Who is responsible for your data
Finctual, the service available at finctual.com, is the controller for the processing described in this notice. Questions and privacy requests can be sent to info@finctual.com.
When another website or platform is the original source of content, that platform remains separately responsible for its own processing.
Who and what this notice covers
This notice covers two main groups: people who create or use a Finctual account, and financial-content creators whose publicly available content is discovered or graded by Finctual.
Account and profile data
Name, email address, immutable account identifier, authentication and MFA status, chosen display name, username, location, market focus, biography and a selected or uploaded profile picture.
Saved activity
Watchlists, trade-journal entries, grading jobs, discovery searches, creator selections, retention settings and related timestamps or status information.
Public creator data
Platform handles, display names, biographies, avatars, follower and engagement information, public posts, captions, audio-derived transcripts, publication dates and source links.
Claims and scores
Assets, trade direction, targets, time horizons, price outcomes, ROI, grades, Elo and trust ratings, originality or similarity indicators and explanations generated from public calls.
Technical and security data
Session records, truncated or pseudonymous network identifiers used for rate limiting, request timing, errors and operational logs needed to secure and run the service.
Information you submit
Video or post URLs, creator handles, pasted claim text, discovery keywords and regions, requested result limits, support messages and privacy-request correspondence.
What we do not collect through the current product: Apart from an optional profile picture, Finctual does not ask users to upload media files, connect brokerage accounts, or provide payment-card details. Passwords are handled by Amazon Cognito and are not stored in Finctual's application database.
Why we use data and our legal bases
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and secure an account; provide profiles, watchlists, journals, exports, grading and discovery. | Account, profile, submitted and saved-activity data. | Performance of our contract with the account holder. |
| Find public financial claims, measure their market outcome, build historical scorecards and identify similar calls. | Public creator content, source metadata, market data and derived scores. | Our legitimate interests in transparent, evidence-based review of public financial commentary. We limit this to relevant public content, show sources where available, and accept correction, objection and review requests. |
| Prevent abuse, enforce rate limits, investigate errors and keep the service reliable. | Technical, security and limited account data. | Our legitimate interests in protecting Finctual, its users and the integrity of its results. |
| Respond to support, privacy and legal requests. | Contact details, correspondence and relevant records. | Our legitimate interests in responding, and compliance with legal obligations where applicable. |
| Use optional non-essential cookies or send marketing in the future. | Only the information described when the choice is offered. | Consent. Finctual does not currently use advertising or analytics cookies. |
You do not have to create an account, but the private profile, watchlist, history, journal and data-control features cannot work without the requested account information. Required form fields are marked in the interface.
Where the data comes from
- Directly from you when you register, edit a profile, submit a URL or handle, search, save an item, contact us, or set a retention choice.
- Public platforms and public web sources, currently including TikTok, Instagram, YouTube, X and StockTwits.
- Service providers that retrieve public platform information on Finctual's behalf, including ScrapeCreators and getXAPI.
- Market-data sources, including Yahoo Finance and CoinGecko, used to test a public trade call against subsequent prices.
- Finctual's own analysis, which derives claims, grades, performance, ROI, rankings, similarity and originality information from those inputs.
If you are a graded creator, Finctual may hold information about you even if you have never created a Finctual account. The source is the public profile or content linked from the scorecard, or one of the retrieval providers above.
How automated grading works
Finctual uses automated systems to turn public financial commentary into a testable claim. The system identifies the asset, buy or sell direction, target and time horizon; compares the claim with market prices and relevant benchmarks; then calculates measures such as direction accuracy, target result, drawdown, ROI, a letter grade, rating changes and similarity to other calls. Generative AI may help extract a claim or explain a result.
These outputs are designed for informational review of public commentary. They are not used by Finctual to make decisions about credit, employment, insurance, access to essential services, or other decisions that produce legal or similarly significant effects. Automated extraction can be wrong. Account holders and graded creators can ask us to review, correct or explain an output by emailing info@finctual.com with the source link and disputed result.
Optional profile-picture uploads are checked automatically before storage. Amazon Rekognition looks for inappropriate visual content and reads visible text; Finctual then applies a profanity policy to that detected text. Images that trigger the policy are rejected and are not stored. Automated moderation can make mistakes, so users can choose a supplied Finctual avatar instead.
International transfers
Finctual's primary application data is hosted in AWS's EU (Ireland) region. Some providers named above operate in the United States or other countries outside the European Economic Area, so a requested platform retrieval or provider support operation may involve an international transfer.
Where EU data-protection law requires a transfer safeguard, processing is handled under the applicable provider terms and lawful mechanism, such as an adequacy decision or the European Commission's Standard Contractual Clauses. AWS's Data Processing Addendum includes transfer safeguards for AWS services. Contact us if you want information about the safeguard applicable to a particular transfer.
How long we keep data
We keep information only for the purpose described, taking account of account choices, security, dispute resolution and legal requirements.
| Record | Typical Finctual retention |
|---|---|
| Account, private profile, journal and watchlist | Until you remove an item or delete the account, subject to a short period needed to complete deletion and any record we must keep by law. |
| Uploaded profile picture | Until you replace it, select a supplied avatar, or delete the account. Images rejected by automated moderation are not stored. |
| Saved discovery and grading job history | 7, 30 or 90 days, according to the account setting. The default is 30 days. You can clear this history immediately. |
| Temporary transcription media | Removed by Finctual after processing; an S3 lifecycle rule provides a one-day deletion fallback. The temporary AWS transcription job is also deleted after use. |
| Pseudonymous rate-limit records | Normally less than two hours. |
| Authentication cookies | Access cookie about 1 hour; refresh cookie up to 30 days; authentication challenge about 5 minutes. The maintenance administrator cookie can last up to 7 days. |
| Public claims, creator profiles and historical scorecards | Retained while reasonably needed to provide historical accountability, comparisons and accurate ratings. There is no current fixed expiry. We review a record when it is no longer needed or when a valid correction, objection or erasure request applies. |
| Operational and security logs | For the period configured in the relevant AWS service and as needed to diagnose errors, protect the service and meet legal obligations. |
| Support and privacy correspondence | For as long as needed to answer the request, demonstrate compliance and handle related disputes. |
External providers can retain their own request, response, security or billing records under their policies. For example, ScrapeCreators states that API responses and usage logs may be retained indefinitely. Finctual's account deletion cannot delete a provider's independent operational records or the original content on a social platform.
Your choices and data-protection rights
Depending on the law and circumstances, you may ask for access to your data, correction, deletion, restriction, portability, or object to processing based on legitimate interests. Where processing relies on consent, you can withdraw it without affecting earlier lawful processing. You can also ask for information about automated analysis and contest an incorrect score.
Open Profile → Privacy center to download account data, set saved-history retention, clear history, or delete the account and its private data.
Email info@finctual.com. Include the relevant platform handle or source link and the right you want to exercise. Do not send a password or authenticator code.
We may need to verify identity before acting. Rights are not absolute: for example, we may retain information needed for legal claims, comply with a legal duty, or refuse an unfounded or excessive request with an explanation. Account deletion removes private account data but does not automatically erase original social-platform content or every global scorecard derived from public material; requests concerning those records are assessed separately.
You may complain to the Office of the Commissioner for Personal Data Protection in Cyprus, or the supervisory authority where you live or work. We would appreciate the chance to address the concern first.
Security, children and changes
Security
Finctual uses measures including HTTPS, access-controlled AWS resources, Amazon Cognito authentication, optional authenticator-app MFA, HttpOnly session cookies, rate limiting, validation, and separation of temporary media from long-lived records. No online service can guarantee absolute security. If you believe an account or record is at risk, contact us promptly.
Children
Finctual is not designed to collect children's private account information. Public financial content may occasionally include a young person; a parent, guardian or affected person can contact us to request review.
Changes to this notice
We will update this page when processing, providers or legal requirements materially change. The effective date at the top shows when the current version applies. Where a change materially affects account holders, we will provide an additional notice through an appropriate channel.
Ask for a privacy receipt.
Tell us which account, source, creator profile or scorecard your request concerns.