Last updated 27 September 2026

Privacy

ScanPro at stonkly.ai is run by Stonklab. This page says what we collect, why, who else handles it and how long we keep it. Questions go to support@stonkly.ai.

The short version: we keep what it takes to run your account and the features you use. We show no ads, use no tracking cookies or third-party analytics, and we don’t sell or share your data for advertising.

What we collect

  • Your account. Your username, email address, password, plan, when you joined and when you confirmed your address. The password is stored only as a salted one-way hash, so nobody here can read it.
  • If you continue with Google. Google tells us your account's email address, whether Google has verified it, and your permanent Google account ID. We keep the ID and the address so we can recognise you next time. Google's sign-in also includes your name and profile picture; we don't keep either. We never see your Google password or anything else in your Google account.
  • What you make in the app. Watchlists, saved scans, paper-trading portfolios and bots, alert and notification settings, lesson progress, and any access tokens you create for an AI assistant (stored as a one-way hash, like the password).
  • The newsletter. If you subscribe without an account: your email address and whether it is waiting for confirmation, subscribed or unsubscribed. For members, which editions you chose.
  • Messages you send us. Bug reports, feature ideas and other feedback: the title, what you wrote and the page you were on. Each one is kept and also emailed to our support inbox, with your address when it is confirmed so we can reply.
  • Push notifications. Only if you turn them on: the delivery address and keys your browser gives us for that device.
  • Visit counts. We count page views ourselves, without cookies or outside scripts: the page's path and, for the first page of a visit, the site you came from (its domain only) and any utm_source tag. We don't store your IP address or browser details. To count unique visitors per day we keep a scrambled code made from them with a key that is thrown away every day, so a visit can't be linked to another day's. Nothing is sent when your browser has Do Not Track or Global Privacy Control turned on.
  • Server logs. Like any website, our web server records each request: your IP address, the time, the address requested and your browser's identification. We use them to fix problems and to stop abuse.

Cookies and browser storage

One cookie keeps you signed in. It lasts 30 days or until you sign out, and page scripts can’t read it. While a Google sign-in is in progress a second cookie, lasting ten minutes, protects it from forgery. There are no advertising, analytics or third-party cookies.

The app also saves a few display choices in your browser’s own storage: light or dark theme, whether the sidebar is collapsed, chart settings and the symbols you viewed recently. They stay on your device and are never sent to us.

How we use it

To run your account and the features you use; to send the email you need or asked for (confirming your address, password resets, a notice when your password or address changes, and the newsletter if you subscribed); to answer your messages; and to keep the service secure and working. Nothing else.

Who else handles it

  • Our hosting provider. The app and its database run on servers we rent. The provider stores the data for us and has no other use for it.
  • Amazon Web Services. Amazon's email service (in the United States) sends our email and receives mail addressed to us, so it handles the addresses and contents of those messages.
  • Google. Only if you choose Continue with Google, for the sign-in described above.
  • Your browser's push service. Only if you turn on notifications: they are delivered through the service your browser's maker runs for that.
  • An AI assistant you connect. If you give an assistant an access token, what it reads from your account goes to that assistant's provider, under their terms. You can revoke a token at any time on your Account page.

Market data comes to us from data providers; nothing about you is sent to them. We would disclose information to authorities only where the law requires it.

How long we keep it

  • Your account and what you made in it. Until you delete the account.
  • Sign-in sessions. 30 days, or until you sign out. A password reset signs you out everywhere.
  • Email links. A confirmation link works for 48 hours, a password reset link for one hour, and each works once.
  • Newsletter sign-ups. An unconfirmed sign-up is deleted after 7 days. After you unsubscribe we keep the address marked as unsubscribed, so it is not mailed again.
  • Visit counts. 400 days.
  • Web server logs. 30 days.
  • Backups. Nightly, each kept for 7 days.

Your choices

You can change your email address and password on your Account page, switch newsletter editions and notifications on or off there, and leave the newsletter in one click from any issue.

You can delete your account yourself, at the bottom of the Account page. That removes it and everything made in it at once, including feedback you sent; copies in backups are gone within 7 days after that, and copies of your feedback already emailed to our support inbox stay there until we clear it. To get a copy of your data or correct it, write to support@stonkly.ai from the address on your account. We answer within 30 days.

Security

Everything between your browser and the site is encrypted. Passwords, access tokens and emailed links are stored only as one-way hashes, and every account’s data is kept separate from every other’s. No system is perfectly secure; if something goes wrong that affects your data, we will tell you.

Children

ScanPro is not meant for anyone under 16, and we don’t knowingly collect their data. If you think a child has signed up, write to support@stonkly.ai and we will delete the account.

Changes

When this policy changes we update this page and the date at the top.