Privacy Policy
Last updated: 25 July 2026 · Effective: 25 July 2026
1. Introduction
This Privacy Policy explains how personal data is collected, used, shared, and protected when you use ThesisLock (the "Service"), available at thesislock.com.
This Policy forms part of, and should be read together with, our Terms of Service. Capitalised terms not defined here have the meaning given to them in the Terms of Service.
We are committed to processing your personal data lawfully, fairly, and transparently in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and Romanian data protection legislation, including Law no. 190/2018.
If you do not agree with this Policy, please do not use the Service.
2. Data Controller
The data controller responsible for your personal data is:
Lacramioara Gabriela Petrescu
Natural person resident in Romania (European Union)
Operating as an unregistered sole operator (not currently a registered PFA, ÎI, or SRL entity)
Contact for all data protection matters: contact@thesislock.com
We are not required to appoint a Data Protection Officer under Article 37 GDPR, as our processing does not consist of large-scale monitoring or large-scale processing of special-category data. All data protection enquiries are handled directly at the address above.
3. Summary
We keep this short because it matters:
- We collect the minimum needed to run the Service.
- We never see or store your payment card details.
- We do not sell, rent, or trade your personal data. Ever.
- We do not use your content to train artificial intelligence models, and our AI provider does not use it to train theirs.
- We do not connect to your brokerage account. We hold no account numbers, no positions verified against any broker, no trade confirmations, and no money.
- Everything you write in ThesisLock, you wrote. We store it and give it back to you.
4. Personal Data We Collect
We collect only data you provide directly, or that is generated automatically as a technical consequence of you using the Service. We do not buy personal data, and we do not collect personal data about you from third parties.
4.1 Account data
| Data | Source |
|---|---|
| Email address | You, at signup |
| Hashed password / authentication credentials | You, via Supabase Auth |
| Account creation date, last sign-in timestamp | Generated automatically |
| Subscription status, plan, and billing period dates | Generated from payment events |
We never store your password in readable form. Authentication credentials are hashed and managed by Supabase Auth.
4.2 Content you create
Theses, Claims, pre-committed actions, kill conditions, written notes, ticker symbols you follow, self-reported allocation percentages, tags, retirement and re-entry records, and the full event history generated by your activity within the Service.
Note on allocations: these are figures you type in yourself. They are not retrieved from, verified against, or reconciled with any brokerage account, and we have no means of doing so.
4.3 Payment data
Payment is handled entirely by Lemon Squeezy LLC as Merchant of Record. You provide your card details directly to Lemon Squeezy.
We never receive, process, or store your card number, CVV, or full billing address. What we receive from Lemon Squeezy is limited to: a subscription identifier, a customer identifier, plan and status, renewal date, and the email address associated with the purchase — the minimum required to grant and maintain your access.
4.4 Technical and log data
Error logs, request timestamps, HTTP status codes, and browser/device type as reported in standard request headers. IP addresses may appear transiently in infrastructure logs held by our hosting and database providers.
We do not maintain analytics profiles, behavioural profiles, advertising identifiers, or cross-site tracking of any kind.
4.5 Communications
If you email us or submit feedback through the Service, we retain that correspondence and your email address in order to respond and to keep a record of the issue.
4.6 Special-category data
We do not seek, request, or knowingly process special-category personal data within the meaning of Article 9 GDPR (data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data concerning sex life or sexual orientation). Please do not enter such data into free-text fields.
We also do not process criminal conviction or offence data under Article 10 GDPR.
5. Why We Process Your Data, and Our Legal Basis
Under Article 6 GDPR, every processing activity requires a legal basis. Ours are set out below.
| Purpose | Data used | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Create and maintain your Account; authenticate you | Account data | 6(1)(b) Performance of a contract |
| Store, display, and return the content you create | Content you create | 6(1)(b) Performance of a contract |
| Generate AI-assisted summaries and claim reviews | Relevant Thesis/Claim text, transcript excerpts | 6(1)(b) Performance of a contract |
| Send alerts, drawdown notifications, and reminders you have configured | Account data, content, notification settings | 6(1)(b) Performance of a contract |
| Grant, maintain, and revoke paid access | Subscription data from Lemon Squeezy | 6(1)(b) Performance of a contract |
| Respond to your support requests | Communications | 6(1)(b) Performance of a contract |
| Keep the Service secure; detect and prevent fraud, abuse, and unauthorised access | Technical logs, account data | 6(1)(f) Legitimate interests |
| Diagnose faults and improve reliability | Technical logs | 6(1)(f) Legitimate interests |
| Retain transaction and tax records | Limited billing records | 6(1)(c) Legal obligation |
| Establish, exercise, or defend legal claims | As relevant | 6(1)(f) Legitimate interests |
| Optional marketing communications, if we ever introduce them | Email address | 6(1)(a) Consent |
Legitimate interests. Where we rely on legitimate interests, we have assessed that our interest in operating a secure, functioning service does not override your rights and freedoms, principally because the data involved is limited, technical, and not used to build any profile of you. You may request a summary of that assessment by emailing us, and you have the right to object under clause 9.6.
Consent. We currently send no marketing email. If that changes, we will ask for your consent first, and you will be able to withdraw it at any time without affecting your use of the Service or the lawfulness of processing carried out before withdrawal.
If you do not provide the data. Email address and password are necessary to create an Account; without them we cannot provide the Service. All other data is optional in the sense that you choose what to write.
6. Artificial Intelligence Processing
6.1 Certain features — earnings claim review and news summarisation — send text to a third-party large language model provider, currently Anthropic PBC, for processing.
6.2 The data sent is limited to what the feature requires: the text of the relevant Claim or Thesis you are reviewing, and excerpts from the publicly available source material. We do not send your email address, account identifier, payment data, or unrelated content.
6.3 Your content is not used to train AI models. We do not train models on your content, and our processing agreement with our AI provider is on terms under which inputs submitted through the API are not used to train their models.
6.4 AI output may be inaccurate. This is a data-quality warning as well as a legal one: do not treat machine-generated text about your holdings as a verified record. See clause 8 of the Terms of Service.
6.5 No solely automated decision-making. We do not make any decision about you by solely automated means that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22 GDPR. AI features generate text for you to read and judge; they do not decide anything about your Account, your access, or your rights.
6.6 We may change AI providers. Where we do, we will update the sub-processor list in Annex A and continue to apply the standards set out in this clause.
7. Who We Share Data With
We share personal data only with the sub-processors listed in Annex A, each of which processes only what its function requires, under a written data processing agreement compliant with Article 28 GDPR.
We may also disclose personal data:
- where required by law, court order, or a lawful request from a competent authority;
- where necessary to establish, exercise, or defend legal claims;
- to professional advisers (legal, accounting) under a duty of confidentiality; and
- to a successor entity in connection with a reorganisation, incorporation of a PFA or SRL to operate the Service, merger, or sale of assets — in which case we will notify you and this Policy will continue to apply until replaced.
We do not sell, rent, licence, or trade personal data. We do not share personal data with advertisers, data brokers, or analytics networks.
8. International Transfers
Several sub-processors store or process data outside the European Economic Area, principally in the United States. The destination for each is stated in Annex A.
Where personal data is transferred outside the EEA, we rely on one or more of the following safeguards under Chapter V GDPR:
- Standard Contractual Clauses approved by the European Commission (Implementing Decision (EU) 2021/914), incorporated into our agreement with the relevant processor;
- an adequacy decision of the European Commission, where one applies to the recipient; or
- supplementary technical and organisational measures applied by the processor, including encryption in transit and at rest.
You may request further detail on the specific safeguards applying to any transfer by emailing contact@thesislock.com.
9. Your Rights
Under the GDPR you have the following rights. All are free of charge, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse it, giving reasons.
9.1 Right of access (Art. 15). Obtain confirmation of whether we process your data, a copy of it, and information about how it is processed.
9.2 Right to rectification (Art. 16). Have inaccurate data corrected and incomplete data completed. Most of your data is directly editable within the Service.
9.3 Right to erasure (Art. 17). Have your data deleted. You can do this yourself at any time from the Settings page — deletion is a permanent, irreversible hard delete across all records. You may also request it by email.
9.4 Right to restriction (Art. 18). Require us to limit processing in certain circumstances, for example while a dispute about accuracy is resolved.
9.5 Right to data portability (Art. 20). Receive the data you have provided in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible. The Service does not currently include a self-service export function. If you wish to exercise this right, email contact@thesislock.com and we will provide your data as a machine-readable file within the statutory time limit.
9.6 Right to object (Art. 21). Object at any time to processing based on legitimate interests. Where you object, we will stop unless we can demonstrate compelling legitimate grounds that override your interests, or the processing is needed for legal claims.
9.7 Right to withdraw consent (Art. 7(3)). Where processing is based on consent, withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
9.8 Rights in relation to automated decision-making (Art. 22). As stated in clause 6.5, we carry out no such decision-making.
9.9 How to exercise your rights
Email contact@thesislock.com. We may ask you to verify your identity before acting, to make sure we do not disclose your data to someone else.
We will respond within one month of receiving your request, as required by Article 12(3) GDPR. Where a request is complex or where we have received a number of requests, we may extend this by up to two further months, and we will tell you within the first month if we do, explaining why.
9.10 Right to complain
If you believe we have handled your personal data unlawfully, you have the right to lodge a complaint with a supervisory authority.
Romania — Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, 010336, Bucharest, Romania
Website: dataprotection.ro
You may alternatively complain to the supervisory authority in your EU country of residence or place of work. You also have the right to an effective judicial remedy.
We would appreciate the chance to address your concern first, but you are under no obligation to contact us before complaining.
10. Data Retention
We keep personal data only as long as necessary for the purpose it was collected for.
| Data | Retention period |
|---|---|
| Account data and content | For as long as your Account is active |
| All Account data and content, on deletion | Hard-deleted immediately on account deletion; residual copies in encrypted backups are overwritten in the ordinary backup cycle, within 30 days |
| Technical and error logs | Up to 90 days, then deleted or anonymised |
| Support correspondence | Up to 24 months from the last message |
| Transaction and tax records | Retained for the period required by Romanian tax and accounting law — currently 10 years — held in the first instance by Lemon Squeezy as Merchant of Record |
| Records needed for a live or anticipated legal claim | Until the claim and any appeal period is concluded |
Inactive accounts.We do not currently delete accounts for inactivity. If we introduce such a policy, we will give at least 60 days' notice by email before any account is affected.
Anonymised data. We may retain aggregated or anonymised data that cannot be linked back to you, for statistical purposes. This is no longer personal data and is not subject to the retention limits above.
11. Security
We apply technical and organisational measures appropriate to the risk, including:
- Encryption in transit (TLS) for all connections, and encryption at rest for stored data via our database provider;
- Row-Level Securitypolicies enforced at the database layer, so that a user's records are inaccessible to any other user even in the event of an application-layer fault. These policies have been audited directly against the live database;
- Password hashing — passwords are never stored in readable form;
- Re-verification of your password before permanently destructive operations such as account deletion;
- Cryptographic signature verification on all incoming payment webhooks, with replay protection and idempotency;
- Timing-safe comparison for security tokens;
- Security response headers and suppression of raw internal error messages to the browser;
- Access limitation — administrative access to production systems is limited to the operator alone.
No system is perfectly secure. We cannot and do not guarantee absolute security. You are responsible for keeping your own credentials confidential and for using a strong, unique password.
11.1 Data breach notification
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ANSPDCP without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by Article 33 GDPR. Where the breach is likely to result in a high risk to you, we will notify you directly and without undue delay under Article 34 GDPR, describing what happened, the likely consequences, and what we are doing about it.
12. Cookies and Similar Technologies
ThesisLock uses only strictly necessary cookies. We use no analytics cookies, no advertising cookies, no tracking pixels, no session recording, and no third-party marketing tags.
| Cookie / storage | Purpose | Type |
|---|---|---|
| Supabase authentication tokens | Keep you signed in and maintain your session securely | Strictly necessary |
| Session state | Preserve interface state within a session | Strictly necessary |
Because these cookies are strictly necessary to deliver a service you have explicitly requested, they are exempt from the consent requirement under Article 5(3) of Directive 2002/58/EC (the ePrivacy Directive) and Romanian Law no. 506/2004. This is why you do not see a cookie consent banner.
You can block or delete cookies in your browser settings, but the Service will not function without the authentication cookies.
If we ever introduce analytics or marketing cookies, we will update this Policy and obtain your prior, freely given, specific, informed, and unambiguous consent through a consent mechanism before any such cookie is set.
13. Children
The Service is not directed at, and may not be used by, anyone under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we hold personal data of a person under 18, we will delete it and close the Account without delay. If you believe a child has provided us with personal data, contact contact@thesislock.com.
14. Third-Party Links
The Service may contain links to third-party websites, including source material, filings, and news articles. We are not responsible for the privacy practices or content of those sites. This Policy applies only to ThesisLock.
15. Changes to This Policy
We may update this Policy from time to time.
- Non-material changes(clarifications, corrections, formatting) take effect on publication, and we will update the "Last updated" date.
- Material changes — including any new purpose of processing, any new category of data collected, any change of legal basis, or the introduction of non-essential cookies — will be notified to you by email to the address on your Account at least 30 days before they take effect, so that you can review them and, if you wish, delete your Account before they apply.
Previous versions of this Policy are available on request.
16. Contact
For any question, request, or complaint concerning your personal data:
Email: contact@thesislock.com
Web: https://thesislock.com
Annex A — Sub-Processors
Each of the following processes personal data on our behalf under an Article 28 GDPR data processing agreement.
| Sub-processor | Function | Personal data processed | Primary location |
|---|---|---|---|
| Supabase, Inc. | Database, authentication, storage | Account data, all content you create | United States / EU regions |
| Vercel, Inc. | Application hosting, edge delivery | Request logs, IP address (transient) | United States / global edge |
| Anthropic PBC | AI processing for claim review and news summarisation | Relevant Thesis/Claim text and source excerpts only | United States |
| Lemon Squeezy LLC | Merchant of Record, payment processing, invoicing, tax | Name, billing details, card data (held by them, never by us), email | United States |
| Alpaca Securities LLC / Alpaca Markets | Market data, news, ticker validation | Ticker symbols only — no personal data | United States |
| earningscalls.dev | Earnings call transcripts | Ticker and company identifiers only — no personal data | United States |
| ImprovMX | Inbound email forwarding for contact@thesislock.com | Content and sender address of email you send us | European Union |
| Google (Gmail) | Receipt and storage of forwarded support email | Content and sender address of email you send us | United States / EU |
We will update this Annex when we add, remove, or replace a sub-processor. Where a change materially affects the processing of your personal data, we will notify you in accordance with clause 15.
This Policy is provided in English. A Romanian translation may be made available for convenience; in the event of any conflict, the English version prevails, save where mandatory Romanian law requires otherwise.