Privacy Policy
Effective August 21, 2026
The short version
We collect what the product needs to work, we don’t sell your data, there are no ads, and you can erase everything yourself — in the app, in one place, permanently. Sestara AI and sestara.net are operated by JULL LLC, the data controller for this policy.
1. What we collect
- Account: email address, password (held by our auth provider — we never see it), your name, and an optional phone number.
- Consent record: that you confirmed being 18+ and accepted the risk disclosure and these policies, and when.
- What you put in: portfolio holdings, watchlist tickers and notes, decision-journal entries, alert rules, feedback, and chat messages.
- What the product generates for you: committee verdicts and reports, scores, track-record grades, credit and purchase history.
- Push token: only if you turn on morning-brief notifications; turning them off removes it.
- Usage analytics: first-party product events — which features you open and when — stored only in our own database to understand what’s useful and improve the app. PII-light (an opaque id and the feature name, never message content), and never shared with or sold to a third party.
- Technical basics: standard server logs (timestamps, endpoints, status codes) for reliability and abuse prevention.
We do not collect your brokerage credentials, card numbers, precise location, contacts, or advertising identifiers.
2. How we use it
To run Sestara for you: compute your portfolio views, run the committee on tickers you choose, evaluate your alerts, compose your Daily Open, sync one account across web and mobile, process purchases, respond to feedback, and keep the service secure. That’s the list — no advertising, no selling, no profiling for third parties.
3. Who processes it for us
Sestara runs on established processors, each receiving only what its job requires:
- Supabase — authentication and database hosting.
- Render — application servers and background workers.
- Vercel — web hosting.
- Stripe — payments. Your card details go directly to Stripe and never touch our servers.
- Anthropic — the AI models behind the committee and chat. Requests contain the financial dossier being analyzed and your questions — chat can include your holdings so answers are grounded — and are not used to train models per our API terms.
- Market-data providers (SEC EDGAR, Finnhub, Yahoo Finance) — we send them ticker symbols, never your identity.
- Resend — transactional email (confirmations, welcome, resets).
- Expo — push-notification delivery, if you opt in.
4. How long we keep it
For as long as you have an account. When you delete your account (Account screen → Delete my account), every table keyed to you is truncated immediately — portfolio, watchlist, verdicts, journal, alerts, push tokens, purchase history, the consent record, and the login itself. There is no recoverable archive. Aggregate operational logs that don’t identify you may persist for a short rotation window.
5. Security
Traffic is encrypted in transit (TLS); data is encrypted at rest by our hosting providers; passwords are handled exclusively by Supabase Auth; secrets are stored in managed environment configuration; and paid features require authenticated sessions. No system is perfectly secure — if we learn of a breach affecting your data, we will notify you as required by law.
6. Children
Sestara is for adults. We do not knowingly collect data from anyone under 18; the signup flow requires an explicit 18+ confirmation, and we delete underage accounts on discovery.
7. Your rights
You can view most of your data directly in the product, correct your profile in the app, export what you entered by asking us, and erase everything yourself without asking anyone. Depending on where you live you may have additional statutory rights (access, portability, objection); contact us through the feedback form to exercise them and we will respond within the legally required time.
8. Changes
If this policy changes materially we will notify you in the app or by email before the change takes effect. The effective date above always reflects the current version.