Privacy Policy

Last updated: April 10, 2026

1. Data We Collect

  • Account data: email address, password hash, account creation date.
  • Telegram identifier: your Telegram user id, linked through a single-use deep link token.
  • Subscription data: plan, billing cycle, trial status, subscription identifier from Paddle.
  • Usage data: prompts sent to the bot, tickers searched, timestamps (used for rate limiting and research quality).
  • Analytics: anonymised events (page views, button clicks) through PostHog and error reports through Sentry.

2. How We Use Your Data

We use personal data to operate the Service, process payments, generate market research responses, enforce usage limits, prevent fraud and improve the product. We never sell personal data.

3. Data Sharing

  • Paddle — payment processing, tax handling, subscription management (merchant of record).
  • Supabase — hosted database and authentication provider, located in the Seoul region.
  • Telegram — message delivery to and from the bot.
  • OpenAI — AI inference for market research responses (no account identifiers are sent).
  • PostHog and Sentry — product analytics and error monitoring.

4. Data Retention

Account data is retained for as long as you maintain an active subscription. After cancellation we retain minimal billing records for seven years as required by tax law and delete all other personal data within 30 days on request.

5. GDPR Rights

If you are in the European Economic Area or the United Kingdom, the General Data Protection Regulation (GDPR) gives you the following rights:

  • Right of access — request a copy of your personal data.
  • Right to rectification — correct inaccurate personal data.
  • Right to erasure — request deletion of your personal data ("right to be forgotten").
  • Right to data portability — receive your data in a machine-readable format.
  • Right to object — object to processing based on legitimate interests.
  • Right to restrict processing — limit how we use your data.

To exercise any of these rights, contact support@askbit.app. We respond within 30 days.

6. Cookies

We use essential cookies for authentication (Supabase session cookie) and a single localStorage key to remember your language preference. We do not use advertising cookies.

7. Children

The Service is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us for removal.

8. Contact

Questions about this Privacy Policy can be sent to support@askbit.app.