This beta Privacy Policy explains what TickrScope expects to collect, why the data is needed, which controls users should have, and which details still need operator, legal, and processor confirmation before paid public launch.
Reviewed June 2026. Reviewed 12 June 2026. Beta privacy status: Data controller details pending. Privacy contact, ICO registration status, processor names, transfer safeguards, DPIA, ROPA, and retention periods remain pre-launch blockers.
This policy covers people who visit the TickrScope website, join the beta, use the Telegram bot, create an account, receive research outputs, submit support messages, use billing flows, or ask TickrScope to handle a privacy request. Before paid public launch, TickrScope needs the final operator or company name, direct privacy contact, postal contact where required, ICO fee or registration position, and final complaint route.
TickrScope may process account details, workspace membership, Telegram identifiers, usernames, names, email addresses, watchlists, saved notes, research prompts, generated research cards, alert settings, onboarding answers, experience level, interests, optional portfolio context, support tickets, bug reports, bad-output reports, billing references, cookie preferences, device or browser data, IP addresses, audit events, and technical security logs. TickrScope should collect only what is needed for the service purpose and should not ask for broker credentials, private keys, seed phrases, full card numbers, or CVV details.
Telegram chat IDs, usernames, names, commands, and message text can pass through Telegram before reaching TickrScope. Telegram is a platform dependency and a data-protection weak point. Do not send broker credentials, private keys, full payment details, private financial documents, or other secrets through Telegram. Before wider launch, TickrScope needs a processor or controller assessment for Telegram, a transfer assessment where required, and a channel-migration plan if Telegram becomes unsuitable.
Onboarding and watchlist data helps TickrScope remember the markets, companies, alert preferences, and research style you ask it to follow. It should be used to organise evidence and reduce repeated setup steps, not to infer suitability or make personal trade recommendations.
Billing and support data may include Stripe customer references, plan status, invoice events, support messages, bug reports, report-command context, service emails, and audit records. TickrScope should use this data only to operate access, resolve issues, keep required records, and handle privacy or billing requests.
Data may be used to create and secure accounts, deliver research features, organise watchlists, remember alert preferences, generate and store research cards, send service messages, process beta access, operate support, investigate reports, prevent abuse, enforce usage limits, keep audit records, manage billing references, respond to legal requests, fulfil data-rights requests, and improve reliability. Onboarding, watchlist, and optional portfolio context may simplify the interface and organise research, but must not be used to decide what you should buy, sell, hold, size, or trade.
If you provide portfolio context, it is used to organise research, show concentration, track watchlist relevance, and surface evidence gaps. It must not be used to tell you what to buy, sell, hold, size, or trade, and you should be able to remove it through the data-rights workflow.
The likely lawful bases are contract for core service delivery, legal obligation for records required by law, legitimate interests for security, abuse prevention, service improvement, and dispute handling, and consent for optional analytics or marketing where required. The final lawful-basis map still needs privacy review and must be reflected in the DPIA, ROPA, processor list, retention schedule, and user-facing notice.
Hosting, database, Telegram, Stripe, email, support, monitoring, analytics, security, and model providers may process limited data needed to operate the beta. Stripe may handle payment method data and subscription events; TickrScope should not store full card numbers or CVV details. Final provider names, processor roles, contracts, subprocessors, locations, data processing agreements, and international-transfer safeguards must be confirmed before public launch.
AI can help summarise public sources, compare evidence, draft research cards, and flag missing context. AI outputs may be inaccurate or incomplete and should remain challengeable. TickrScope must not make solely automated decisions with legal or similarly significant effects, and it must not use AI to decide suitability, trade timing, position size, or personal recommendations. Broader AI use needs source trails, human challenge routes, privacy review, and DPIA coverage.
Necessary cookies and similar storage may be used to run the website, remember preferences, support access controls, and secure the beta. Optional analytics should remain off unless accepted. Cookie choices, storage names, provider scripts, and retention periods are covered in the Cookie Policy.
Data should be retained only as long as needed for service delivery, security, support, legal, accounting, billing, audit, and dispute purposes. Account, billing, research, support, Telegram, security log, consent, and backup retention periods must be defined by purpose, minimised, and matched to deletion and export fulfilment before paid public launch.
Users should be able to request access, correction, export, deletion, restriction, objection, portability, and withdrawal of optional consent where applicable. Telegram routes include /privacy, /export, /delete, and /stop. Some security, billing, tax, audit, and legal records may need to be retained even after account deletion, but unnecessary personal data should be removed or minimised where possible.
Expected controls include TLS, password hashing, tenant isolation, least-privilege admin access, audit logs, backup hygiene, secret scanning, rate limits, webhook verification, and a breach response plan that can assess ICO notification within 72 hours where required. No online service is risk-free, so security reports should be treated as urgent beta support issues.
TickrScope is intended for adults aged 18 or over. It is not designed for children. The service is not intended to collect special-category data, broker credentials, private keys, full card data, government identity documents, or private financial documents unless a future legally reviewed workflow specifically requires it.
Some providers may process data outside the UK or EEA. Before paid public launch, TickrScope must confirm the provider locations, transfer mechanisms, data processing agreements, subprocessors, and any transfer risk assessments required for Telegram, model providers, hosting, email, analytics, support, and billing services.
Read the related beta controls: Cookie Policy, Terms, Risk, Acceptable use, and Accessibility. Pre-launch privacy blockers remain: final legal entity details, privacy contact, ICO registration or fee position, processor list, DPAs, international-transfer position, DPIA, ROPA, retention schedule, breach response plan, SAR/export/delete identity workflow, and privacy notice acknowledgement.