Privacy Policy
Privacy officer
In accordance with Quebec's Law 25 (art. 8), Polaris has designated a privacy officer responsible for the protection of personal information. You can reach them at:
Privacy Officer (Responsable de la protection des renseignements personnels)
Email: privacy@polarisapp.ca
For any request regarding your data, access, rectification, or deletion rights.
Minimum age and minors
Polaris is intended for persons aged 18 or older. We do not knowingly collect any data concerning minors. If we learn that a minor has created an account, their data is immediately deleted.
Data we collect
When you use the Service, we collect:
- Account data: email address, hashed password (never stored in plain text), registration date, preferred language.
- Usage data: stocks added to your watchlists, investment notes, conviction levels, configured alerts, history of generated analyses.
- Technical data: IP address fingerprint (SHA-256 hashed, never stored in clear text) used to limit abuse, browser type, theme preference, session identifier. Rate limiting itself runs in memory, without storing your IP address.
- Portfolio (if you create one): holdings, quantities, cost basis, declared accounts, value snapshots, and — if you connect a broker — positions and balances read in read-only mode.
- Investor profile (if you answer the questionnaire): risk tolerance, investment horizon, objectives, and the history of your successive answers.
- Notifications: your device or browser token, required to deliver an alert to you, along with your delivery preferences.
- Social activity and presence (if you use the community spaces): your messages, comments and public profile, plus a last-activity timestamp used to show who is online.
- Mobile app diagnostics: a pseudonymous device identifier, generated by the app and reset on reinstall, used to link crash reports from the same device.
- Billing data (for Pro/Elite subscribers): managed by Stripe under their own policy. We store no card number, only a Stripe customer ID.
- Error data (Sentry): in case of bug, we capture the error message, call stack, and relevant URL. No personal data is intentionally transmitted. Sentry also records a session replay (a reconstruction of your navigation: pages viewed, clicks, masked fields) for 5% of sessions chosen at random, and for sessions where an error occurs. Text input and sensitive content are masked by default.
How we use your data
- Authenticate your account and personalize your experience.
- Generate personalized analyses (macro regime applied to your watchlist, thesis wake-up, alerts).
- Calculate your usage quota (free plan) without revealing details to other users.
- Improve the Service (aggregated and anonymized usage statistics).
- Notify you of alerts or substantial changes (by email if configured).
To produce analyses, thesis wake-ups, assistant answers and message moderation, the content you enter is sent to the AI model (Anthropic, USA — or OpenAI as a failover): depending on the feature, your thesis and its invalidation signals, your portfolio positions, your question to the assistant, or the message you post. This transfer is governed by a processing agreement and serves only to produce your result. These requests contain neither your name, nor your email, nor your account identifier. We do not sell this content to anyone and do not share it with any other third party.
Automated decisions and profiling
In accordance with Law 25 (art. 12.1), we inform you that Polaris uses algorithms to generate:
- An opportunity score (0-100) based on public indicators (P/E, ROE, RSI, etc.);
- A synthetic verdict (Buy / Sell / Hold) calculated from the score;
- Automatic alerts (thesis wake-up) based on thresholds you configured.
These decisions produce no legal effect for you and are not used to evaluate personal aspects (credit, employment, etc.). You can always:
- Know which factors influence a score (clicking on each indicator displays its detail);
- Disable any automatic alert at any time;
- Obtain a detailed explanation by writing to privacy@polarisapp.ca.
Hosting and subprocessors
Your data is processed by the following subprocessors:
- Supabase — PostgreSQL database, authentication, storage of watchlists, alerts, position notes, encrypted broker tokens (AES-256-GCM) and all user data. Hosting region: Central Canada (ca-central-1, Montreal) — all your client data is stored in Canada, in compliance with Quebec's Law 25.
- Questrade (Canada) — if you connect your Questrade account to import your portfolio. Read-only access: Polaris can read your positions and balances, never place orders or transfer funds. OAuth tokens encrypted with AES-256-GCM, revocable anytime from
/portefeuilleor directly in Questrade. - SnapTrade (where applicable) — a multi-broker aggregation service (e.g. Wealthsimple, Interactive Brokers, Questrade), used only if you connect a supported brokerage account. Read-only access(positions and balances, never orders or transfers), tokens encrypted with AES-256-GCM, revocable anytime from
/portefeuille. - Coinbase (USA) — if you connect your Coinbase account to import your cryptocurrency holdings. Read-only access(
wallet:accounts:readandwallet:transactions:read): Polaris can read your holdings, never place orders or transfer funds. API key and secret encrypted with AES-256-GCM, revocable anytime from/portefeuilleor directly in Coinbase. - Vercel (USA, US-East region) — web application hosting and server function execution. Client data only in transit (TLS 1.3), no persistent storage.
- Stripe (USA, Ireland) — payment processing and billing.
- Anthropic (USA) — Claude AI models for analysis generation.
- OpenAI (USA) — two uses: (1) text-to-speech for the audio briefing (the briefing text is sent to be converted into audio); (2) failover for AI features — if Anthropic is temporarily unavailable, the same request is replayed to OpenAI so the service stays up.
- Sentry (USA) — application error monitoring.
- Resend (USA) — transactional emails (alerts, confirmations).
- hCaptcha (Intuition Machines, USA) — bot protection on the sign-in, sign-up and password-reset pages. Receives your IP address and technical signals from your browser when you submit one of those forms.
- Upstash (USA) — shared memory used to rate-limit abuse (requests per visitor). Receives only a fingerprint of your IP address, never the address itself.
- Expo (650 Industries, USA) — mobile app update delivery and push notification routing (your device token passes through it).
- Google Fonts (USA) — the site's fonts are served from Google's delivery network, so your IP address and browser are disclosed to it on every page load.
- logo.dev (USA) — official company logos shown next to tickers. Your browser loads the image directly from this service, which receives your IP address in the process.
- YouTube / Google (USA) — video thumbnails (
i.ytimg.com), loaded by your browser as soon as a video list is displayed: Google then receives your IP address and the video identifier. If you open a video, playback goes throughwww.youtube-nocookie.com, the no-tracking-cookie mode — chosen specifically to limit what Google can tie to your visit. - images.financialmodelingprep.com (USA) — stock and ETF logos. Your browser loads the image directly from this CDN, which receives your IP address and the symbol being displayed.
- CoinCap (USA) — cryptocurrency icons. As with logo.dev, your browser loads the image directly from this service, which receives your IP address in the process.
- Twelve Data, FMP, Polygon.io / Massive, Finnhub, Alpha Vantage, FRED, the Bank of Canada, multpl.com, the NBER and CoinGecko — financial and market data sources (anonymous requests only — prices, indices, rates, etc.; no personal data about you is transmitted).
International transfers
Several of our subprocessors that handle information about you (Anthropic, OpenAI, Vercel, Sentry, Stripe, Resend, hCaptcha, Upstash, Expo, Google Fonts, logo.dev, CoinCap) are located in the United States. Our financial data providers (Twelve Data, FMP, Polygon.io / Massive, Finnhub, Alpha Vantage, FRED, the Bank of Canada, multpl.com, the NBER and CoinGecko) are mostly US-based, but receive only anonymous requests (no personal data). In accordance with Law 25 (art. 17), we inform you that your data may be processed outside Quebec. We have evaluated that:
- These subprocessors offer adequate protection of personal information, aligned with Quebec and Canadian standards (PIPEDA);
- Data Processing Agreements (DPAs) are in place with each subprocessor limiting the use of your data solely to Service purposes;
- You can object to these transfers by deleting your account (AI features in particular are not available without transfer to Anthropic or, as a failover, to OpenAI; the audio briefing is not available without transfer to OpenAI).
Your rights
Under Quebec's Law 25 and GDPR, you have the right to:
- access your data;
- correct or complete it;
- request its deletion ("right to be forgotten");
- request portability in a readable format;
- object to processing or withdraw consent;
- file a complaint with the Quebec Access to Information Commission (CAI).
To exercise these rights, write to us at privacy@polarisapp.ca. We respond within 30 days. Deleting your account entails the immediate and irreversible deletion of all your notes, alerts, watchlists and history.
Breach notification
In accordance with Law 25 (art. 3.5), in case of a confidentiality incident presenting a serious risk of harm, we commit to:
- Notify the Quebec Access to Information Commission within 72 hours;
- Notify you directly by email as soon as possible, with a description of the incident, the data affected, and the measures taken;
- Maintain an internal incident register (Law 25 art. 3.8).
Data retention
Your account data is kept as long as your account is active. You can delete your account at any time from your account settings.
Deleting your account immediately erases your personal data (notes, alerts, watchlists, portfolio), except for information subject to a legal retention obligation (e.g., billing data kept 7 years by our payment processor, per applicable accounting and legal requirements).
Cookies
We use strictly necessary cookies:
- Supabase session cookie to keep you signed in.
- Theme preference cookie (light / dark / auto) — stored in localStorage, never sent to the server.
- Language preference (FR / EN) — determined by the URL path (
/fr,/en) via next-intl. - No advertising cookies, no ad trackers and no data resale: no Google Analytics, no Facebook Pixel, no ad network.
- Audience measurement (Vercel): we use Vercel Analytics and Speed Insights to count page views and measure load times. These measurements are not used for advertising and do not build an advertising profile; they record usage events (for example submitting the sign-up form), including before an account is created.
Changes to this policy
This policy may evolve. Substantial changes will be notified by email or through the application at least 30 days before they take effect. Your continued use of the Service after notification constitutes acceptance of the changes.