This Privacy Policy explains what information FlowFinder collects, how we use it and the choices you have. We aim to keep this short and readable — if anything is unclear, please email flowhelp@yahoo.com.
What we collect
- Account data: email, name (optional), hashed password, plan, and OAuth identifiers if you sign in with Google.
- Usage data: page views, scans run, tickers viewed, watchlists, saved scans, and session timestamps. Used to operate the product and produce admin analytics.
- Technical data: a long-lived anonymous cookie (ff_anon), user-agent, approximate country/city derived from IP, and device type. We hash IPs before storing them in the geo-lookup cache.
- Payment data: processed by Stripe. We never see or store your card details.
How we use it
- Provide and improve the Service (running scans, computing indicators, sending account email).
- Authenticate sessions and protect against brute-force attempts.
- Produce aggregate analytics for the admin dashboard (visitors, DAU/WAU/MAU, retention).
- Communicate with you about your account, security or service updates.
Cookies
We use a single first-party cookie (ff_anon) to recognise returning browsers so we don't count refreshes as new visitors. Auth cookies (access_token, refresh_token,session_token) keep you signed in. We do not sell or share these with advertisers.
Third-party services
- Stripe — subscription billing
- Finnhub — live market data
- Google OAuth (optional) — sign-in
- ipapi.co — country-level geo lookup (IP is hashed in our cache)
Your rights
You can access, update or delete your account from the Profile page or by emailing us. We retain analytics events for up to 24 months, geo cache entries for up to 90 days, and account records as long as your account is active. Deleting your account removes your profile and unlinks events from your user ID.
Security
Passwords are hashed with bcrypt. Auth cookies are HttpOnly + Secure + SameSite=None. Database access is restricted; production secrets are kept in environment variables, not in source. We do our best — but no online service can guarantee perfect security.
Children
FlowFinder is not directed at children under 16. We do not knowingly collect personal information from anyone under 16.
Changes
We may update this Policy. Material changes will be communicated in-app or by email.
Contact
Questions or data requests? Email flowhelp@yahoo.com.
