Privacy Policy
Privacy Policy
GexTweak.
Effective: September 6, 2026 · Last updated: September 6, 2026
On this page
1. Scope
This Privacy Policy explains how GexTweak ("we", "us") collects, uses, stores, and shares personal information when you use our website, dashboard, and related services ("Service"). It applies to all Users, including free-tier accounts.
2. Data We Collect
2.1 Account data
- Email address — used as your login identifier and for transactional notifications.
- Username — optional, set during signup or via Google OAuth.
- Sign-in identifiers — email address, and if you use it, your Google or Discord account identifier and the profile name/avatar those providers share. Authentication is operated by Clerk (see §5); we store the Clerk user id alongside your account.
- Password — stored by Clerk as a salted one-way hash; we never see your plain-text password.
- Two-factor authentication — if enabled, the authenticator secret is held by Clerk.
2.2 Subscription data
- Current tier (free / retail / whale), plan expiration date, trial status.
- Whop billing identifiers (membership ID, product ID) — full card data stays with Whop.
2.3 Usage data
- Last-login timestamp, account creation date.
- IP address (used for security, rate limiting, and abuse detection).
- User-agent string (browser + OS, for compatibility & security).
- Active session tokens (so you can stay logged in across devices).
- Server-side logs of API requests, including ticker symbols queried and feature usage (for billing tier enforcement and debugging).
2.4 User-generated content
- Watchlist tickers you add.
- Alert settings you configure.
- Referral codes you generate or redeem.
- Your username and your broadcast-email preference.
- Custom layouts and preferences — chart and terminal preferences are stored in your browser's localStorage, not on our servers.
2.5 Communications
- Emails you send to support.
- Broadcast email preferences (subscribed / unsubscribed).
3. How We Use Your Data
| Purpose | Data Used |
|---|---|
| Authenticate & authorize you | Email, sign-in provider identifiers, Clerk user id, session tokens |
| Provide subscription features | Subscription tier, tier expiration |
| Process payments & renewals | Email (shared with Whop), webhook events |
| Send transactional emails (login alerts, billing receipts, security) | |
| Detect & prevent fraud, abuse, scraping | IP, user-agent, request patterns |
| Save your preferences across sessions | Watchlists, layouts, alerts |
| Deliver alerts you opted into (Discord/email) | Alert settings, email |
| Improve the Service (aggregate analytics) | Anonymized usage stats |
| Comply with legal obligations | All data, when required by law |
We do not sell your personal data. We do not run third-party ads. We do not share your data with data brokers.
4. Cookies & Tracking
We use first-party cookies and similar storage (localStorage) for:
- Session cookies — keep you logged in. Expire on logout or after inactivity.
- CSRF tokens — protect against cross-site request forgery.
- Preferences — remember theme choice, default ticker, layout settings.
- localStorage — terminal and chart preferences (drawings, selected view, chart settings) are kept in your browser only.
- Service-worker cache — stores app files locally so pages load faster offline or on a slow connection.
We do not use third-party ad-tracking cookies. We do not use Google Analytics, Facebook Pixel, or similar tracking pixels.
5. Third-Party Services
To run the Service, we share specific data with these processors:
| Provider | Purpose | Data Shared |
|---|---|---|
| Clerk | Authentication: sign-in, sign-up, OAuth, two-factor, sessions | Email, sign-in identifiers, provider profile basics, IP/user-agent at sign-in |
| Whop | Payment processing & subscription billing | Email, billing info, subscription events |
| OAuth sign-in (optional, via Clerk) | Google ID, email, profile name | |
| Unusual Whales | Institutional flow, dark pool prints, earnings data | None — server-side API key only |
| Market data providers | Derived quotes and options chains | None — server-side API keys only |
| Discord | Optional sign-in (via Clerk), community and alert delivery | Discord ID, username, email if you sign in with Discord; your Discord account if you join the community |
| Google Fonts and script CDNs (jsDelivr, unpkg, plot.ly) | Font and script files | Your IP address when those files load |
| Email infrastructure | Transactional emails (verification, password reset, billing) | Email address |
| Cloud hosting (Oracle Cloud) | Server hosting | All app data, encrypted in transit |
Each processor has its own privacy policy — review them for full details on their data handling.
6. Data Retention
- Active accounts: data kept while account is active + 90 days after last login.
- Cancelled subscriptions: account data kept 12 months in case of re-subscription.
- Deleted accounts: personal data deleted within 30 days; anonymized logs may persist.
- Billing records: kept 7 years for tax & legal compliance.
- Audit logs: security & admin audit trails kept 12 months.
7. Security
We use industry-standard protections:
- HTTPS / TLS encryption for all traffic.
- Authentication, password hashing and two-factor handled by Clerk (SOC 2 Type II); our own session cookie is HttpOnly and SameSite.
- CSRF protection on all state-changing requests.
- Rate limiting & IP blocking for abusive traffic.
- Optional 2FA (TOTP) for account access.
- Card data stays with Whop (PCI-DSS compliant) — we never see card numbers.
- Server-side admin audit log of all sensitive actions.
No system is 100% secure. If we become aware of a breach affecting your data, we will notify you within 72 hours where required by law.
8. Your Rights
Depending on your jurisdiction (GDPR, CCPA, similar), you may have these rights:
- Access — request a copy of personal data we hold about you.
- Correction — fix inaccurate data (also doable in your account settings).
- Deletion — request account deletion. Email support to start the process.
- Portability — request your data in a machine-readable format.
- Opt out — unsubscribe from marketing emails anytime (link in every email).
- Withdraw consent — for processing based on consent.
- Lodge a complaint — with your local data protection authority.
Submit any request to gextweak@gmail.com. We respond within 30 days.
9. Children's Privacy
The Service is not directed to anyone under 18. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.
10. International Users
The Service is hosted in the United States. By using it, you consent to your data being processed in the US, which may have different data protection laws than your country. For EU/UK users, we rely on standard contractual clauses or equivalent safeguards where required.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be announced via email or in-app notice at least 7 days before taking effect. The "Last updated" date at the top reflects the latest revision.
12. Contact
Privacy questions or requests:
- Email: gextweak@gmail.com
- General support: gextweak@gmail.com