Privacy Policy
Last updated: 9 September 2026
This policy explains what Analyst Report collects, why, who else sees it, and what you can require of us. It covers analystreport.ai and everything served from it.
The controller is Winternet Labs, registered in the Netherlands under KVK number 98514601. For anything in this policy — including a request to see or delete your data — write to [email protected].
1. The short version
- We collect an email address, and only after you confirm it do we send you anything beyond that confirmation.
- There is no analytics, no advertising, and no tracking cookie on this site. The only cookie is the one that keeps you signed in.
- Your IP address is shortened before it is stored. We never keep the full one.
- We do not sell or rent your data, and we never will.
- The companies you research are not used to train anything and are not shown to anyone.
2. What we collect
If you give us your email address. The address itself; the ticker or company name you were looking at when you asked, which is what the first email is about; which form you used; the date; and the state of your subscription — whether you have confirmed, where the sequence has reached, when we last wrote, whether you unsubscribed or the address bounced. We also store a shortened IP address and a truncated browser user-agent string, to make abuse of the form traceable. The IP is cut to its first three groups (IPv4) or first three segments (IPv6) before it is written, so what is stored identifies a network, not a device.
If you create an account. Your email address, an optional name and avatar, and — for a password account — a bcrypt hash of your password. We never store the password itself. If sign-in with Google is enabled and you use it, we receive your name, email address, and avatar from Google. We also hold your tier and credit balance.
If you start a research run. The company or ticker you asked about, in the words you typed; the resolved symbol and company name; the status of each of the five steps and any defects the review gate recorded; the model used; what the run cost us; any quality warnings; and, if you supply one, the byline name and email you want on the finished report. Runs are linked to your account.
Automatically. A signed session cookie once you log in. Rate-limit counters keyed to a shortened IP address or an email address. Ordinary server logs kept by our hosting provider. Nothing else — see section 6.
3. Why we use it, and the legal basis
To run your account and deliver what you asked for (Art. 6(1)(b) GDPR — performance of a contract): authenticating you, starting and tracking runs, producing and delivering reports, and answering support mail.
To send the email sequence (Art. 6(1)(a) GDPR — consent): the sample note and the follow-up emails, sent only after you confirm. You can withdraw consent at any time by unsubscribing, and withdrawing it does not affect what was sent before.
To keep the service standing up (Art. 6(1)(f) GDPR — legitimate interests): rate limiting, abuse prevention, debugging, and keeping our sending domain out of spam folders by retiring addresses that bounce or complain. We use the least data that achieves this, which is why the IP address is shortened before storage rather than after.
To keep records the law requires us to keep (Art. 6(1)(c) GDPR): once paid ordering opens, invoices and transaction records.
We do not profile you and we take no automated decisions that produce legal or similarly significant effects.
4. Email: how consent actually works here
When you submit an address it is stored as pending and sent exactly one message: a request to confirm. If you never click the link, that is the only email you will ever receive from us, and the record sits unconfirmed. Clicking it marks the address active, which is the only state our sending job will write to.
Every email carries a one-click unsubscribe. Unsubscribing is permanent: the record is marked unsubscribed and signing up again does not quietly revive it — it goes back through confirmation. If an address hard-bounces, or someone marks a message as spam, we retire it automatically and stop sending.
The sequence is four emails over roughly eleven days, and it stops early if you buy. We do not send other companies’ marketing, and your address is not shared with anyone for their own use.
5. Who else sees your data
We use these providers, each only for what is listed. They act on our instructions and may not use your data for their own purposes.
- MongoDB Atlas — the database holding accounts, leads, and runs.
- Resend — sends every email, and tells us when one bounces or is marked as spam.
- Vercel — hosts the site and keeps ordinary request logs.
- Yahoo Finance — receives the text you type into ticker search, so it can return matching companies. It receives no account details and nothing identifying you.
When report generation opens, a run will additionally be processed by a large language model provider (currently DeepSeek), an object store for the report and its exhibits, and an isolated sandbox that executes the model-written analysis code. What reaches them is the research task — a company, its filings, its market data. Your name, your email address, and your account are not sent, and a report byline is only included if you asked for one. None of this is live yet: the generation engine is not connected, so no model provider has received anything.
We will also disclose data where the law requires it, or to establish or defend a legal claim. If the business is ever transferred, we will tell you before your data moves.
6. Cookies, and the tracking we do not do
This site sets one cookie: the signed session cookie that keeps you logged in. It is strictly necessary, so it needs no consent banner, and it is gone when you sign out.
There is no Google Analytics here, no advertising pixel, no session recorder, no third-party script of any kind. We do not build a profile of you, do not track you between sites, and cannot tell you apart from another visitor until you type something into a form.
7. Where your data is
We keep data in the EU where the provider offers it. Some providers above operate outside the EEA, including in the United States, and the model provider that will process runs operates outside the EEA. Those transfers rely on the European Commission’s Standard Contractual Clauses or an adequacy decision. Ask us and we will tell you which applies to a given provider.
8. How we protect it
- Everything travels over TLS.
- Passwords are stored only as bcrypt hashes, never in plain text.
- Confirmation and unsubscribe links are signed, so they cannot be forged or edited to affect somebody else’s subscription.
- Runs are bound to the account that created them, and a run can only be read by its owner.
- The IP address is shortened at the moment of collection, so the full one never reaches the database.
No system is perfectly secure. If a breach affects your data and puts you at risk, we will tell you and the supervisory authority as Articles 33 and 34 GDPR require.
9. How long we keep it
- Unconfirmed addresses — kept on file, and never mailed beyond the single confirmation request. Ask us and we will delete one straight away.
- Confirmed subscribers — until you unsubscribe. After that we keep the address and its unsubscribed status, and nothing else, so that we can honour the request and not mail you again.
- Accounts and their runs — while the account exists. Ask us to close it and we delete the account, its runs, and the reports they produced.
- Rate-limit counters — hours, then they expire.
- Server logs — kept by our host under its own retention, typically weeks rather than months.
- Invoices, once there are any — seven years, as Dutch tax law requires.
10. Your rights
You may ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, to receive it in a portable form, and to withdraw consent at any time.
Two of these need no request at all: unsubscribing is one click in any email, and it takes effect immediately. For anything else, write to [email protected] and we will answer within one month. We may ask you to confirm your identity before acting on a request about an account.
If you think we have handled your data badly, you can complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or to the authority where you live.
11. Children
Analyst Report is for adults. We do not knowingly collect data from anyone under 18. Tell us if you believe we have, and we will delete it.
12. Changes
We may update this policy. For material changes we will email account holders and confirmed subscribers before they take effect, and the date at the top always tells you which version you are reading.
13. Contact
Analyst Report — [email protected]
Winternet Labs, the Netherlands — KVK 98514601