Legal

Privacy Policy

What data AI Panic processes, why, and which rights you have.

Last updated:

Scope and controller

This policy applies to the AI Panic website and applications and to the data processed when you use them — as a guest or with an account.

The responsible controller (legal entity name and postal address) is maintained in the central legal configuration and will be stated here before publication. This page is a development draft until then.

Data we receive

  • Identity and account data. When you create an account or sign in, our authentication provider Clerk supplies the necessary authentication and session technology and provides us with the identity data needed to run your account (such as your email address, name and avatar, depending on the sign-in method).
  • Profile and usage data. Your internal profile IDs, comments you post, Saved Articles, watchlist entries and price alerts, and your feed preferences (preferred, hidden and muted categories and sources, and custom feed subscriptions).
  • Correspondence data. If you contact us — now or via future support and submission channels — we process the content of your message and the contact details you provide.
  • Technical and security logs. Server-side logs (for example request and error logs) used to operate, secure and debug the service.

We do not run analytics tracking or advertising trackers, and we do not operate a newsletter; no data is processed for those purposes.

Payments

Paid AI Panic Plus subscriptions are processed by Stripe. Checkout and payment data are entered into and processed by Stripe under Stripe's own privacy notices; AI Panic does not see or store your full payment card number. We receive from Stripe what is needed to run your subscription (for example payment status, plan and renewal events).

How we use data

  • Operating your account, sign-in and session.
  • Storing and displaying your comments, saved articles, watchlists and alerts.
  • Personalizing your feed according to the preferences you set.
  • Processing and managing Plus subscriptions via Stripe.
  • Handling requests and submissions you send us.
  • Keeping the service secure, preventing abuse, and debugging errors.

Legal bases (GDPR)

Where the GDPR applies, we process personal data on these bases:

  • Contract (Art. 6(1)(b)) — providing your account, saved content, personalization and paid subscriptions.
  • Legitimate interests (Art. 6(1)(f)) — operating, securing and improving the service, including technical logs and abuse prevention.
  • Legal obligation (Art. 6(1)(c)) — where retention or disclosure is required by law.
  • Consent (Art. 6(1)(a)) — only where a processing purpose requires it; consent can be withdrawn at any time with effect for the future.

Processors and service providers

  • Clerk — authentication and session technology for accounts.
  • Stripe — checkout, billing and subscription management for Plus.
  • Marketstack — receives server-side market data requests from our backend to display stock information; it never receives payment card data from us.
  • Hosting and infrastructure providers — operate the servers and databases the service runs on.

International transfers

Some processors may process data outside the EU/EEA. Where that happens, it takes place under the safeguards the GDPR requires for such transfers (for example adequacy decisions or standard contractual clauses).

Retention

We retain data by category and only as long as the purpose requires: account and profile data for the life of your account; content you create (comments, saved articles, watchlists, alerts, preferences) until you delete it or delete your account; billing records as required by tax and commercial law; technical and security logs for limited periods appropriate to their security purpose. We do not state fixed periods here because they are maintained operationally and may differ by category.

Security

We apply appropriate technical and organizational measures to protect personal data, including authenticated access, transport encryption and access controls. No internet service can guarantee absolute security.

Your choices and rights

Where the GDPR applies, you have the right of access, rectification, erasure, restriction of processing, data portability, and the right to object to processing based on legitimate interests. Where processing is based on consent, you can withdraw it at any time with effect for the future. You also have the right to lodge a complaint with a supervisory authority. To exercise your rights, use the privacy contact stated in the controller section above.

Account deletion

You may request deletion of your account at any time via the privacy contact. Deletion removes your account and profile data; content you published (such as comments) is removed or anonymized, and billing records are retained only where the law requires it.

Children

AI Panic is not directed at children under 16, and we do not knowingly process their data. If you believe a child has provided us data, contact us so we can remove it.

Changes to this policy

We update this policy when the service or its processing changes. The current version and its update date are always shown at the top of this page.