B/Blindspot ResearchReturn to research

BLINDSPOT RESEARCH

Privacy

This page describes the information used to operate your Blindspot Research account and subscription.

Authentication and payments

Clerk processes authentication for Blindspot Research. Stripe processes subscription payments. Blindspot does not use those services to personalize research or connect to a brokerage account.

Account and subscription records

Railway hosting and its Postgres database store the minimum account, subscription, and permitted member-state records needed to operate the product. The database stores a Clerk account identifier and a limited projection of subscription status; Stripe remains the payment system of record.

Permitted member state is limited to product settings and research progress. It does not include source images, OCR output, uploaded-file metadata, account identifiers, holdings, position data, or transaction history.

Browser-local research continuity

Before payment, this browser may keep a strict versioned local draft containing only up to eight covered ticker symbols, the primary ticker, report version, fixed canonical answer IDs, the current funnel phase, and question index. It stores no answer text, date of birth, age, risk or suitability profile, email or account identifier, image, OCR text, filename, holdings, P&L, prompt, source ledger, or report output. An old, malformed, mismatched-subject, or mismatched-report draft is rejected or reset.

For screenshot entry, the current tab may separately keep only the coarse tuple inputKind, sourceType, and visibleDateState. It never contains image pixels, OCR, filenames, account identifiers, holdings, or values, and it is cleared on decline, cancel, read rejection or error, typed-ticker replacement, dynamic-analysis error, or successful analysis.

First-party measurement

When enabled, Blindspot records a short-retention, first-party funnel count for visits, onboarding start and completion, free-proof, the D6 product-example/value-proof page, and paywall presentation, server-created Checkout, webhook-confirmed access, and first authenticated persisted-report open. The historical event label first_paid_analysis means that first report open; it is never emitted before persistence. The historical event label social_proof_viewed means only that the D6 product-example/value-proof page rendered. It does not mean social proof; the page view is not a rating, testimonial, review, adoption measure, user-feedback record, attribution, or product-outcome claim. It retains no card position or content, answer, ticker, company, source ledger, research output, screenshot, OCR, prompt, holding, P&L, email, or Clerk or Stripe identifier. The record otherwise contains only an opaque server-derived session value, coarse time/status, and sanitized campaign source, campaign, and medium values. Measurement rows are retained for no more than 30 days.

Optional TikTok measurement

Only after affirmative marketing-measurement consent and only when separately enabled in production, Blindspot may send a limited conversion event to TikTok for Business. The footer control is off by default and lets you revoke this preference; revocation removes pending, undelivered TikTok events associated with its non-reversible consent key. The event contains an opaque event ID, event name/time, and the canonical Blindspot homepage URL only; it does not include email, Clerk or Stripe identifiers, tickers, screenshots, OCR, images, filenames, account or holding data, P&L, prompts, research, report output, request URLs, query values, IP address, or user-agent. A server-side retry record retains the same limited fields for no more than 30 days. TikTok may process technical browser or network data under its own policy.

Support requests

Support submission requires a signed-in Clerk session. Blindspot stores only the reply email, selected category, request reference, status, and timestamps needed to respond. The form does not accept a message, screenshots, OCR, account numbers, portfolio or holding information, P&L, or prompts. Support requests are retained for no more than 90 days and are not used for analytics. To prevent abuse, the server stores a non-reversible HMAC bucket derived from the verified Clerk subject with a distinct secret; it never stores the raw subject, IP, or user-agent, and the bucket expires within 24 hours.

Images and portfolio information

If you voluntarily use a screenshot, image, or pasted public text in the research flow, the original image, OCR text, pasted text, account identifiers visible in the image, and holding values are used only in the current local browser session. They are not sent to the report provider and are not stored in the Blindspot account, subscription, or member-state records. Only one confirmed covered ticker and the coarse allowed context classification may continue.

Blindspot does not request brokerage credentials or import brokerage holdings.

Paid report processing and retention

After server-verified subscription access and your explicit report request, Blindspot sends the confirmed ticker, coarse allowed context, and current public source ledger to OpenAI for one source-backed report attempt. It does not send image bytes, OCR, pasted text, holdings, P&L, email, payment identifiers, or a raw account identifier. The provider request uses a pseudonymous safety identifier and may use one web search.

Blindspot stores the confirmed ticker, coarse context, opaque lifecycle identifiers and timestamps, validated report fields, HTTPS citation title and link, report/model version, and bounded token/search/cost receipt. Terminal job, attempt, and safe diagnostic records are retained for no more than 30 days. A completed report is retained for no more than 90 days or until account deletion, whichever comes first.

Retry creates no new charge. A failed or expired attempt consumes no successful-report quota. Quota is used only when a validated cited report is atomically saved. Opening a saved report performs no new generation.

Questions

For questions about this privacy information, contact support through the support channel provided in the product.