Privacy Policy
Last Updated: February 23, 2026
1. Introduction
Thank you for using Toponelogic. Toponelogic is an AI-powered investment analysis platform that provides multi-agent analysis for stocks and cryptocurrencies, together with related websites, applications, and services (collectively, the “Services”), operated by Toponelogic Inc. (“Toponelogic,” “we,” “us,” or “our”).
This Privacy Policy (“Policy”) sets out how your information is collected and otherwise processed when you access or use the Services, including any other services that link to or reference this Policy. We use “information,” “personal information,” and “personal data” to refer to information relating to an identified or identifiable natural person.
This Policy should be read together with our Terms of Service and Financial Disclaimer. Please read it carefully. If you do not agree with this Policy, please do not use the Services.
2. How This Policy Applies
Toponelogic provides the Services directly to individual users. We act as the controller of the personal information described in the “Information We Collect and Use” section and are responsible for processing it as set out in this Policy.
The Services may integrate with or link to third-party services (such as sign-in, payment, market-data, and AI model providers). This Policy does not cover the processing of your information by those third parties through your use of any third-party integration. When using integrated apps and services, please review the relevant third party’s own terms and privacy policy.
3. Information We Collect and Use
We may collect and use the following types of information when you access or use the Services:
Account Data. To create an account, you provide your email address and display name, and you set a password (stored only as a salted hash). If you register or sign in through Google, Facebook, or Apple, we receive the basic profile information you authorize, such as your name, email address, and profile picture. We never receive the password for those accounts.
Payment Information. If you subscribe to a paid plan, our payment processor (Stripe) collects and processes your payment details directly. We receive only limited billing metadata, such as your plan, transaction status, card brand, and the last four digits. We never receive or store full payment card numbers.
API Keys. Any third-party API keys you choose to add in your settings. These are encrypted at rest and used only to make requests to those services on your behalf.
User Content. Content you generate on the Services, including posts, predictions, comments, watchlists, notes, and other content you upload, create, or share in community and workspace features.
Technical and Usage Data. We automatically collect data to administer, provide, secure, and improve the Services, including: usage and inference data (analysis requests, the features and content you interact with, pages viewed, and interaction patterns); technical and network data (IP address, browser type and settings, date and time stamps, referring URLs, and language preferences); device data (device type, operating system and version, and screen resolution); and data collected through cookies and your browser’s local storage to operate the Services and remember your preferences (see the “Your Rights and Choices” section).
Communication Data. Information you provide when you communicate with us — for example, when you contact support, send feedback, or respond to a survey.
Location Data. We may derive your approximate location (such as city, region, or country) from your IP address, for security and to operate the Services. We do not collect precise GPS location.
Third-Party Data. If you use a third-party integration, we may receive and process data from that third party (and share certain data with it) in order to provide the integrated feature.
Because Toponelogic is an analysis tool and not a broker-dealer or financial institution, we do not perform identity verification (KYC), and we do not collect government identification numbers, brokerage account details, or biometric data.
4. How We Use Information
In addition to the purposes already set out above, we may use, process, or disclose your information for the following purposes, including to:
- Administer, operate, and provide the Services (including diagnostics, monitoring, troubleshooting, data analysis, testing, system maintenance, support, and hosting of data);
- Process your AI analysis requests and deliver the resulting reports;
- Provide user support and respond to your queries, requests, complaints, and feedback;
- Investigate and help prevent security issues and abuse, and improve the security of the Services, including using automated systems to detect spam, malware, fraud, and other illegal or abusive activity;
- Better understand your interests and needs, and personalize your experience;
- Analyze and research how you interact with the Services, and continually improve them, including adding new features or capabilities;
- Provide and improve features that use artificial intelligence, machine learning, or similar technologies;
- Manage your account, subscription, and billing;
- Comply with applicable laws, regulations, and legal process, and assist law enforcement and regulatory authorities as required by law;
- Communicate with you, including service messages about changes to the Services;
- Send marketing and promotional materials, and measure the effectiveness of our marketing;
- Enforce our terms, conditions, and policies; and
- Fulfill any other purposes for which you provided the data, or that are related to the above.
Artificial Intelligence
When you submit an analysis request, we send the relevant inputs — such as ticker symbols and publicly available market data — to AI model providers to generate analysis. We do not send your account identity or other personal identifiers to those providers, and AI-generated outputs are informational only and are not decisions made about you. See our Financial Disclaimer for the limits of AI-generated content.
Combined Information
Unless otherwise prohibited by law, we may combine the information we collect through your use of the Services with information we receive from other sources, both online and offline, and use that combined information as set out above.
Aggregated and De-identified Information
We may aggregate or de-identify information collected through the Services so that it can no longer be linked to you or your device. Subject to applicable law, we may use and share such information for any purpose.
5. Legal Bases for Processing
If you are an individual in the European Economic Area (EEA), the United Kingdom, Switzerland, or any other country that requires a legal basis for processing, our basis for collecting and using your information depends on the information concerned and the context in which we collect it. The legal bases we rely on include:
- Consent — where you have given us consent to process your information for a specific purpose;
- Contract — where processing is necessary to perform our contract with you, such as to provide the Services and manage your account and subscription;
- Legitimate interests — where processing is necessary for our legitimate interests or those of others (for example, to operate, secure, analyze, and improve the Services and prevent fraud), provided those interests are not overridden by your rights; and
- Legal obligation — where processing is necessary to comply with applicable law or respond to lawful requests.
6. How We Share Your Information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We may share your information with the following categories of recipients, including those who process it on our behalf for the purposes described in this Policy:
Service Providers and Business Partners
We may disclose your information to service providers who support our business, such as cloud hosting and infrastructure providers, our payment processor (Stripe), AI model providers, market-data providers, and analytics and security vendors. These providers help us provide, administer, and support the Services and are permitted to process your information only on our behalf.
Third-Party Integrations
We may share certain data with third-party integration providers if you give them access to your account, or by providing your own API keys, including any content you choose to use in connection with those integrations.
Our Corporate Group
We may share your information with our subsidiaries and affiliates in order to provide, maintain, and improve the Services.
Corporate Transactions
We may share or transfer your information in connection with, or during negotiations of, a merger, acquisition, reorganization, financing, asset sale, or similar transaction, or in the event of insolvency.
Law Enforcement and Legal
We may disclose your information where we believe it is necessary or appropriate to comply with applicable law and legal process; respond to requests from public and government authorities; enforce our terms; or protect the rights, privacy, safety, or property of Toponelogic, our users, or others.
With Your Consent
We may share your information for other purposes with your consent or at your direction.
7. International Data Transfers
We are based in the United States and process information there and in other countries where our service providers operate. Data-protection laws vary among countries, and some provide more protection than others. Regardless of where your information is processed, we apply the protections described in this Policy.
Where we transfer personal data from the EEA, the United Kingdom, or Switzerland to a country that has not been recognized as providing an adequate level of protection, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, to protect that data.
8. Security of Your Information
We attach great importance to the security of your information and maintain technical, administrative, and physical safeguards designed to protect it — including TLS/SSL encryption in transit, encryption at rest for sensitive data such as API keys, salted password hashing, support for two-factor authentication (2FA), role-based access controls, and limiting access to personal data on a need-to-know basis.
However, no method of transmission or storage over the internet is completely secure, and we cannot guarantee absolute security. We encourage you to use a strong, unique password, enable two-factor authentication, and avoid sharing your account credentials.
9. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Services. When you delete your account, we delete or de-identify your personal data within a reasonable period (generally within 30 days), except where we are required or permitted to retain it — for example, to comply with legal obligations, resolve disputes, prevent fraud, or establish, exercise, or defend legal claims. Aggregated or de-identified data may be retained indefinitely.
10. Children and Minors
The Services are intended for adults (persons who meet the legal age of consent in their jurisdiction, and in any case at least 18 years old) and are not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal information, please contact us and we will take commercially reasonable steps to delete it.
11. Your Rights and Choices
Email Marketing
If you do not wish to receive marketing emails from us, you can follow the unsubscribe instructions in those emails or contact us. We will still send you non-promotional, service emails about your account, billing, security, and your use of the Services.
Cookies and Similar Technologies
We use a minimal set of strictly necessary technologies — primarily your browser’s local storage — to keep you signed in and remember preferences such as theme and language. We do not use third-party advertising or cross-site tracking cookies. You can sign out or clear your browser storage at any time, and we honor “Do Not Track” (DNT) and Global Privacy Control (GPC) signals where applicable.
Requests Regarding Your Information
Depending on the laws of your jurisdiction, you may have the right to:
- Access, or obtain a copy of, the information we hold about you — in some cases in a structured, machine-readable format;
- Correct or update inaccurate or incomplete information;
- Delete your information;
- Object to or restrict certain processing, or withdraw consent you previously provided (without affecting the lawfulness of prior processing);
- Object to the sale or sharing of your information (note: we do not sell or share your information for advertising); and
- Request a review of decisions made solely by automated processing that significantly affect you.
To exercise your rights, contact us at privacy@toponelogic.com with your name, account email, and a description of your request. To protect you, we may need to verify your identity before acting, and we will respond within the timeframe required by applicable law. In some cases we may be unable to fully comply with a request — for example, where the law requires us to retain information — and we will explain why. If you have a complaint, please contact us first; you may also have the right to complain to your local data-protection authority.
12. Contact Us
If you have any questions about this Policy or wish to exercise your rights, please contact us:
Toponelogic Inc. — Privacy Team
Email: privacy@toponelogic.com
General Support: support@toponelogic.com
13. Changes to This Policy
We may update this Policy from time to time to reflect changes to applicable laws or to the Services. When we do, we will revise the “Last Updated” date at the top and, where required by law, provide additional notice. Your continued use of the Services after the updated Policy takes effect constitutes your acceptance of it.
14. Prevailing Language
This Policy is prepared in English and may be translated into other languages for your convenience. If there is any inconsistency between the English version and a translation, the English version prevails to the maximum extent permitted by applicable law.
15. Additional Information for Certain Jurisdictions
If you access the Services from one of the jurisdictions below, the following supplemental terms apply in addition to this Policy. In the event of a conflict, the jurisdiction-specific terms control for residents of that jurisdiction.
European Economic Area, United Kingdom, and Switzerland
In addition to the rights described in the “Your Rights and Choices” section, you have the right to access, correct, delete, restrict, or object to our processing of your personal data; the right to data portability; and the right to withdraw consent at any time. Where we rely on legitimate interests, you may object to that processing, and we will stop unless we have an overriding legitimate ground. You also have the right to lodge a complaint with your local data-protection supervisory authority.
California
The California Consumer Privacy Act (CCPA/CPRA) gives California residents the right to know the categories and specific pieces of personal information we collect, the sources and purposes, and the categories of recipients; the right to delete and to correct their information; and the right to opt out of the “sale” or “sharing” of personal information. We do not sell or share personal information for cross-context behavioral advertising, and we do not use sensitive personal information for purposes that would trigger the right to limit. We will not discriminate against you for exercising your rights. To exercise these rights, contact us at privacy@toponelogic.com; we aim to respond within 45 days.