Privacy Policy

Last updated: August 18, 2026

THE SHORT VERSION

SquawkFlow is a market-data terminal. It does not execute orders, does not connect to your brokerage, and does not take payment. The only personal information an account requires is an email address and a password. We do not sell personal information, we do not run advertising networks, and we do not build profiles for resale. Email admin@squawkflow.com to have your account and its data deleted.

1. Who We Are

SquawkFlow (“SquawkFlow”, “we”, “us”) operates the website at squawkflow.com and the API at api.squawkflow.com. This policy explains what we collect from visitors and account holders, why we collect it, how long we keep it, and how to have it removed.

2. What We Collect

2.1 Account data

When you register, we store an email address, a bcrypt hash of your password, a randomly generated account identifier, and the timestamp your account was created. We never store your password in plaintext or in any reversible form, and no one at SquawkFlow can read it. We do not ask for your name, phone number, address, date of birth, government identifier, income, or net worth.

2.2 Workspace and preference data

If you are signed in, the layout of your terminal — which panels you added, how you arranged them, and what you named each workspace — is saved to your account so it follows you between devices. This is UI configuration, not personal information. It is deleted automatically when the account is deleted.

2.3 Email alert subscriptions

The free tool pages (gamma exposure, dark-pool flow, sector rotation, SPX max pain, options flow, VIX term structure) let you subscribe to email alerts. For each subscription we store the email address, which tool you subscribed to, an unsubscribe token, and the IP address the request came from. The IP address is stored for one purpose only: rate-limiting so a single source cannot flood the list with other people’s addresses. Every alert email carries a one-click unsubscribe link.

2.4 Developer API keys

If you create a key for the public API, we store a SHA-256 hash of the key (never the key itself), the first characters of the key so you can tell your keys apart in the dashboard, the label you gave it, its access tier, when it was created, when it was last used, and a per-day request count. The request count is a total — we do not log which endpoints you called or what parameters you sent alongside your key.

2.5 Analytics

We use Google Analytics 4 to understand which pages people find useful and where they get stuck. It records page views and a small set of named product events — for example opening the terminal, reading an article, adding a panel, or clicking a call to action. These events carry contextual labels such as which page or which tool the click came from. They never carry your email address, your account identifier, or any content you entered. On embeddable widgets served to third-party sites, analytics storage is explicitly denied, IP anonymisation is on, and page views are not sent at all.

2.6 Server logs and rate limiting

Our application logs record the HTTP method, path, response status, and processing time of each request. They do not record IP addresses or account identifiers. Rate limiting keeps a short in-memory window of recent request timestamps per IP address; entries are discarded within a minute and are never written to disk. Our infrastructure providers keep their own connection logs — see section 6.

3. What We Do Not Collect

4. Browser Storage and Cookies

SquawkFlow itself sets no cookies. It uses your browser’s localStorage, which stays on your device and is never transmitted to us unless a specific feature sends it. What we store there:

Clearing your browser storage removes all of it. Google Analytics sets its own cookies under its own policy; blocking them does not affect any SquawkFlow feature.

5. Why We Collect It

Where the GDPR applies, our lawful bases are performance of a contract (accounts and workspaces), consent (email alerts and analytics), and legitimate interests (security, abuse prevention, and product measurement).

6. Service Providers

A small number of third parties process data on our behalf:

We do not sell, rent, or trade personal information to anyone, for any purpose. We share it only with the processors above, or where we are legally compelled to.

7. AI Features

Terminal analysis, SquawkBot commentary and the AI Copilot send market context and the question you typed to a large language model provider for generation. Copilot conversations are held in server memory for the duration of your session and expire automatically; they are not written to our database. Do not enter sensitive personal information into any AI prompt on SquawkFlow.

8. Retention

9. Your Choices and Rights

Depending on where you live, you may have additional rights under the GDPR, UK GDPR, or the CCPA/CPRA, including the right to object to processing and the right not to be discriminated against for exercising them. We honour these requests regardless of where you live.

10. Security

Passwords are hashed with bcrypt. API keys are stored only as SHA-256 hashes. Traffic is served over HTTPS and proxied through Cloudflare. Sessions are signed JWTs with a 7-day expiry. No system is perfectly secure, and we make no guarantee that unauthorised access can never occur.

11. International Transfers

Our infrastructure and processors are based in the United States, so data you provide is processed there. If you access SquawkFlow from outside the United States, you are transferring that information to the United States.

12. Children

SquawkFlow is not directed at anyone under 18 and we do not knowingly collect information from children. If you believe a child has created an account, email us and we will remove it.

13. Changes to This Policy

We will update this page and the date at the top when this policy changes. Material changes to what we collect or who we share it with will be communicated to account holders before they take effect.

14. Contact

Privacy questions, data requests, and deletion requests: admin@squawkflow.com. See the contact page for other enquiries.

About SquawkFlow · Open Terminal · Terms of Service · Contact