Privacy Policy
Last updated 20 August 2026. Version 2 — voice pass and "when a human looks at your data" section added on Kurt's review.
What SignalDay holds
- Your email address (for login and receipts).
- The holdings and balances you enter or import — the positions in each account you have set up.
- The model you have chosen (a copy of its target percentages) and any per-account ticker mappings you have set.
- The rebalance history SignalDay has generated for you: which trades it calculated and which you ticked off.
- The ingest token that turns a forwarded signal email into an update on your account.
What SignalDay never holds
- Your brokerage credentials.
- Your tactical asset allocation strategy provider's credentials.
- Passwords of any kind — SignalDay signs you in with a one-time link sent to your email, and there is no password to breach.
- Social security numbers, tax identification numbers, or tax lots.
- Credit card or bank account numbers — those live with Stripe.
See What we never store for the plain-language version.
We do not sell your data
SignalDay does not sell, rent, or trade your personal data or your holdings to any third party. There is no advertising business, no audience-targeting business, and no data-broker relationship — the subscription fee is the only way SignalDay earns money.
The subprocessors listed below are third parties SignalDay pays to run the service (billing, prices, email, hosting). Each receives only what it needs to do its job, and none of them receive your holdings or your trade history.
Subprocessors
- Stripe — subscription billing and card handling.
- Tiingo — end-of-day price data for the tickers on your model.
- PostHog — pseudonymous product analytics; the privacy boundary is enforced in code (no positions, dollar amounts, tickers, or emails leave through it).
- Amazon SES — transactional email delivery (login links, receipts).
- Render — hosting and database.
- Cloudflare — DNS, CDN, and inbound-mail routing.
Export and deletion
You can export a copy of everything SignalDay holds for you, and delete your account, at any time from Settings. Deletion is permanent seven days after you confirm it: the data is unrecoverable at that point, not by you and not by us.
Stripe retains its own billing ledger — invoices, payment history — independently of a SignalDay deletion, for its own tax and dispute records. Deleting a SignalDay account cancels the subscription and removes SignalDay's copy of your data; Stripe's ledger persists as Stripe requires.
When a human at SignalDay looks at your data
Almost always, the answer is "never" — your data flows through automated code and nobody is reading it. The exceptions, in full:
- When you email us for support and we need to look at your account to answer. We ask for your explicit yes before opening anything specific to you.
- When an automated job breaks in a way that needs a person to unstick it. We aim to fix root causes so breaks don't recur, and we look at the minimum needed to restart the job.
- If a security investigation names your account (abuse report, suspicious activity affecting your data or someone else's).
- When we're compelled by US law. SignalDay is US-hosted and registered in Wyoming; a request from a non-US authority is refused unless it's routed through a US legal-assistance process.
Analytics
SignalDay records behavioural events (which pages, which buttons, counts of things) through PostHog, using a pseudonymous identifier — not your email. Financial values never leave in an event payload; the code that would send one refuses to. Behavioural events are captured server-side, so an ad-blocker in the browser does not affect them.
Contact
Email us at [email protected] for anything to do with your data or this policy.