Privacy Policy

Last updated: August 12, 2026

Overview

Castling Financial is owned and operated by Castling Holdings LLC. This Privacy Policy explains how Castling Holdings LLC ("we," "us") handles information when you use Castling Financial and related products (the "Service"). You can browse public EDGAR-derived fundamentals without an account. Optional features (Castle AI chat, MCP connectors, and paid subscription tiers) require an email sign-in and may process additional account, billing, and chat data as described below.

The Service is available worldwide. If you use it from outside the United States, your information may be processed in the United States and other countries where we or our subprocessors operate, which may have different data-protection rules than your home country. If you use the Service, we may also process site analytics and advertising measurement data (including through Cloudflare Zaraz and Google tags) as described under Site analytics, Advertising measurement, and Cookies below.

Information we collect

Depending on how you use the Service, we may handle:

  • Account information: email address and authentication metadata when you sign in with a one-time email code (OTP). We create a profile tied to that account for subscription and usage settings.
  • Billing and payment information: if you subscribe to a paid tier, Stripe collects and processes payment method details when you complete Checkout or update billing in the Customer Portal. We store subscription status, tier, billing period, Stripe customer and subscription identifiers, and related billing-account records needed to enforce entitlements. We do not store your full card number on our servers.
  • Castle AI chat: messages you send, tool/context needed to answer, and short-lived history tokens used to continue a conversation. Chat content may be sent to our model provider (OpenRouter) to generate replies. With your consent (the "save chats on this device" behavior, on by default), your conversation history is stored locally in your browser so you can reopen past chats; it is not stored on our servers. History tokens are encrypted and time-limited (about 24 hours) and bound to your account. Chats may be reviewed and used to improve our AI models.
  • MCP connectors: when you connect Castling to an MCP client via OAuth, we process authorization grants and tool requests made on your behalf under your subscription limits.
  • Usage metering: product usage counters (for example MCP calls per billing period and Castle AI messages per UTC day) so we can enforce plan limits.
  • Site analytics and performance: we use Cloudflare to measure how the Service loads and performs (for example page views, load times, and browser or device type). Cloudflare's analytics do not use cookies for advertising or cross-site tracking. We also use Google Analytics (loaded through Cloudflare Zaraz when configured) to understand how visitors use the Service (for example pages viewed, approximate location derived from IP, device/browser type, and referral source). Google Analytics may use cookies or similar technologies when allowed by your consent choice.
  • Advertising measurement: when you interact with our ads or visit the Service, we may load advertising measurement tags — including Google Ads conversion tags (gtag.js) and, where configured via Cloudflare Zaraz, measurement pixels for other ad platforms we advertise on (for example Reddit and X). Those tags help us measure whether ads lead to page visits, account sign-up, or a paid subscription, and may set or read advertising cookies or similar identifiers. For Google Ads enhanced conversions, we may provide Google a hashed form of your account email (hashed in your browser before it is sent) so Google can better match the conversion to an ad interaction in a privacy-safe way.
  • Usage and device data: hosting and infrastructure providers may log technical information such as IP address, browser type, and pages or API requests, for security, reliability, and abuse prevention.
  • Local browser storage: we store data locally in your browser (for example cached financial results, chat conversation history, and chat session helpers) to make the Service faster and to let you reopen past chats. This history lives on your device, not on our servers, and you can clear it from Profile settings, in-chat delete controls, or your browser settings.
  • Search queries: the ticker or company you look up is processed to retrieve the corresponding public filing data.

Data we publish

EDGAR filing-derived warehouse data (fundamentals, line items, and related public tables/views the dashboard reads) is intentionally available to the browser via our public Supabase anon key under row-level security. That data originates from public filings. Paid plans monetize Castle AI chat, MCP access, history depth, usage limits, and related UX, not a private lock on the public warehouse itself.

How we use information

We use this information to operate, authenticate, bill, secure, and improve the Service; to enforce personal-use and plan limits; to prevent abuse; to provide Castle AI and MCP features you request; to understand how the Service is used (including via Google Analytics); and to measure whether our ads lead to sign-ups or paid subscriptions (including enhanced conversion matching as described above). With your consent, we may review and use your Castle AI chats to improve our AI models. We do not sell your personal information.

International transfers

We and our subprocessors may process personal information in the United States and other jurisdictions. Where required by applicable law (for example the EU/UK GDPR), we rely on appropriate transfer mechanisms offered by our providers (such as Standard Contractual Clauses) or other lawful bases. By using the Service, you understand that your information may be transferred to and processed in countries other than your own.

Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, or export personal information we hold about you, or to object to or restrict certain processing. To make a request, email support@castlingfinancial.com. We may need to verify your identity before responding. You can also clear local browser storage yourself, and stop using optional features (Castle AI, MCP, paid tiers) at any time.

If you have an account, you may request deletion of account-linked personal data subject to records we must keep for billing, security, fraud prevention, or legal compliance. You can update payment methods and cancel renewal through the Stripe Customer Portal ("Manage billing" in Settings) without deleting your account.

Data retention

We keep personal information only as long as needed for the purposes described in this policy, including to provide the Service, meet legal obligations, resolve disputes, and enforce our agreements. Chat history tokens are short-lived (~24 hours). Usage metering and billing records (including webhook event logs used to apply subscription changes) are retained for the periods needed to operate subscriptions, reconcile Stripe events, and comply with law. Aggregated or de-identified analytics may be kept longer.

Subprocessors

We rely on subprocessors to deliver the Service. They process data on our behalf as needed to provide their services:

  • Supabase: authentication, database, and related backend services;
  • Stripe: payment processing, Checkout, Customer Portal, subscription billing, and tax calculation where applicable;
  • OpenRouter: model inference for Castle AI (and related worker tooling);
  • Cloudflare: hosting, CDN, Workers, security, cookieless analytics, and Zaraz consent / tag management;
  • Google: Google Analytics and Google Ads conversion measurement;
  • Reddit and X: advertising measurement pixels when loaded through Cloudflare Zaraz for campaigns on those platforms;
  • Public data sources such as SEC EDGAR, from which filings originate.

These providers have their own privacy practices. We are not affiliated with or endorsed by the SEC.

Cookies and similar technologies

We use local browser storage so the Service can function and perform well, as described above. Auth sessions may rely on tokens managed by our auth provider.

Cloudflare may inject a small JavaScript snippet to collect aggregated analytics and performance data. That Cloudflare measurement is designed to be cookieless and is not used to profile you across other websites.

We use Cloudflare Zaraz as our consent management platform and (where configured) to load analytics and advertising measurement tools, including Google Analytics and optional ad-platform pixels. Google Ads conversion tags may also load directly on the Service. Those technologies may use cookies or similar identifiers for analytics and ad measurement. We use Google Consent Mode so analytics and advertising cookies load according to your choice (and applicable regional rules). You can change your cookie preferences anytime via Cookie settings in the site footer. When Google Ads enhanced conversions are used, your email may be normalized and hashed in the browser (SHA-256) before being sent to Google for match improvement — we do not send your raw email to Google Ads for this purpose. See Google's advertising technologies and Google's Privacy Policy for details on how Google processes analytics and ads data.

Children's privacy

The Service is not directed to children under 13 (or under 16 where a higher age of digital consent applies), and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.

Changes to this policy

We may update this Privacy Policy from time to time. Changes are effective when posted, and the "Last updated" date above will reflect the latest revision.

Contact

Questions about this Privacy Policy can be sent to support@castlingfinancial.com. The Service is operated by Castling Holdings LLC.