Privacy Policy
Last updated: July 25, 2026
Overview
Castling Financial is owned and operated by Castling Holdings LLC. This Privacy Policy explains how Castling Holdings LLC ("we," "us") handles information when you use Castling Financial and related products (the "Service"). You can browse public EDGAR-derived fundamentals without an account. Optional features (Castle AI chat, MCP connectors, and paid subscription tiers) require an email sign-in and may process additional account, billing, and chat data as described below.
The Service is available worldwide. If you use it from outside the United States, your information may be processed in the United States and other countries where we or our subprocessors operate, which may have different data-protection rules than your home country. If you reach the Service through our Google Ads, we may also process advertising measurement data as described under Advertising measurement and Cookies below.
Information we collect
Depending on how you use the Service, we may handle:
- Account information: email address and authentication metadata when you sign in with a one-time email code (OTP). We create a profile tied to that account for subscription and usage settings.
- Billing and payment information: if you subscribe to a paid tier, Stripe collects and processes payment method details when you complete Checkout or update billing in the Customer Portal. We store subscription status, tier, billing period, Stripe customer and subscription identifiers, and related billing-account records needed to enforce entitlements. We do not store your full card number on our servers.
- Castle AI chat: messages you send, tool/context needed to answer, and short-lived history tokens used to continue a conversation. Chat content may be sent to our model provider (OpenRouter) to generate replies. With your consent (the "save chats on this device" behavior, on by default), your conversation history is stored locally in your browser so you can reopen past chats; it is not stored on our servers. History tokens are encrypted and time-limited (about 24 hours) and bound to your account. Chats may be reviewed and used to improve our AI models.
- MCP connectors: when you connect Castling to an MCP client via OAuth, we process authorization grants and tool requests made on your behalf under your subscription limits.
- Usage metering: product usage counters (for example MCP calls per billing period and Castle AI messages per UTC day) so we can enforce plan limits.
- Site analytics and performance: we use Cloudflare to measure how the Service loads and performs (for example page views, load times, and browser or device type). Cloudflare's analytics do not use cookies for advertising or cross-site tracking.
- Advertising measurement: when you arrive from our Google Ads campaigns, we use Google Tag Manager and Google's conversion tag (gtag.js) to measure whether ads lead to account sign-up or a paid subscription. That tag may set or read advertising cookies or similar identifiers used by Google for ad measurement and attribution. For enhanced conversions, we may provide Google a hashed form of your account email (hashed in your browser before it is sent) so Google can better match the conversion to an ad interaction. in a privacy-safe way.
- Usage and device data: hosting and infrastructure providers may log technical information such as IP address, browser type, and pages or API requests, for security, reliability, and abuse prevention.
- Local browser storage: we store data locally in your browser (for example cached financial results, chat conversation history, and chat session helpers) to make the Service faster and to let you reopen past chats. This history lives on your device, not on our servers, and you can clear it from Profile settings, in-chat delete controls, or your browser settings.
- Search queries: the ticker or company you look up is processed to retrieve the corresponding public filing data.
Data we publish
EDGAR filing-derived warehouse data (fundamentals, line items, and related public tables/views the dashboard reads) is intentionally available to the browser via our public Supabase anon key under row-level security. That data originates from public filings. Paid plans monetize Castle AI chat, MCP access, history depth, usage limits, and related UX, not a private lock on the public warehouse itself.
How we use information
We use this information to operate, authenticate, bill, secure, and improve the Service; to enforce personal-use and plan limits; to prevent abuse; to provide Castle AI and MCP features you request; and to measure whether our Google Ads lead to sign-ups or paid subscriptions (including enhanced conversion matching as described above). With your consent, we may review and use your Castle AI chats to improve our AI models. We do not sell your personal information.
International transfers
We and our subprocessors may process personal information in the United States and other jurisdictions. Where required by applicable law (for example the EU/UK GDPR), we rely on appropriate transfer mechanisms offered by our providers (such as Standard Contractual Clauses) or other lawful bases. By using the Service, you understand that your information may be transferred to and processed in countries other than your own.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or export personal information we hold about you, or to object to or restrict certain processing. To make a request, email support@castlingfinancial.com. We may need to verify your identity before responding. You can also clear local browser storage yourself, and stop using optional features (Castle AI, MCP, paid tiers) at any time.
If you have an account, you may request deletion of account-linked personal data subject to records we must keep for billing, security, fraud prevention, or legal compliance. You can update payment methods and cancel renewal through the Stripe Customer Portal ("Manage billing" in Settings) without deleting your account.
Data retention
We keep personal information only as long as needed for the purposes described in this policy, including to provide the Service, meet legal obligations, resolve disputes, and enforce our agreements. Chat history tokens are short-lived (~24 hours). Usage metering and billing records (including webhook event logs used to apply subscription changes) are retained for the periods needed to operate subscriptions, reconcile Stripe events, and comply with law. Aggregated or de-identified analytics may be kept longer.
Subprocessors
We rely on subprocessors to deliver the Service. They process data on our behalf as needed to provide their services:
- Supabase: authentication, database, and related backend services;
- Stripe: payment processing, Checkout, Customer Portal, subscription billing, and tax calculation where applicable;
- OpenRouter: model inference for Castle AI (and related worker tooling);
- Cloudflare: hosting, CDN, Workers, security, and cookieless analytics;
- Google: Google Tag Manager and Google Ads conversion measurement when you interact with our ads;
- Cookiebot by Usercentrics: consent management for cookies and advertising measurement;
- Public data sources such as SEC EDGAR, from which filings originate.
These providers have their own privacy practices. We are not affiliated with or endorsed by the SEC.
Cookies and similar technologies
We use local browser storage so the Service can function and perform well, as described above. Auth sessions may rely on tokens managed by our auth provider.
Cloudflare may inject a small JavaScript snippet to collect aggregated analytics and performance data. That measurement is designed to be cookieless and is not used to profile you across other websites.
If you reach the Service through Google Ads, Google's conversion tag may use cookies or similar technologies for advertising measurement and attribution (for example to credit a sign-up or purchase to an ad click). We use Cookiebot by Usercentrics as our consent management platform and Google Consent Mode so advertising cookies load according to your choice (and applicable regional rules). When enhanced conversions are used, your email may be normalized and hashed in the browser (SHA-256) before being sent to Google for match improvement — we do not send your raw email to Google Ads for this purpose. See Google's advertising technologies for details. We do not use additional third-party ad networks beyond Google Ads measurement described here.
Children's privacy
The Service is not directed to children under 13 (or under 16 where a higher age of digital consent applies), and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.
Changes to this policy
We may update this Privacy Policy from time to time. Changes are effective when posted, and the "Last updated" date above will reflect the latest revision.
Contact
Questions about this Privacy Policy can be sent to support@castlingfinancial.com. The Service is operated by Castling Holdings LLC.