you were on and technical context about the failure; we do not attach your IP address, account ID or email by default. Only when an error occurs does Sentry also record a replay of that page, with text and form inputs masked by Sentry's default privacy settings. There is no routine session recording.
We do not collect special-category data, we do not profile you for advertising, and we do not sell personal data.
How we use your data & our lawful basis
- Creating and running your account, saving your watchlist, follows and preferences, and showing your in-app alerts — performance of our contract with you.
- Taking payment for Pro and managing renewals and cancellations — performance of our contract.
- Keeping the service available, monitoring errors and session replays, and preventing abuse — our legitimate interests in running a working, secure product.
- Answering your emails and providing support — legitimate interests / contract.
- Sending you the email digest, if you turn it on — your consent, which you can withdraw at any time.
- Keeping records we are required to keep for tax and accounting — legal obligation.
Service providers we share data with
We share personal data only with the providers that run the product. Each acts on our instructions under its own data-processing terms.
- Clerk (United States) — authentication and account records. Holds your email, name, sign-in method, and the settings listed above.
- Stripe (United States and Ireland) — subscription payments, hosted checkout, and the billing portal. Receives your email address and the card and billing details you give it directly.
- Vercel (United States) — hosts the website and its API routes. Processes request data in transit and in its logs. We do not run Vercel Analytics or Speed Insights.
- Fly.io (United States; our servers are in London) — hosts the backend that stores filing data and serves the API. It holds no account data: our filings database contains no personal data about you.
- Sentry (Functional Software, Inc., United States) — error monitoring and session replay for the website, and error monitoring for the backend. The backend is configured not to send personal data.
- Resend (United States) — email delivery, used only if you opt in to the digest. Receives your email address and the message.
- OpenRouter and Anthropic (United States) — generate the written briefs. We send only facts we have computed from public filings — tickers, filer names, share counts, dates, scores. No account data, email address, watchlist or usage history is ever sent to a model.
Company logos come from logo.dev, with Financial Modeling Prep as a fallback. Those images are fetched by our server and re-served from our own domain, so your browser never contacts them and they never see your IP address. We may also disclose data where the law requires it.
AI-generated briefs
Pro briefs, the weekly recap and the network read are written by a language model from facts we compute ourselves from public filings. The model narrates those facts; it does not receive your personal data, and your data is not used to train any model. Generated text can still be wrong — see our Terms.
Email is opt-in and off by default. We will send you service messages about your account and billing — a receipt, a failed payment, a security notice — because those are part of the contract. Anything else requires you to switch it on.
If you opt in, the digest contains the same public-filing material the site does: notable insider and institutional buying, and the tickers you watch. It is not advertising and we do not share your address with anyone other than our email provider. Every email carries an unsubscribe link, and you can also turn it off at any time in Settings. Unsubscribing takes effect immediately and does not affect your Pro access.
Cookies & browser storage
We set only strictly-necessary cookies (your sign-in session) and two preference cookies (display currency and view density), plus a few preferences kept in your browser's local storage. We run no advertising cookies and no cross-site tracking. Our Cookie Policy lists every one by name.
International transfers
Several of these providers are based in the United States, so your data is transferred outside the UK. Where that happens, the transfer is made under safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, or under an adequacy decision — including the UK Extension to the EU–US Data Privacy Framework where the provider is certified. You can ask us for details of the safeguard that applies to a particular provider.
How long we keep it
- Account data and your settings — for as long as your account exists. Deleting your account removes them.
- Billing records — Stripe keeps payment and invoice records for as long as the law requires; we keep the transaction records needed for UK tax and accounting purposes, currently six years from the end of the relevant accounting period.
- Error reports and session replays — kept by Sentry for its standard retention period and then deleted automatically.
- Server logs — kept by our hosts for their standard short retention periods, and used only for security and debugging.
- Email records — delivery records are kept while you are subscribed; if you unsubscribe we keep your address on a suppression list so we do not email you again by mistake.
Deleting your account
You can delete your account yourself: Settings → Account → Manage account → Delete account. If you have a Pro subscription, cancel it first from Settings → Manage billing — deleting the account does not cancel the subscription, and your card would keep being charged. If you would rather we did it, email support@insideedge.io and we will cancel the subscription and delete the account for you.
Deletion removes your account, your watchlist, your follows and your preferences. Billing records that we are legally required to retain, and diagnostic data already collected, remain until their retention period expires.
Your rights
Under UK GDPR you have the right to:
- access a copy of your personal data;
- have inaccurate data corrected;
- have your data erased;
- restrict or object to processing, including processing we base on legitimate interests;
- receive your data in a portable format;
- withdraw consent — for example to email — at any time, without affecting processing done before you withdrew it.
To exercise any of these, email support@insideedge.io. These rights are free to use. If you are unhappy with how we handle your data you can complain to the UK Information Commissioner's Office (ICO), ico.org.uk, though we would rather you came to us first.
Security
The site is served over HTTPS with a strict Content-Security-Policy and the usual protective response headers. Authentication and payments are handled by specialist providers rather than by us, so we never hold passwords or card numbers. No system is perfectly secure, but we take measures appropriate to the data we hold.
Children
The service is not intended for anyone under 18, and we do not knowingly collect data from children.
Changes to this policy
We may update this policy from time to time. The effective date above shows the current version, and we will tell you about material changes where it is appropriate to do so.