1. Introduction and controller
This Privacy Policy ("Policy") describes how Black Pearls Operator ("Operator," "we," "us," or "our") collects, uses, discloses, retains, and protects information when you access or use the Black Pearls service ("Service").
For purposes of applicable data protection laws, the Operator acts as the controller (or equivalent) for processing described here, unless a separate statement designates a different entity for a specific region.
This Policy should be read together with the Terms of Service. Capitalized terms not defined here have the meanings given in the Terms.
We do not sell your personal information for money. We process information to operate an analysis-only discipline tool, not to trade on your behalf.
2. Scope, global availability, and prohibited jurisdictions
The Service is intended for Subscribers worldwide except where use is prohibited by sanctions, export control, or local law. We do not knowingly offer the Service to individuals in comprehensively embargoed or sanctioned jurisdictions described in our Terms (Schedule A).
If you access the Service from a permitted jurisdiction, you are responsible for ensuring that your use complies with local privacy, financial conduct, and telecommunications rules.
We may block access based on geolocation, payment origin, or identity signals without detailing detection methods.
3. Categories of information we process
Account and identity data. When you authenticate (e.g., via Clerk), we receive identifiers such as user id, email address, and authentication metadata necessary to maintain your workspace.
Workspace and subscription data. Plan tier, billing correlation ids, legal acknowledgment timestamps, feature entitlements, and configuration you save in settings.
Discipline and analytical data. Records you create (such as declined-trade notes and pre-mortem journal entries), watchlists, hypothetical position lists, preferences, alert settings, exports you request, and periodically refreshed analytical outputs stored in your account.
Technical and security data. Session tokens, rate-limit counters, audit logs, background job authentication tokens, error reports, and similar operational logs required to secure and operate the Service.
Optional product usage milestones. When we enable coarse usage summaries, the Service may log pseudonymous milestone events (such as visiting a page, completing sign-up, or first use of key features) with page and feature context—but not your email, user id, payment identifiers, secrets, or free-text content. Your browser may store a short-lived deduplication key in session storage to avoid double-counting.
Payment data. Stripe processes payment instruments; we receive subscription status and customer references, not full card numbers stored by us.
Optional AI interactions. When enabled, prompts and structured context necessary to produce assistive text may be transmitted to model providers. Screenshot import (beta) processes images transiently and does not retain them after extraction.
Integrations you configure. Webhook URLs, Notion tokens you supply, and delivery logs for outbound notifications you elect to receive.
4. Sources of information
We collect information directly from you, from authentication and payment providers you choose to use, from scheduled data refresh jobs you authorize, and from your device or browser when you interact with the Service.
We do not obtain brokerage account balances or execute trades; market or portfolio information in the Service comes from data you upload, demonstration datasets, or structured inputs you provide.
5. Purposes of processing
We process information to: provide and maintain the Service; authenticate users and enforce entitlements; process subscriptions; display analytical surfaces and discipline tooling; dispatch alerts and digests you configure; comply with law; detect abuse; improve reliability and security; communicate operational notices; and, when optional usage milestones are enabled by configuration, measure coarse activation metrics without identifying you in those logs.
We do not process information to provide personalized investment advice, manage assets, or execute transactions on your behalf.
Where optional AI features are enabled, processing includes generating narrative assistance grounded in structured artifacts—subject to quotas and logging described in product documentation.
6. Legal bases (EEA/UK and similar regimes)
Where the GDPR, UK GDPR, or comparable laws apply, we rely on: contract (providing the Service you request); legitimate interests (security, fraud prevention, product improvement balanced against your rights); consent (where required for optional features or marketing); and legal obligation (tax, sanctions screening, regulatory requests).
You may withdraw consent for optional processing where consent is the basis, without affecting lawfulness of prior processing.
8. International transfers
Information may be processed in countries other than your own, including Canada and the United States, where providers or infrastructure are located.
Where required, we implement appropriate safeguards (such as standard contractual clauses or equivalent mechanisms) for cross-border transfers. Contact us for information about safeguards applicable to your region.
9. Retention
We retain information for as long as your workspace is active and as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements.
Backup copies may persist for a limited period after deletion. Aggregated or de-identified data may be retained without identifying you.
Account deletion features, where available, initiate erasure workflows described in product documentation; some records may be retained where law requires.
10. Security
We implement administrative, technical, and organizational measures appropriate to the nature of the Service, including access controls, account isolation, signed session mechanisms, and authentication for background data refresh jobs.
No method of transmission or storage is completely secure. You are responsible for securing devices, export files, webhook secrets, and integration tokens you control.
11. Your rights
Depending on your location, you may have rights to access, rectify, erase, restrict, object, port, or withdraw consent regarding personal information, and to lodge a complaint with a supervisory authority.
To exercise rights, contact us at the email below. We may verify identity before responding. We will respond within timeframes required by applicable law.
California residents have additional rights described in the California Privacy Notice at `/legal/california`. We do not sell or share personal information for cross-context behavioral advertising.
Canadian residents (PIPEDA). If you are in Canada, you have rights to access and challenge the accuracy of personal information we hold about you, and to complain to the Office of the Privacy Commissioner of Canada. We process personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws, in addition to the rights described above.
12. Children
The Service is not directed to individuals under the age of majority. We do not knowingly collect personal information from children. If you believe we have done so, contact us for deletion.
13. Automated processing and profiling
The Service may compute scores, thresholds, and alerts from data you upload or connect. These are analytical transforms for discipline and education, not automated decisions producing legal or similarly significant effects about you within the meaning of Article 22 GDPR unless you independently ascribe such significance.
Optional model-generated text is assistive and non-determinative. You should not treat it as authoritative.
15. Account deletion and export
Where available in Settings, you may export workspace data and request account deletion. Deletion cancels active Stripe subscriptions tied to your account where configured.
Erasure removes cloud workspace artifacts, configuration, and associated personal data subject to backup cycles (typically up to thirty days), fraud holds, and legal retention.
Exports you download remain your responsibility to secure and delete on your devices.
16. Webhooks and third-party destinations
When you configure outbound webhooks or Notion sync, we transmit event summaries you trigger to URLs or APIs you supply. We do not control how recipients process that data.
You must provide lawful bases and notices to any third party who receives personal data via your integrations.
17. Changes to this Policy
We may update this Policy to reflect operational, legal, or regulatory changes. The effective date at the top indicates the latest revision. Material changes will be communicated through the Service or account email where practicable.
Continued use after an update constitutes acknowledgment of the revised Policy.
18. Contact
Privacy and legal inquiries may be directed to navophoto@protonmail.com. We will endeavor to respond within reasonable timeframes.