MackAIBETA
TermsPrivacy
Back to MackAI
Your data, made legible

Privacy Policy

A clear account of what MackAI collects, why we need it, where AI and service providers are involved, and the controls available to you.

MACKAI LEGAL
Document
Privacy
Last updated
July 12, 2026
Effective
July 12, 2026
Version
2026.07
01
No data sales

We do not sell personal information or use it for cross-context behavioral advertising.

02
Context is feature-specific

AI and search providers receive only the prompts, queries, and selected context needed for the feature you use.

03
You can request deletion

Contact us to remove waitlist information or request deletion of your account and associated data.

IN THIS DOCUMENT
01Scope and who is responsible02Information we collect03How we use information04AI processing and automated features05When information is shared06Legal bases for processing07Retention and deletion08Security09International data transfers10Your choices and privacy rights11Cookies and local storage12Children13Policy changes and contact
QUESTIONS OR REQUESTSsupport@mackai.app

We have written this document to be readable. Section headings and summaries help navigation, but the complete text controls.

01

Scope and who is responsible

This Privacy Policy explains how the operator of MackAI (“MackAI,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information when you visit mackai.app, join the waitlist, create an account, use MackAI Today or the Full Terminal, purchase a plan, or otherwise interact with us (collectively, the “Service”).

For personal information covered by this Policy, MackAI is the controller or business responsible for deciding why and how it is processed. This Policy does not govern third-party websites or services that you visit independently.

02

Information we collect

We collect information you provide, information created through your use of the Service, and limited technical information generated when the Service operates.

CategoryExamples
Waitlist and accountEmail address, name, waitlist note, Google account identifier, display name, profile image, invitation status, and account preferences.
Portfolio and researchPositions, cash and cost-basis inputs, transactions, watchlists, plans, theses, notes, alerts, investor profile, risk preferences, research, and decision records.
Conversations and filesPrompts, Ask Mack conversations, feedback, pasted material, uploaded content, and the outputs generated in response.
Billing and usagePlan, subscription status, purchases, credit balance, usage records, model and feature usage, token counts, and estimated service cost. Our payment provider handles full card details.
Connected credentialsThird-party API keys you choose to store, together with provider type and connection status. Stored key material is encrypted at rest.
Technical and diagnosticsIP address, browser and device information, authentication session data, timestamps, request logs, crash reports, performance data, error context, user ID, and account email attached to diagnostic events.

We also receive public or licensed market, company, economic, filing, news, and research information from third-party sources. That information is generally not personal information about you, but it may be combined with your portfolio context to provide the Service.

03

How we use information

We use personal information to:

  • authenticate users, administer invitations, and maintain accounts;
  • display and analyze your portfolio, watchlist, plans, research, and decision history;
  • generate personalized briefs, conversations, alerts, rankings, and other AI-assisted outputs;
  • retrieve market and research data for the companies and themes you follow;
  • process subscriptions, allocate usage credits, and maintain transaction records;
  • deliver requested emails and operational communications;
  • secure, debug, monitor, measure, and improve the Service;
  • enforce our Terms, prevent abuse, and comply with legal obligations; and
  • respond to support, privacy, and account requests.

We do not use private portfolio content to train our own general-purpose AI models. We may use aggregated or de-identified operational information to understand performance, reliability, cost, and feature usage where it can no longer reasonably identify you.

04

AI processing and automated features

When you use AI-assisted features, we send the AI or search provider the instructions, queries, and selected context needed to produce the requested output. Depending on the feature, that context may include ticker symbols, portfolio positions, watchlist items, theses, plans, notes, investor preferences, prior conversation, or retrieved source material.

Providers process that information under their applicable service terms, data-processing commitments, and privacy policies. Retention and model-improvement practices can vary by provider and account configuration. We therefore recommend that you do not submit passwords, payment-card details, government identifiers, bank credentials, medical data, or other information that is not needed for investment research.

MackAI may prioritize or summarize items for your review, but it does not place trades, move money, or make legal or similarly significant decisions about you without your action.

05

When information is shared

We do not sell personal information or use it for cross-context behavioral advertising. We disclose information only as needed to operate the Service, complete a transaction, follow your direction, protect rights and safety, or comply with law.

Recipient categoryPurpose and information involved
Hosting and databaseProviders such as Vercel and Supabase host the application, database, and authentication systems and process account, portfolio, request, and session information.
AI and searchProviders such as Google Gemini, Vercel AI Gateway and its search partners, and Exa receive prompts, queries, retrieved sources, and selected portfolio context needed for requested research.
PaymentsPolar processes checkout and subscription administration. We provide account and product details and receive purchase, plan, and payment-status records.
DiagnosticsSentry receives errors, technical context, user ID, and account email so we can detect and investigate failures.
Email deliveryResend receives the email address and message content needed to deliver briefs or service communications you request or enable.
Market and public dataMarket-data, filings, news, and economic-data providers receive ticker symbols, document identifiers, or research queries needed to return information.

We may also disclose information to professional advisers; to authorities or other parties when reasonably necessary to comply with law or protect the Service, users, or others; or in connection with a financing, merger, acquisition, reorganization, or sale of assets. If ownership changes, this Policy continues to apply until you are notified otherwise.

06

Legal bases for processing

Where European Economic Area or United Kingdom data-protection law applies, we rely on one or more of these legal bases:

  • Contract: to create your account and provide features you request.
  • Legitimate interests: to secure, operate, debug, understand, and improve the Service; prevent abuse; and communicate about it, where those interests are not overridden by your rights.
  • Consent: where you opt into optional emails or another feature that requires consent. You may withdraw consent at any time.
  • Legal obligation: to maintain required records and respond to lawful requests.
07

Retention and deletion

We retain account and portfolio information while your account is active and for a limited period afterward when needed to provide the Service, resolve disputes, enforce agreements, maintain security, or satisfy legal obligations. Specific periods depend on the type of information and why we hold it.

  • Waitlist information is kept while we evaluate or administer access, or until you ask us to remove it.
  • Billing and transaction records may be retained for tax, accounting, fraud-prevention, and legal requirements.
  • Operational logs, diagnostics, and backups are retained on limited cycles that may vary by provider.
  • De-identified information may be retained where it can no longer reasonably identify you.

You may request account deletion by emailing us. We aim to complete verified deletion requests within 30 days, subject to legal retention, security needs, and ordinary backup deletion cycles.

08

Security

We use administrative, technical, and organizational safeguards designed for the nature of the Service. These include authenticated access, user-scoped application queries, encrypted network connections, restricted production access, and AES-256-GCM encryption for stored bring-your-own API keys.

No internet service is completely secure. We cannot guarantee that information will never be accessed, lost, altered, or disclosed without authorization. You can help by protecting your Google account, using restricted API keys, monitoring provider usage, and promptly reporting suspected compromise.

09

International data transfers

MackAI and its service providers may process information in countries other than the one where you live. Those countries may have different data-protection laws. Where required, we use recognized transfer mechanisms or rely on providers that offer appropriate contractual safeguards for international transfers.

10

Your choices and privacy rights

Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, or portability of personal information, and to withdraw consent or appeal a denied request. You may also have the right to complain to your local data-protection authority.

  • Portfolio records and preferences can be reviewed or changed through the Service where editing is available.
  • Stored API keys can be removed from Settings.
  • Optional brief emails can be disabled in the relevant delivery settings.
  • Google account access can be revoked through your Google account controls.
  • Account, waitlist, access, or deletion requests can be sent to support@mackai.app.

We may need to verify your identity before completing a request. Authorized agents may submit requests where local law permits, subject to proof of authorization. We will not discriminate against you for exercising an applicable privacy right.

11

Cookies and local storage

We use cookies and similar browser storage that are necessary to authenticate you, secure sessions, remember interface preferences, and route selected product settings. For example, the Service may store theme or AI-provider preferences locally in your browser.

We do not use advertising cookies or cross-site behavioral advertising. Blocking essential cookies may prevent sign-in or other core features from working.

12

Children

The Service is intended for adults and is not directed to children under 18. We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us so we can investigate and delete it where appropriate.

13

Policy changes and contact

We may update this Policy as the Service, providers, or legal requirements change. If an update materially changes how we handle personal information, we will provide reasonable notice through the Service, email, or another appropriate channel. The date above shows when this version was last updated.

For privacy questions, account deletion, waitlist removal, or rights requests, contact support@mackai.app. Please do not include passwords, API keys, or other secrets in your email.

RELATED DOCUMENTTerms of Service

Read the companion document for the complete picture.

Open Terms of Service
MackAIBETA

Portfolio intelligence for individual investors.

TermsPrivacy© 2026 MackAI
Not financial advice.