Last updated: October 7, 2026
THE SHORT VERSION
SquawkFlow is a market-data terminal. It does not execute orders, does not connect to your brokerage, and does not take payment. The only personal information an account requires is an email address and a password. To count real visitors, we give each browser a random visitor ID and keep web request logs, which include IP addresses, for 90 days. We do not sell personal information, we do not run advertising networks, and we do not build profiles for resale. Email admin@squawkflow.com to have your account and its data deleted.
SquawkFlow (“SquawkFlow”, “we”, “us”) operates the website at squawkflow.com and the API at api.squawkflow.com. This policy explains what we collect from visitors and account holders, why we collect it, how long we keep it, and how to have it removed.
If you have an account, we store an email address, a bcrypt hash of your password, a randomly generated account identifier, and the timestamp your account was created. We never store your password in plaintext or in any reversible form, and no one at SquawkFlow can read it. If you used or shared an invite code, we also store the code and which account referred which. We do not ask for your name, phone number, address, date of birth, government identifier, income, or net worth.
If you are signed in, the layout of your terminal, which panels you added, how you arranged them, and what you named each workspace, is saved to your account so it follows you between devices. This is UI configuration, not personal information. It is deleted along with the account.
The free tool pages (gamma exposure, dark-pool flow, sector rotation, SPX max pain, options flow, VIX term structure), the morning brief and the ticker pages let you sign up for email alerts. For each sign-up we store the email address, which tool you chose, an unsubscribe token, whether the address has agreed to the daily levels email, and the IP address the request came from. We use the IP address to rate-limit sign-ups, so a single source cannot flood the list with other people’s addresses. It is stored with the sign-up record. Every alert email we send carries an unsubscribe link. Unsubscribing stops all alert emails to that address at once. The record is kept, marked inactive, so that the address is not emailed again; email us if you want it deleted entirely. For the daily levels email, we also record which address was sent the email on which day, so that no one gets the same email twice; records older than 90 days are removed each time the daily email goes out. For the weekly digest email, we record which address was sent it for which week. Those records are not deleted on a schedule. An older early-access list, no longer offered on the site, holds email addresses and an optional plan name.
If you create a key for the public API, we store a SHA-256 hash of the key (never the key itself), the first characters of the key so you can tell your keys apart in the dashboard, the label you gave it, its access tier, when it was created, when it was last used, and a per-day request count. The request count is a total and does not record which endpoints you called. Our API server logs (section 2.6) record each requested address, but a key sent in the address as ?key= is masked before the line is written. Sending it in the X-API-Key header keeps it out of the address altogether.
We use Google Analytics 4 to understand which pages people find useful and where they get stuck. It records page views and a small set of named product events, for example opening the terminal, reading an article, adding a panel, clicking a call to action, or voting in the Lab. These events carry contextual labels such as which page or which tool the click came from. They never carry your email address, your account identifier, or any content you entered. On embeddable widgets served to third-party sites, Google Analytics storage is explicitly denied, IP anonymisation is on, and page views are not sent to Google. Instead, one embed_viewed event is sent, carrying the widget name and the host name of the site that embeds it. The visitor ID in section 2.7 still applies there.
Our API server at api.squawkflow.com logs each request it receives, including the IP address, the requested path and query string, and the response status. We use these logs for debugging and abuse prevention. They are rotated automatically. Rate limiting keeps recent request timestamps per IP address in memory only. They are never written to disk, stop counting after at most one hour (the email sign-up and feedback forms count per hour, most other requests per minute), and are cleared whenever the server restarts. Separately, the public developer API counts hourly requests from callers without a key against a SHA-256 hash of the IP address. Those counters are stored on our server and are not yet deleted on a schedule. Our infrastructure providers keep their own logs, see section 6.
Every page on squawkflow.com gives your browser a random visitor ID. It is a random string with no meaning outside your browser, and it is not linked to an account, a name or an email address. It is stored in a first-party cookie named sf_vid and in localStorage under sf_vid_v1, together with the day of your first visit, the day of your latest visit, and the number of different days you have visited. The cookie lasts one year and is refreshed on each visit.
About once a day per browser tab, the page sends a small request to squawkflow.com/b carrying the visitor ID, the first-visit day and the day count. The same kind of request is also sent when you do one of a few named things: view the morning brief, use the main chart or calculator on certain tool pages, open the terminal from a tool page, or pin a symbol. Those requests add the event name and, where relevant, the tool name or the path of the page it came from. That path can include the ticker symbol of the page you were on, for example /gex-heatmap/SPY. They never carry a search or anything you typed. We use this to count how many visitors come back on later days. The /b address stores nothing itself. The request is recorded in our hosting provider’s request logs.
Those web request logs record, for every request to squawkflow.com, the IP address, the browser user agent, the referring page, and the full requested address, which includes the visitor ID on /b requests. We copy them daily to tell human visitors apart from bots and to count visitors. Our copies are kept for 90 days, then deleted, both on our server and in our private backup storage. The backup storage purges deleted copies within about a week after that. Daily visitor totals worked out from these logs contain no IP addresses or visitor IDs, and we keep them indefinitely. Bot-traffic reports kept with them can name the network ranges and user agents of bot sources.
When a live terminal connection closes, our API server writes one record with a keyed hash of your IP address, the connect and disconnect times, how long the connection lasted, which data channels were open, and a coarse client type (browser, bot, other or none). These records are pseudonymous, not anonymous. The hash uses a secret key that stays on our server and is not included in our backups, so a backup copy on its own cannot be turned back into addresses. The same address hashes the same way on different days, which lets us measure how long people keep the terminal open and whether they come back. These records are kept for 90 days, then deleted, including backup copies, which are purged within about a week after that.
When you vote on a record in the Lab, we store the vote, the record and engine it is for, the record’s status at the time, the time of the vote, and a keyed hash of your IP address (HMAC-SHA256 with a secret key), so each address gets one vote per record. The vote record stores no IP address. Our API server log (section 2.6) does record that your IP address sent a vote, but not which way you voted. Votes are not linked to your identity or to an account. Your browser also remembers your own vote in localStorage, and the vote and the engine name are sent to Google Analytics as an event, under Google Analytics’ own browser ID. Votes have no set deletion date.
If you send feedback, we store your message, the category you chose, the page you sent it from, which tool on that page and which link opened the form, the as-of time shown on that page if there was one, a rough count of how many days you have visited (one, two, or three or more), the hour it was sent, whether our spam filter flagged it, and a keyed hash of your IP address (HMAC-SHA256 with a secret key; for an IPv6 address, of its /64 network) used only to limit abuse. We do not store your IP address, visitor ID, browser details or email address with it. Before the message is stored, we automatically try to remove common personal details from it, such as email addresses, phone numbers and card numbers. Automatic removal cannot catch every format, so please do not include personal or account details. Your browser keeps its own copy of the reference code, the date and the start of your message in localStorage, so this site can show you later if your request was built. If a message does not send, your browser also keeps it in localStorage until it does. This site removes both from your browser once they are 90 days old, the next time you open any page here. Our API server log (section 2.6) records that your IP address sent feedback, but not what you wrote. Opening the form and sending it are recorded in Google Analytics as events carrying which link you used and the category, never the message.
When you play the daily Predictions game, our server issues your browser a random player ID, which your browser keeps in localStorage. We store a hash of that ID (never the ID itself), a short public reference code, the time it was issued, each pick you make (the session date, the bucket you chose and the time), and a keyed hash of your IP address (HMAC-SHA256 with a secret key; for an IPv6 address, of its /64 network) with the ID and with each pick. The keyed hash limits how many picks one network can make per session and counts one pick per network in the crowd split. If you arrived through someone’s share link, we store their reference code with your player ID. If you choose a display handle, it is shown publicly on the leaderboard next to your score. We do not store your IP address, email address, visitor ID or browser details with any of it, and picks are not linked to your identity or to an account. Our API server log (section 2.6) records that your IP address sent a pick, but not which bucket you chose. Earnings calls on /predict and /earnings pages store the same fields: the symbol and report date, your over or under pick and its time, with the same keyed address hash. Report results (line, closes, move) are stored per report and hold nothing about players.
A feedback message is free text, so anything typed into it is stored as written, apart from what our automatic removal catches (section 2.10), and deleted after 90 days. Please leave personal, account and trading details out of it.
SquawkFlow sets these first-party cookies on squawkflow.com:
sf_vid, the random visitor ID described in section 2.7, with your first-visit day and day count. Lasts one year and is refreshed on each visit.sf_returning, set to 1 when you open the terminal, so the home page can send you straight back to the terminal (or to the morning brief on a phone). It carries no ID. Lasts one year and is refreshed each time you open the terminal._ga and _ga_ followed by an ID for our Google Analytics property, set by our Google Analytics tag (section 2.5) to recognise your browser across visits. They last about two years.SquawkFlow also uses your browser’s localStorage and sessionStorage. These stay on your device. The visitor ID is sent to us as described in section 2.7; the rest is never sent to us unless a specific feature sends it. What we store there:
sf_vid_v1, the visitor ID, first-visit day and day count (section 2.7); sf_beacon_sent_day (sessionStorage), the day this tab last sent itsquawkflow:auth-token, your signed-in session token (a JWT that expires after 7 days)squawkflow:layouts, squawkflow:active-layout, terminal workspace layouts, so signed-out users keep their arrangement toosquawkflow-watchlist, squawkflow_recent_searches, your symbols and recent lookupssf-continuity, the symbols you pinned, your chosen workspace and your notes, shown and managed on the saved on this browser pagesf_terminal_decision_v1, the last market read the terminal showed, so it can display it while it loadssquawkflow:color-scheme, squawkflow_audio_config, squawkbot:muted, squawkbot:expanded, display and audio preferencessquawkflow:onboarding-complete, squawkflow:visited-terminal, squawkflow:banner-dismissed-on, squawkflow:banner-pageviews (sessionStorage), sf_install_nudge_v1, first-run, banner and install-prompt statesquawkflow:start-here-progress, your progress through the Start Here learning pathsquawkflow:lab-vote: followed by a record ID, your own vote on that Lab recordsquawkflow:achievements, squawkflow:streaks, squawkflow:achievements:enabled, optional usage-streak featuressquawkflow:referral-code, an invite code, if you arrived through onesf_predict_player_v1, your Predictions game player ID and reference code; sf_predict_ref_v1, the reference code of a share link you arrived through, until your player ID is issued (section 2.11)sf_feedback_v1, the reference code, the date and the start of each feedback message you sent from this browser (the last 20), so this site can show you later if your request was built; sf_feedback_draft_v1, a feedback message that did not send, kept until it does. This site removes both once they are 90 days old (section 2.10)Clearing your browser’s site data for squawkflow.com removes all of it, cookies included. Blocking the Google Analytics cookies does not affect any SquawkFlow feature.
Where the GDPR applies, our lawful bases are:
A small number of third parties process data on our behalf:
We do not sell, rent, or trade personal information to anyone, for any purpose. We share it only with the processors above, or where we are legally compelled to.
Polymarket is not a processor of ours. The Election Center links to Polymarket market pages; if you follow one, Polymarket receives your visit directly, under its own privacy policy. SquawkFlow does not currently load Polymarket's hosted widget on any page. If the Election Center page loads it, your browser fetches the widget directly from Polymarket, which then receives your IP address, your browser's user agent and the address of the page it is shown on, and may set its own cookies, storage or tags. Polymarket's own privacy policy governs that data. SquawkFlow receives nothing from Polymarket.
Terminal analysis, SquawkBot commentary and the AI Copilot generate text with a language model that runs on our own server. Market context and the question you typed are processed there and are not sent to an outside AI provider (see section 6). Copilot conversations are held in server memory for the duration of your session and expire automatically; they are not written to our database. Do not enter sensitive personal information into any AI prompt on SquawkFlow. Feedback messages are the one exception to “processed on our own server”: they are summarized with Anthropic’s Claude, as described in section 6.
sf_vid expires one year after your last visit, sf_returning one year after you last opened the terminal, and the Google Analytics cookies after about two years.Depending on where you live, you may have additional rights under the GDPR, UK GDPR, or the CCPA/CPRA, including the right to object to processing and the right not to be discriminated against for exercising them. We honour these requests regardless of where you live.
Passwords are hashed with bcrypt. API keys are stored only as SHA-256 hashes. Terminal session records, Lab votes, Predictions game picks and feedback messages store only keyed hashes of IP addresses. Traffic is served over HTTPS, and api.squawkflow.com is proxied through Cloudflare. Sessions are signed JWTs with a 7-day expiry. No system is perfectly secure, and we make no guarantee that unauthorised access can never occur.
Our infrastructure and processors are based in the United States, so data you provide is processed there. If you access SquawkFlow from outside the United States, you are transferring that information to the United States.
SquawkFlow is not directed at anyone under 18 and we do not knowingly collect information from children. If you believe a child has created an account, email us and we will remove it.
We will update this page and the date at the top when this policy changes. Material changes to what we collect or who we share it with will be communicated to account holders before they take effect.
Privacy questions, data requests, and deletion requests: admin@squawkflow.com. See the contact page for other enquiries.