thesis*back to the app →

Privacy Policy

Last updated August 16, 2026 · Beta

Thesis is built on a simple privacy premise: we can only mishandle data we don't collect, so we collect very little. No data sales, and — importantly for a finance app — no financial data at all: we never know what you own, what you're worth, or what you trade.

1. What we collect

An account, a watchlist, and a short list of in-app research actions. That's the whole list.

  • Account: handle, display name, and a password we store only as a salted bcrypt hash.
  • Email (optional): you can add an address so a forgotten password can be reset. You can confirm it, change it, or remove it at any time from your account page. Without one, a lost password can't be recovered.
  • Watchlist: the symbols you choose to follow.
  • Research activity: timestamped events from a fixed list — opening the app, viewing an asset, running a search (we log that you searched, not what you typed), reading the brief, viewing your recap, adding to your watchlist.
  • Friend graph: which accounts you're connected to, and your invite code.
  • Shared research profile (off by default): you can generate a link that shows your own research — statistics first, and the full list of what you've read to anyone who signs up through it. It doesn't exist until you create it, isn't discoverable from your handle, exposes only you and never a friend, never includes your notes, and stops working the moment you revoke it.
  • Packs and notes: the lists and private notes you create. Notes are always private to you. A pack is private by default; if you set one to friends or public, its name, description, assets and your display name become visible to that audience until you change it back or delete it. Public and friends-only packs can be reported by other users, and a pack with enough distinct reports is automatically hidden from public lists pending review.
  • Session cookie: one httpOnly cookie that keeps you signed in.
  • Visit records: a random per-browser identifier, the page step, and where the visit came from (referrer and any campaign tag on the link), so we can tell how many people who arrive go on to make an account. It isn't linked to your account and isn't used to build a profile of you.

We do not collect: holdings, balances, transactions, brokerage links, contacts, location, device fingerprints, or browsing outside the app.

2. Email we send

Password resets and address confirmations always. One weekly recap, only if you leave it on.

  • Password reset and email confirmation: sent only when you ask for them.
  • Weekly recap: at most one email a week — what moved on your watchlist and a summary of your own reading. It only goes to confirmed addresses, you can switch it off in your account page or from the link at the bottom of any recap, and switching it off is immediate.

There is no other marketing email, no drip sequence, and no sharing of your address with anyone for their own use. Mail is delivered by Resend, which processes your address solely to deliver our messages.

3. How your activity is used

To run your own features, and — only if you opt in — to power aggregate stats about your friends that can't be traced back to you.

  • For you: your streak, weekly recap, and personal stats are computed from your own events.
  • For your friends (opt-in): if you enable sharing, your events feed aggregate insights like “3 of your friends read up on NVDA.” Aggregates only appear when at least 3 of your friends are sharing, and any count shown covers at least 2 people — so a specific stat can't be pinned on a specific person. We never show individuals' viewing history, and there is no way to see “what did @sam look at.”
  • Sample group: before enough of your friends have joined and opted in, the app shows a synthetic “sample group” clearly labeled as sample everywhere it appears. It is generated data about fictional people, never presented as anyone you know — no real person's activity is ever behind a sample badge, and no sample row is ever described as a friend of yours.

You choose sharing on or off at signup, and can change it anytime in settings. Turning it off takes effect immediately.

4. Advertising measurement

When we run ads, a Meta pixel loads on public pages so we can tell whether the ads work.

Thesis carries no advertising — nothing in the app is paid placement, and no advertiser influences what you see. But we do sometimes buy ads to reach new people, and when a campaign is running the Meta (Facebook) pixel is loaded so we can count how many people who clicked an ad went on to create an account. It reports page views and account creation to Meta, which may associate them with a Meta account. It is never given your handle, your watchlist, your notes, or anything you've read.

Browser-level ad and tracker blockers stop it, and we don't work around them. If no campaign is running the pixel isn't loaded at all.

5. What leaves our servers

Market-data requests go to data providers without your identity. Nothing about you is sold.

To show quotes and headlines, our server calls market-data sources (Finnhub, Yahoo Finance endpoints, CoinGecko, alternative.me, public news feeds). Those requests carry the symbol being looked up, not your identity. Our other processors are our hosting provider (Vercel), our database provider (Neon) and our email provider (Resend). We don't sell, rent, or trade personal data with anyone. We would disclose data only if legally compelled, and there's very little to disclose.

6. Your data, retention and deletion

Download everything from settings. Delete your account there too, and it goes immediately.

Download my data in your account settings produces a single JSON file with your account details, watchlist, notes, lists, packs, friend list and reading history. It's worth doing before you delete anything.

Your data is kept while your account exists. Deleting your account erases your profile, watchlist, events, notes, packs, invites, and friend links from the production database immediately (cascade delete, no soft-delete limbo). Aggregates already shown to friends aren't retroactively recomputed, but they never contained your identity in the first place. Routine encrypted backups, where used by our hosting provider, expire on the provider's schedule.

7. Security

Passwords are bcrypt-hashed, sessions are random 256-bit tokens in httpOnly cookies, password-reset and email-confirmation links are single-use and stored only as hashes, and the app runs over HTTPS in production. It's a beta run by a small team, not a bank — which is one more reason we deliberately hold no financial data worth stealing.

8. Age

Thesis is for adults 18+. We don't knowingly collect data from anyone under 18; if that happens, tell us and we'll delete the account.

9. Changes & contact

If this policy changes materially, we'll say so in the app before the change applies. Questions or data requests: the contact option on the About page.