← Back to the app

Privacy Policy

Last updated September 3, 2026

This English version is provided for convenience. The service is offered by a Brazilian company under Brazilian law; in case of conflict, the Portuguese version prevails.

In short: we keep what the product needs to work and to bill you — including your conversations with the agent and what it concludes about how you invest, which is what lets it remember you. You can see, correct and delete all of it whenever you want. We do not keep the documents you upload, and we do not sell anything to anyone.

1. What data we collect

Sign-up: name, e-mail and profile photo, received from Google when you sign in. We neither ask for nor store a password: authentication happens at Google.

Product usage: your watchlists, the assets you mark as "I own", the purchase history you choose to record in your portfolio — quantity, price, date and an optional note — and the alerts you set up.

Optional financial context: goal, horizon, experience and depth of analysis that you choose to provide. These fields are not inferred from conversation text and can be edited or deleted in the agent’s "Context" control.

Optional investment theses: text, assumptions and invalidation signals you decide to save for an asset. No thesis is created automatically. If YOU ask for a draft, we read only YOUR messages about that asset — never the agent’s replies — to fill in the form; nothing is saved until you confirm, and the screen shows which conversations the draft came from. You can edit, archive or delete each record.

Reactions to news: when you react to an article, we keep the reaction you chose. There is at most one per person per article; you can change or remove it. Counters are aggregated and never identify participants.

Simulated portfolios: the practice portfolios you build, with every buy and every sell — the ticker, the quantity, the market price at the time, the date and the reason you write when selling. The money is fake, but the record is yours: it shows what you considered buying and when you changed your mind. You can delete each portfolio at any time, and deleting it removes its trades as well.

Atlas, a private lab with restricted access: when enabled for your account, it keeps conversations, research, theses, simulated orders and trades, costs and a decision journal. The full state and the journal are included in the data export and are removed along with the account.

Your conversations with the agent: we keep what you write and what it replies, so the conversation can pick up where it left off and so it remembers what has already been discussed. You can delete any conversation, and deleting it removes the messages from our database.

Optional voice transcription: when you record in the message field, the audio is processed temporarily by Google or by OpenAI solely to produce the transcription. We do not store the audio in a database, file, analytics, logs or history. The text comes back as an editable draft and only enters the conversation history if you decide to send it.

Deep research reports: we keep the asset, the optional question, the full text of the report, the source categories and the technical generation data. This keeps a paid report from disappearing if the tab closes and lets you consult and export it later.

Usage metering: we record which action you performed (message, report, statement reading), when, and the estimated cost. This record keeps the ACTION and the cost — never the text of the question.

Notification history: we keep only the channel, the technical reference and the moment a notification was delivered. This record keeps briefings, news, alerts and closing summaries from arriving in a pile; it does not keep the text of the notification.

App usage: we record when you view a market, open an asset, edit a list or go through an onboarding step — with the region, the ticker and the step, nothing more. It tells us what works in the product. This record keeps the ACTION, never what you type, and is included in your data export like everything else.

Billing: Stripe processes payments and stores card data. We receive only the customer identifier, the status and the plan. Card numbers never pass through our servers.

Technical data: IP address and browser information, used for security, usage limits and for choosing the default language and market.

2. The agent’s memory: what it keeps about you

This is the most important part of this policy, because it is the one that least resembles the others: beyond what you write, we keep what the agent CONCLUDES from what you write.

Conversation summary: every few messages, we generate a sentence about what was discussed and which assets came up. It is what lets the agent pick up a topic weeks later instead of starting from scratch.

Semantic representation: we may turn that summary into a numeric sequence to locate related topics without sending every conversation to the agent. It carries no authority of its own, does not mix data between people and is deleted along with the memory and the account.

Investment criteria: when you make clear how you decide — "I avoid indebted companies", "I only look at dividend payers", "I consider anything above 15 times earnings expensive" — the agent records that as a sentence, to adapt the next analysis to what matters to you.

Each record keeps its ORIGIN: whether you STATED it, or whether we INFERRED it from the way you ask. These are different things and the agent weighs them differently — an inference is treated as a hypothesis, never as a fact about you.

You see everything, confirm what is right and delete what is not, under Profile → Agent’s mind. Confirming an inferred item changes its origin to "stated", because once you have read it and said it is true, it is no longer our deduction.

We use none of this for advertising, we do not sell it and we do not cross-reference it with other people’s data. The profile serves a single purpose: improving the answer YOU receive.

3. Why we process each piece of data (legal basis)

Performance of the contract (Art. 7, V of the LGPD, Brazil’s data protection law): sign-up, lists, portfolio, simulated portfolios, alerts, notification history, financial context you chose to provide, reactions to news, conversations with the agent, the memory and criteria described in section 2, billing and usage metering. Continuity between conversations is not an extra: it is the core function of the product you signed up for, and it does not exist without storage.

Legitimate interest (Art. 7, IX): technical data used for security, abuse prevention and fault diagnosis.

Compliance with a legal obligation (Art. 7, II): tax and billing records, kept for the period the law requires.

You can object to the profiling described in section 2 by deleting the records. The agent keeps working; it simply goes back to treating each conversation as the first.

4. Who we share data with

Google (Firebase Auth): authentication of your account.

OpenAI: the questions you ask, the open asset, the context of your lists and of the assets marked as "I own", the financial choices you saved, the summary of previous conversations and the criteria from section 2, plus the documents sent to the reader, are processed to generate the answer. It may also temporarily receive the audio you choose to record when the primary transcription is unavailable. We ask OpenAI not to retain this content. Send only what you would be comfortable sharing.

Google (Gemini): in the public agent, it does NOT generate the agent’s answers. It receives (a) the text of public articles for the independent verification that checks the report’s claims, (b) the text of news articles to build similarity search and (c) temporarily, the audio you choose to record for transcription. Voice transcription does not automatically send your portfolio, your conversation history or documents; it receives only the passage you dictated. In the private Atlas lab, it also receives research context to contribute to the analysis.

Anthropic (Claude): in the private Atlas lab, it may receive the research context and the simulated thesis for a critical review. Exa and Firecrawl receive research queries and public source addresses for discovering and reading evidence.

Stripe: payment processing and subscription management.

Neon and Vercel: database and hosting.

Upstash: quote cache and usage-limit counters. It stores an identifier and a count, not conversation content.

Sentry: error monitoring. Configured to NEVER send request bodies — which is where your question and documents travel. It receives the failure and where it happened.

Market data providers (brapi, Financial Modeling Prep, Yahoo Finance, CoinGecko) and web search: they receive the ticker or the search term needed for the query, never your identity.

Meta (pixel and Conversions API): measures the campaigns that bring people to Compound. Only with your consent in the banner does Meta receive the event (visit, sign-up, subscription), the ad click identifier and technical access data; the e-mail travels only as a fingerprint (SHA-256), never in the clear. The server-side API requires the same first-party proof of consent before sending any conversion.

We do not sell your data. We do not build advertising profiles, nor do we hand your list or your conversations to advertisers.

5. Documents you upload

The statement reader accepts PDFs and images of financial statements. These files are sent to OpenAI, processed in memory to generate the analysis and are NOT stored by Compound: not in the database, not on disk, not in a bucket.

This is a design decision, not just a policy one: financial statements can be sensitive data, and the safest way to store them is not to.

6. How long we keep data

Account data, content you created, portfolio positions and purchase history, and financial context: for as long as the account exists or until you delete them.

Investment theses: until you edit, archive or delete the record, or request account deletion.

Reactions to news: for as long as the account exists or until you remove the reaction. Deleting the account removes your choices; the counters shown to other people are aggregated and do not reveal identity.

Simulated portfolios: for as long as the account exists or until you delete the portfolio. Deleting a portfolio removes its buys and sells.

Conversations with the agent: for as long as the account exists or until you delete the conversation. Deleting a conversation removes its messages and summary.

Deep research reports: for as long as the account exists. Deleting the account removes the full text, the question and the associated metadata.

Investment criteria (section 2): until you delete them under Profile → Agent’s mind, or delete the account. We keep at most the 20 most recent; beyond that, the oldest one you have not yet confirmed goes first.

Usage records: kept for as long as the account exists, for cost and capacity analysis. TO BE EXACT: today there is no automatic age-based purge. We are building one, and when it ships this section will state the retention period — we will not publish a number the system does not yet honor.

Notification history: kept for as long as the account exists to enforce the spacing between channels; deleting the account removes these records immediately.

Billing records: they stay with Stripe, our payment processor, for the applicable legal period. Closing your account here does not delete them there, and could not: they are the tax record of the transaction.

Account deletion is immediate and done by you, in the app itself: Profile → Delete account. We delete sign-up data, lists, portfolio with its entire purchase history, alerts, notification history, financial context, theses, reactions to news, topics of interest, conversations, summaries, investment criteria, fixed income, simulated portfolios, reports and usage records on the spot, and we cancel the active subscription before deleting.

7. Your rights

The LGPD guarantees you: confirmation that we process your data, access to it, correction, anonymization or deletion, portability, information about who we share it with, and review of automated decisions that affect your interests.

Access and portability: Profile → Download my data returns, as JSON, everything we keep about you — sign-up data, lists, portfolio with quantity, price, date and note of each recorded purchase, fixed income, simulated portfolios with all buys and sells, alerts, notification history, interests, theses, reactions to news, financial context, usage, subscriptions, conversations, deep research reports, summaries and investment criteria with the origin of each.

Contesting what we inferred: Profile → Agent’s mind shows each criterion the agent formed about you, with its origin. You confirm or delete, item by item. An inference nobody can contest is a black box, which is why this control exists before any request.

Deletion: Profile → Delete account, with no intermediary and no waiting.

Name correction: Profile → edit. The remaining sign-up data comes from your Google account and is changed there.

You can also revoke Compound’s access to your Google account at any time, in your Google account settings.

8. Security

The session uses an httpOnly cookie, inaccessible to browser scripts, and is revalidated against Firebase on every request.

All traffic is encrypted in transit (HTTPS) and the database is encrypted at rest.

API keys and secrets live only on the server and never reach the browser.

No system is perfectly secure. If an incident occurs that could pose a relevant risk to you, we will notify you and the ANPD (Brazil’s data protection authority) as the LGPD requires.

9. Cookies

Necessary cookies, always on: the session cookie (to keep you signed in) and the language cookie (to remember your choice). Without them the app does not work.

Measurement cookies, OPTIONAL: we use Google Analytics, Microsoft Clarity and Meta to understand where visits come from and how people navigate. They are only loaded if you allow them — until you answer, or if you decline, the measurement scripts do not enter the page. Your choice is kept in the browser and in a first-party preference cookie, also used so the server honors the same decision; we do not ask again.

Ad measurement cookies (_fbp and _fbc, from Meta) are only created after your consent, through the same banner. Google ad personalization is off by default in our configuration, even with measurement allowed.

The internal operations panel is outside any third-party measurement.