DT
Dossier Terminal
← Back to Home
Legal

Privacy Policy

Last updated: March 2026 · Version 1.0

Dossier Terminal, Ltd. ("Dossier Terminal," "we," "us," or "our") operates the website dossierterminal.ai and the Dossier Terminal application (collectively, the "Platform"). This Privacy Policy explains how we collect, use, disclose, and protect your information when you visit our website or use the Platform.

By using the Platform, you agree to the collection and use of information in accordance with this policy.

1. Information We Collect

1.1 Information You Provide

  • Account information: Name, email address, and password when you create an account.
  • Profile information: Timezone, notification preferences, and display settings.
  • User-generated content: Investment theses, journal entries, conversation messages with James, and notes you create within the Platform.
  • Payment information: Billing details processed through Stripe. We do not store your credit card number on our servers.
  • Communications: Emails or messages you send to us for support or feedback.

1.2 Portfolio Data (via Plaid)

When you connect a brokerage account, we receive portfolio data through Plaid Inc., including:

  • Account holdings (ticker symbols, share quantities, cost basis)
  • Account balances
  • Transaction history

We receive read-only access. We cannot execute trades, transfer funds, or modify your brokerage accounts. Your brokerage login credentials are transmitted directly to Plaid and are never stored on or transmitted through our servers.

1.3 Information Collected Automatically

  • Usage data: Pages visited, features used, time spent in the application, and interactions with James.
  • Device information: Browser type, operating system, device type, and screen resolution.
  • Log data: IP address, access times, and referring URLs.
  • Analytics: We use PostHog for product analytics to understand how the Platform is used and to improve the experience. Analytics data is used in aggregate and is not sold to third parties.

2. How We Use Your Information

We use the information we collect to:

  • Provide the service: Generate personalized dossiers, power James conversations, monitor your theses, and deliver your daily briefings.
  • Improve the Platform: Analyze usage patterns to improve features, fix bugs, and develop new capabilities.
  • Communicate with you: Send morning dossier emails (if enabled), thesis alerts, service updates, and respond to support requests.
  • Process payments: Manage your subscription through Stripe.
  • Ensure security: Detect and prevent fraud, abuse, and unauthorized access.

3. How We Protect Your Data

  • Encryption in transit: All data transmitted between your device and our servers is encrypted using TLS 1.3.
  • Encryption at rest: All data stored in our database is encrypted using AES-256 encryption.
  • Row-level security: Your data is cryptographically isolated from other users at the database level through Supabase Row-Level Security policies. James can only access data belonging to you.
  • Infrastructure: The Platform is hosted on Vercel (frontend) and Supabase (database), both of which maintain SOC 2 compliance.
  • Access controls: Administrative access to production systems requires multi-factor authentication.

4. Data Sharing and Disclosure

We do not sell your personal data. We do not sell, rent, or trade your personal information, portfolio data, conversation history, or any other user data to third parties.

We share data only with the following categories of service providers, solely to operate the Platform:

  • Plaid Inc. — Portfolio connectivity (receives your brokerage credentials and provides portfolio data to us).
  • Stripe Inc. — Payment processing (receives your billing information).
  • Anthropic — AI model provider (receives conversation content to generate James's responses). Anthropic does not use your data to train their models.
  • Vercel — Application hosting.
  • Supabase — Database hosting and authentication.
  • Resend — Email delivery (receives your email address for dossier and notification delivery).
  • PostHog — Product analytics (receives anonymized usage data).

We may also disclose your information if required by law, subpoena, or court order, or if necessary to protect the rights, safety, or property of Dossier Terminal, our users, or the public.

5. AI-Generated Content

The Platform uses artificial intelligence (specifically, Anthropic's Claude models) to generate James's responses, daily dossiers, thesis assessments, and behavioral observations. When you interact with James:

  • Your messages, portfolio data, theses, and journal entries are sent to Anthropic's API to generate responses.
  • Anthropic processes this data solely to return a response and does not retain it for model training purposes.
  • AI-generated content may contain errors, inaccuracies, or incomplete information. It should not be relied upon as the sole basis for investment decisions.

6. Cookies and Tracking

The Platform uses essential cookies required for authentication and session management. We use PostHog for product analytics, which may set cookies to track usage patterns across sessions. We do not use advertising cookies or sell tracking data to advertisers.

You can configure your browser to refuse cookies, though this may affect your ability to use the Platform.

7. Data Retention

  • Active accounts: We retain your data for as long as your account is active.
  • Cancelled accounts: After cancellation, we retain your data for 90 days in case you resubscribe. After 90 days, your data is permanently deleted.
  • Deleted accounts: When you delete your account, all associated data — including portfolio data, conversations, theses, journal entries, and vault items — is permanently deleted within 30 days.
  • Backups: Encrypted database backups may retain deleted data for up to an additional 30 days before being purged.

8. Your Rights

You have the right to:

  • Access your data: Export all your data at any time from Settings → Export.
  • Correct your data: Update your account information at any time from Settings → Profile.
  • Delete your data: Delete your account and all associated data from Settings → Delete Account.
  • Disconnect brokerages: Remove any connected brokerage account at any time from Settings → Connected Accounts. This immediately revokes our access to that account's data.
  • Opt out of emails: Disable dossier email delivery and notification emails from Settings → Notifications.

If you are a resident of the European Economic Area (EEA), United Kingdom, or California, you may have additional rights under GDPR or CCPA. Contact us at privacy@dossierterminal.ai to exercise these rights.

9. California Privacy Rights (CCPA)

If you are a California resident, you have the right to:

  • Know what personal information we collect, use, and disclose.
  • Request deletion of your personal information.
  • Opt out of the sale of personal information. We do not sell personal information.
  • Non-discrimination for exercising your privacy rights.

10. Children's Privacy

The Platform is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child under 18, we will delete it promptly.

11. International Data Transfers

Your information may be transferred to and processed in the United States. By using the Platform, you consent to the transfer of your information to the United States, which may have different data protection laws than your country of residence.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or an in-app notification. The "Last updated" date at the top of this page indicates when the policy was most recently revised. Continued use of the Platform after changes constitutes acceptance of the updated policy.

13. Contact Us

Privacy Inquiries

Email: privacy@dossierterminal.ai

General support: support@dossierterminal.ai

Entity: Dossier Terminal, Ltd.

Incorporated: Delaware, United States