AstraEye Labs - Privacy Policy
Effective date: August 28, 2026
1. Who We Are
AstraEye Labs ("AstraEye", "we", "us") operates an AI-powered research and analytics platform for crypto assets and U.S. equities. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices and rights you have. It should be read together with our Terms of Service.
AstraEye Labs is not a broker-dealer, investment adviser, commodity trading advisor, exchange, custodian, bank, tax adviser, legal adviser, or money transmitter. AstraEye Labs does not manage money, custody assets, route orders, execute trades for public users, or hold your funds or assets.
2. Information We Collect
We collect the following categories of personal information, from you directly, from your use of the service, and (only when you connect them) from your linked accounts:
- Account and authentication data. Email address, telephone number, country associated with the telephone number, password hash, multi-factor authentication settings, passkey and trusted-device records, session information, and security-verification status used to create, protect, and recover your account. We do not store your password in readable form.
- Billing data. Subscription tier, plan and usage state, and payment identifiers. Card payments are processed by our payment provider (Stripe); full card numbers are entered directly with the processor and do not transit our servers.
- Portfolio and account data. Holdings, balances, symbols, quantities, cost basis, and account labels that you enter manually, import by file, or bring in through an account connection you authorize. This is sensitive information (see Section 10).
- Research and usage data. Research projects, selected templates, analysis types, AI-generated findings, informational research artifacts ("beacons," where enabled), feedback, SAGE questions and answers, and usage/metering data.
- Support data. Messages you send to support and our responses.
- Communications data. Notification preferences and records relating to transactional email and security-code text messages, including SMS consent date, consent version and source, delivery/provider identifiers, verification challenges, and opt-out or support requests.
- Spoken-audio data. If you request a spoken SAGE reply, we send the already-generated reply text to our speech provider and store the resulting audio file and related metadata (such as voice profile, text hash, duration, and generation cost). AstraEye does not collect a recording of your voice for this feature and does not use spoken replies to identify you.
- Technical and security data. IP address, browser or user-agent information, request and route metadata, cookie and session identifiers, logs, audit and security events, error reports, and diagnostic information used to operate, secure, and troubleshoot the platform. Error reports may include account or request context associated with the error.
We do not intentionally collect government IDs, Social Security numbers, or full payment card numbers.
3. How We Use Information
We use information to:
- Provide, operate, and secure the platform and your account.
- Generate AI-assisted research, analytics, dashboards, and SAGE answers.
- Process subscriptions, credits, usage limits, and billing.
- Communicate with you (transactional email, security-code SMS, security alerts, service notifications, and support). We do not use your telephone number for marketing.
- Monitor, debug, prevent abuse, and improve the service.
- Comply with legal obligations.
We use your information only for these purposes and compatible purposes. We do not sell your personal information, and we do not "share" it for cross-context behavioral (targeted) advertising as those terms are defined under applicable privacy law (see Section 11).
Mobile numbers and SMS opt-in/consent records are not sold or shared with third parties or affiliates for their marketing or independent messaging programs. We disclose them only to service providers acting for AstraEye as needed to deliver and secure the SMS messages you requested, or when required by law.
4. AI Processing
To generate research, summaries, or answers, bounded context may be sent to our AI model providers (currently Anthropic and OpenAI). Depending on the feature, this context may include asset symbols, market data, your portfolio positions and approximate values, prior research artifacts, research-observation statistics, and the questions you ask SAGE.
Under the providers' standard commercial API terms, inputs and outputs are not used to train their general models by default unless the customer affirmatively opts in. AstraEye does not opt in to provider training or use your personal or portfolio data to train or fine-tune AstraEye or third-party AI models. Under standard API retention, providers may retain inputs, outputs, and related abuse- monitoring data for up to 30 days, and in limited cases longer to enforce usage policies, investigate abuse, provide support, or comply with law. Different retention applies if AstraEye has obtained and enabled an eligible zero-data- retention arrangement.
We design prompts so they should not include passwords, password hashes, raw session tokens, API secret keys, withdrawal credentials, full payment card data, or sensitive administrative secrets. For spoken SAGE, OpenAI receives only the compliant reply text and speech-generation instructions; it does not receive a recording of your voice. See the Risk and AI Disclosure for more detail.
Some AI prompts may include licensed market or research information or compact context derived from it. Where a data license requires transient processing, we use the model provider under no-retention and no-training controls for that licensed data; if those controls are unavailable, the restricted data is excluded from the prompt. This provider-data restriction is separate from, and does not expand, the personal and portfolio context described above.
5. Market and Reference Data
We fetch market, reference, and on-chain data from third-party data providers and cache it in shared snapshots that power research. These providers receive only outbound reference queries (such as ticker symbols, CIK identifiers, asset identifiers, macroeconomic series IDs, and general on-chain queries) and no personal or portfolio data. The exception is a self-custody public identifier you choose to add: we send a public address, or public addresses locally derived from a supported Bitcoin account xpub, to the configured blockchain endpoint to retrieve public balances and asset information.
These market and reference data sources are not subprocessors for this data flow because we do not disclose personal or portfolio data to them. A current list of material data sources, contractual attributions, and general data-delay information is available in our Data Sources and Attributions notice. AstraEye Labs may cache licensed provider data and create derived research only within the applicable commercial license. Provider-data rights may end when a license expires or terminates, in which case affected provider data may be deleted or made unavailable even if other account information remains retained.
6. Account Connections (Brokerage, Exchange, and Data Linking)
You may connect accounts so AstraEye Labs can read your portfolio for research:
- Stock brokerages are connected through Plaid Inc., a read-only data-linking provider that returns holdings and related account data only. When you link a brokerage, Plaid collects and processes your information (including the credentials you enter in Plaid's interface) under Plaid's own end-user privacy policy - available at https://plaid.com/legal/#end-user-privacy-policy - and Plaid's End User Services Agreement. We receive from Plaid only the read-only holdings and account data needed for research; your brokerage login credentials are handled by Plaid and are not shared with or stored by AstraEye Labs.
- Crypto exchanges are connected using API keys you create on the exchange. We request read-only access, which is all that is required to sync your portfolio. We do not request or require withdrawal, transfer, or trade permissions.
Never provide AstraEye Labs with a self-custody wallet seed phrase, recovery phrase, mnemonic, or wallet private key; an exchange password; or any credential capable of authorizing trades, withdrawals, transfers, transaction signing, or asset movement. We may accept a supported exchange's read-only API authentication or signing credential when it cannot authorize those activities.
The public platform has no order-placement or execution capability. Where a venue exposes permission information, AstraEye rejects keys detected as able to trade, transfer, or withdraw. If a venue cannot prove every permission, the connection is treated as unverified rather than represented as proven read-only. AstraEye may reject or disable a connection if its credential permissions later change to include trade, write, withdrawal, transfer, transaction-signing, or asset-movement capability.
AstraEye never requests or uses withdrawal or transfer permissions and cannot move your funds or assets off your accounts. We do not custody your funds or assets. Any future transaction product would require separate technical, security, legal, and consent review and separate applicable terms.
Any API keys, credentials, or access tokens you provide are stored encrypted at rest, are never exposed to your browser or to AI prompts, and are used only to read your portfolio and to operate the features you explicitly enable. You can disconnect a linked account at any time in your settings.
If you add a supported Ethereum, Solana, or Bitcoin public address, or a supported read-only Bitcoin account xpub, we encrypt the full identifier at rest and retain a keyed hash for deduplication. For an account xpub, AstraEye locally derives a bounded range of public receive and change addresses. We send public addresses to the configured standard blockchain RPC or indexer endpoint to retrieve public blockchain balances and asset information. Public identifiers, derived addresses, and blockchain transactions are pseudonymous, not necessarily anonymous; associating an address with your account may link its public activity to you. Except for the request to the applicable blockchain endpoint, full wallet identifiers and derived addresses are excluded from AI prompts, analytics events, AstraEye application URLs, logs, error-monitoring payloads, and user communications by design. If you choose optional Ethereum or Solana address verification, we process the one-time challenge message and signature to verify control of the corresponding signing key. We do not retain the submitted signature after verification; we retain the resulting verification status and timestamp until the wallet connection is removed. Removing a wallet connection deletes its stored address and balance records, subject to any retention required by law.
We minimize linked-account data to what is reasonably necessary to provide the research features you request. We do not sell this data, share it with nonaffiliated third parties for their own independent purposes, or use it for advertising. The CFPB's compliance dates for its Personal Financial Data Rights rule, 12 C.F.R. Part 1033, are currently stayed and the rule is under reconsideration. We monitor that proceeding and will update our authorization, revocation, data-use, and retention practices when required by applicable law.
7. Service Providers / Sub-Processors
We share information with service providers that host and operate the platform, strictly to provide the service and under contracts that limit their use of the data. These may include, without limitation:
- Amazon Web Services (AWS) - cloud hosting, storage, databases, transactional email (SES), transactional security-code SMS (AWS End User Messaging SMS), logging, and related cloud infrastructure.
- Stripe - payment processing and subscriptions.
- Anthropic and OpenAI - AI model inference (and OpenAI for spoken-audio replies).
- Plaid and connected brokerages / exchanges - account linking and read-only portfolio data (only when you connect them).
- Sentry - error monitoring.
A current list of material service providers that process personal information on our behalf, and the categories of data and services involved, may be maintained in a separate public subprocessor notice. Market and reference data sources that receive only non-personal reference queries are described separately in our Data Sources and Attributions notice and are not included in the subprocessor list for that data flow.
We may also disclose information to comply with law, respond to lawful requests, enforce our Terms, or protect the rights, safety, and security of our users and the platform, and in connection with a business transfer (merger, acquisition, or sale of assets).
8. Data Storage, Security, Location, and Breach Notification
Data is stored with our cloud infrastructure provider (AWS, U.S. region). Sensitive secrets - including any stored account credentials - are encrypted at rest, and data is transmitted over encrypted connections. We maintain a written information security program describing administrative, technical, and physical safeguards for the data we hold. Our safeguards are designed with reference to recognized financial-data security principles, including 16 C.F.R. Part 314. Whether a particular financial-privacy regime applies depends on the activities and regulatory classification of the service; this statement does not claim an exemption from or coverage under that rule.
No online service can guarantee perfect security; you acknowledge the inherent risks of transmitting and storing data online. In the event of a data breach affecting your personal information, we will notify you and applicable regulators as required by applicable breach-notification laws, including the Texas Identity Theft Enforcement and Protection Act, Tex. Bus. & Com. Code § 521.053. When that law requires notice to the Texas Attorney General because a breach affects at least 250 Texas residents, the notice must be made as soon as practicable and no later than 30 days after determining that the breach occurred.
9. Data Retention
We retain information for as long as your account is active and as needed to provide the service, comply with legal obligations, resolve disputes, and enforce our agreements. Retention windows for security logs, audit logs, and research artifacts follow our internal Data Retention & Deletion Policy. When you close your account, we erase or de-identify your personal information as described in that policy, retaining only what is required for legal or recordkeeping purposes.
Some feature-specific periods are shorter. Authentication sessions have an absolute lifetime of up to 30 days. Generated spoken SAGE chat audio becomes unavailable after 14 days; research anticipated-Q&A audio becomes unavailable after 30 days; and generated audio objects are deleted from active storage no later than 30 days after creation. Security codes become invalid after five minutes; challenge records containing the telephone number and associated security metadata are retained for up to 30 days for fraud prevention and security auditing. Security and administrative audit logs are generally retained for up to two years. Provider copies may remain for the provider periods described in Section 4. Backup, fraud-prevention, tax, billing, compliance, and legal records may be retained for longer where reasonably necessary or legally required.
To enforce the Freelancer rule that an account's own email address, a recovery email address, and a phone number can each receive their one-time Astra Credit grant only once, we retain a keyed, versioned cryptographic hash of the verified phone number, of the verified recovery email address, and of the verified account email address, together with grant status, retry ownership, attempt timestamps, and grant time. Each is hashed under a separate key domain, so these records cannot be matched to one another or to any other hash we retain. We do not store the phone number or either email address itself in that eligibility record. The record may remain after account closure because deleting it would allow the same phone number to claim the grant again. It is used only for grant eligibility, retry, fraud prevention, support, audit, and legal compliance.
10. Sensitive Personal Information
We treat portfolio, holdings, linked-account credentials, and financial-account data as highly sensitive financial information as a matter of company policy. Ordinary portfolio holdings are not, solely for that reason, “sensitive data” under every state privacy statute. Under the TDPSA, statutory sensitive data includes specified trait data, genetic or biometric data processed to uniquely identify a person, data from a known child, and precise geolocation data.
We process financial information only to provide, secure, support, and comply with law for the service you request; we do not use it to infer characteristics about you for advertising, and we do not sell or share it for targeted advertising. We do not collect voiceprints or process generated SAGE audio to identify you. If we process data legally defined as sensitive, we will obtain consent or another authorization required by applicable law and complete any required data-protection assessment. In accordance with Cal. Civ. Code § 1798.121, you may direct us to limit the use of sensitive personal information; because we already limit covered uses to permitted purposes, no additional action is generally required, but you may contact us to confirm.
11. No Sale, No Targeted Advertising, No Profiling for Significant Decisions
- We do not sell your personal information for money or other valuable consideration.
- We do not share your personal information for cross-context behavioral (targeted) advertising, and we do not use third-party advertising cookies.
- We do not engage in profiling that produces legal or similarly significant effects about you (see Section 12).
Because we do not sell or share personal information as defined by law, there is no "Do Not Sell or Share My Personal Information" transaction to opt out of - but you retain the rights described in Section 13.
12. Automated Decision-Making
AstraEye Labs uses AI to generate informational research for you to evaluate. We do not use automated processing to make decisions that produce legal or similarly significant effects about you (such as credit, employment, or benefits decisions). You make all financial decisions yourself. See the Risk and AI Disclosure.
13. Your Privacy Rights
Depending on where you live, you may have some or all of the following rights under laws such as the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), Cal. Civ. Code § 1798.100 et seq., the Texas Data Privacy and Security Act (TDPSA), Tex. Bus. & Com. Code § 541.001 et seq., and similar laws in Virginia, Colorado, Connecticut, and other states. In accordance with those laws, and subject to their exceptions, you may exercise:
- Right to know / access the personal information we hold about you and how we use and disclose it (Cal. Civ. Code §§ 1798.100, 1798.110, 1798.115).
- Right to correct inaccurate personal information (Cal. Civ. Code § 1798.106).
- Right to delete your personal information (Cal. Civ. Code § 1798.105).
- Right to data portability - obtain a copy in a portable format.
- Right to opt out of the sale or sharing of personal information, targeted
advertising, and profiling with significant effects (Cal. Civ. Code § 1798.120)
- we do none of these (see Sections 11-12), so there is nothing to opt out of.
- Right to limit the use of sensitive personal information (Cal. Civ. Code § 1798.121; see Section 10).
- Right to non-discrimination for exercising a right (Cal. Civ. Code § 1798.125) - we will not deny service, charge different prices, or provide a different quality of service because you exercised a right.
You can manage much of your data directly in the product - for example, account settings, notification preferences, disconnecting account connections, and closing your account.
14. How to Exercise Your Rights, Verification, and Appeals
To make a privacy request, email privacy@astraeyelabs.io. We will verify your identity (typically by confirming control of your account email) before acting, and will respond within the timeframe required by applicable law (generally within 45 days, extendable where permitted). You may use an authorized agent to submit a request on your behalf with proof of authorization.
Appeals. In accordance with the TDPSA, Tex. Bus. & Com. Code § 541.055, and similar state laws, if we decline your request you may appeal by replying to our decision or emailing privacy@astraeyelabs.io with "Appeal" in the subject. We will respond to appeals within the time required by applicable law (under the TDPSA, within 60 days). If your appeal is denied, you may contact your state Attorney General (for example, the Texas Attorney General for Texas residents, who accepts complaints in accordance with Tex. Bus. & Com. Code § 541.155).
15. Cookies, Sessions, and Global Privacy Control
We use strictly necessary cookies and similar technologies to keep you signed in, remember preferences, and secure the platform (including protection against cross-site request forgery). Session cookies may be associated with IP address, browser/user-agent, and security records. We do not use third-party advertising cookies.
Because we do not sell or share personal information or serve targeted advertising, browser signals such as Global Privacy Control (GPC) or Do Not Track have no sale/share to opt out of; we honor applicable opt-out-preference signals to the extent required by law.
16. Children
AstraEye Labs is not directed to children and is intended for users who are 18 or older. In accordance with the Children's Online Privacy Protection Act (COPPA), 15 U.S.C. §§ 6501-6506, we do not knowingly collect personal information from children under 13 (and, as a financial product, do not intend to collect from anyone under 18). If we learn that we have collected information from a child, we will delete it.
17. Users Outside the United States
AstraEye Labs is operated from the United States and is intended for users in the jurisdictions we serve. Your information is stored and processed in the United States. If you access the service from outside the U.S., you understand that your information will be transferred to and processed in the United States, which may have different data-protection laws than your location.
We do not currently offer the service in every country. Availability is limited by applicable sanctions and export-control laws and by the regions we are able to support, and it may change over time. Where the service is not offered, account registration is refused; if you already hold an account, you may still sign in to review and manage your account settings or to close your account. Requests for a copy of your data are handled as described in the rights sections above, through privacy@astraeyelabs.io.
18. Email Communications
AstraEye Labs uses email for account, service, and optional product or research communications. We do not purchase, rent, scrape, or sell email-address lists, and we do not send cold outreach.
Messages we send
Service and account messages may include:
- verification of an email address supplied during account registration;
- password-reset and new-device approval requests initiated by the account holder;
- important account-security notices; and
- payment receipts and payment-failure notices; and
- important service or legal notices.
Optional product, research, and notification messages may be sent only as permitted by law and are controlled by the recipient's notification preferences. They are not required to use AstraEye.
Address verification and abuse prevention
Before an address is verified, AstraEye sends only the registration verification message. Authentication email endpoints are rate-limited by recipient and network source, return non-enumerating responses, and use expiring, single-use tokens.
Bounces, complaints, and suppression
AstraEye processes delivery, bounce, complaint, rejection, and rendering-failure feedback from its email provider. Permanent bounces and complaints are automatically added to provider-level and application-level suppression lists. Suppressed recipients are blocked before another provider send is attempted.
We monitor bounce and complaint rates and investigate alarms before they approach provider enforcement thresholds. We test this feedback path using the provider's mailbox simulator.
Unwanted or suspicious email
If you receive an AstraEye message you did not expect, do not follow its links. Forward the message, including its full headers when possible, to spam@astraeyelabs.io.
For general help, contact support@astraeyelabs.io or visit the authenticated support center after signing in.
Sender identity
Official AstraEye transactional email is sent from the astraeyelabs.io domain.
AstraEye configures SPF, DKIM, DMARC, and a custom MAIL FROM domain to
authenticate its mail.
19. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated as required by law, and the "Effective date" above will be updated.
20. Contact
Questions or privacy requests may be sent to:
Mailing address:
AstraEye Labs LLC
11721 Pillion Pl
Manor, TX 78653-3767