Legal
Privacy Policy
Last updated 22 August 2026. This policy describes what Investiamus actually does today, not functionality we may add later.
Who operates Investiamus
Investiamus is currently operated as an independent project. No incorporated legal entity, company registration number or registered address has been established for it yet.
For any privacy question, contact contact@investiamus.com.
Data we collect
- Account and authentication data. Your email address and authentication credentials when you create an account, plus session information kept by the authentication provider.
- Watchlist entries. The assets and instruments you save. Visible only to your own account.
- Coverage and verification requests. The asset, country, instrument or provider you ask us to cover or verify, and any free-text note you add.
- Optional coverage-request email. An email address you may add to a coverage or verification request so we can tell you when that specific request is addressed.
- Optional Yield Finder waitlist email. An email address you may submit to be told when the Yield Finder feature becomes available.
- First-party product analytics. Events describing how the product is used: searches, results viewed, routes opened, comparisons, source openings, provider outbound clicks, watchlist additions and sign-up steps.
- Raw investment search queries. The text you type into the asset search, trimmed and capped at 100 characters, so we can see which investments we do not yet cover.
- Country selection. The country you choose in the country selector.
- Provider outbound-click events. Which provider link was opened, from which instrument and country context.
Analytics: what we do and do not use
- Investiamus uses first-party product analytics only. Events are stored in our own application database.
- There is no analytics cookie, no persistent analytics identifier, no per-tab analytics identifier and no analytics user id. Events are stored without any client identifier, so they cannot be joined into a per-visit or per-person journey by us.
- We do not use Google Analytics, Meta Pixel, Segment, Mixpanel, Hotjar, Clarity, a tag manager, any advertising or affiliate pixel, or any cross-site or social tracker.
- Analytics events are not intended to contain email addresses, passwords, authentication tokens, financial-account data or precise addresses. A deny-list strips such fields before an event is stored.
- Raw investment search queries are still stored (trimmed and capped at 100 characters) because understanding which investments people look for and do not find is the core way we decide what to cover next. Please do not type personal information into the search box. For that reason we do not claim the analytics dataset is necessarily legally anonymous.
Why we use this data
- To provide the service and show access routes for your country.
- To maintain your account and your watchlist.
- To understand how the product is used and where it fails.
- To identify missing investment coverage.
- To prioritise verification work and country or asset expansion.
- To respond to a specific notification request you made.
Emails you give us are purpose-bound
Adding an email to a coverage or verification request is optional — requests can be submitted anonymously. If you add one, it is used only to notify you about that specific request. It is not newsletter or marketing consent, and we do not add it to a marketing list.
The Yield Finder waitlist is separate: an email submitted there is used only to tell you when Yield Finder becomes available. Automated notification delivery is not yet built, so notifications are sent manually, if at all, when the relevant work is done. You can ask us to withdraw either request at any time at contact@investiamus.com.
Cookies and browser storage
Investiamus does use a small number of cookies and browser-storage entries. They are functional and infrastructure related. We do not use advertising or marketing cookies, and we set no third-party advertising or analytics cookies.
| Item | Purpose | Lifetime |
|---|---|---|
Cookie __cf_bm | Bot, abuse and security protection provided by our hosting/CDN layer. | About 30 minutes |
Cookie __dpl | Deployment/version consistency, so the assets your browser loads match the served build. | About 1 year |
| localStorage — authentication session | When you sign in, our authentication client stores your session in your browser's localStorage so you stay signed in. It is created at sign-in and removed when you sign out or clear browser storage. | Until sign-out or storage cleared |
| localStorage — country preference | Your selected country, written when you select or change a country, so the site remembers it on your next visit. | Until storage cleared |
| sessionStorage — navigation | Temporary navigation and scroll-position restoration while you browse, used by the page router. | Cleared when the tab closes |
Analytics sets no cookie and no browser-storage identifier. Web fonts are served from our own domain, so a normal page load makes no request to Google Fonts. Google is contacted only if you explicitly choose "Continue with Google" on the sign-in page, in which case Google's own terms and cookies apply to that sign-in flow.
How long we keep data
| Data | Retention |
|---|---|
| Product analytics events | Up to 12 months. |
| Raw investment search query text | Up to 90 days where the raw text is technically separable. Aggregated demand statistics derived from searches may be kept longer without the raw query. |
| Coverage / verification requests without an email address | Up to 24 months, for product-demand analysis. |
| Coverage / verification requests containing an email address | Until the requested notification is fulfilled, the request is closed or abandoned, or 24 months — whichever comes first. |
| Yield Finder waitlist sign-ups | Until the feature launches, until you ask for deletion, or a maximum of 24 months — whichever comes first. |
| Watchlist entries | While your account exists, or until you remove the entry. |
| Account and authentication data | While your account exists, subject to the requirements of the authentication provider that stores it. |
Automatic deletion jobs are not implemented yet. Deletion is currently performed manually in line with the periods above.
Your requests and how to make them
Self-service account or data deletion is not implemented yet. You can contact us at contact@investiamus.com to request:
- access to the personal data we hold about you;
- correction of inaccurate data;
- deletion of your account, watchlist, requests or waitlist entry;
- withdrawal of a notification request;
- answers to any other privacy question.
Tell us the email address you used so we can locate the records. We handle these requests manually and will confirm when they are done. This policy does not attempt to state legal bases or statutory rights that have not yet been reviewed.
Changes
Investiamus is in beta and this policy will change as the product changes. The date at the top of this page reflects the last substantive update.