Legal
Privacy Policy
Last updated 3 August 2026.
1. Controller
The controller of your personal data is Finance Foresight AI Kamil Szczepanik, ul. Wojska Polskiego 114/116/4, 91-743 Łódź, Poland. For any privacy question or to exercise your rights, contact [email protected].
2. What we collect
Account data (email, hashed password), content you submit (papers, research topics), usage and billing records, and a session cookie. We do not collect card details: payment data is handled by our payment provider.
3. Why and on what basis
To provide the Service and your account (performance of a contract), to take payment and keep records (legal obligation and contract), to send transactional email such as verification codes and Gap Alerts (contract and legitimate interest), and to keep the Service secure (legitimate interest).
3a. Visit measurement
We count page visits ourselves, on our own servers, to see which pages are used. No cookie is set and nothing is stored on your device. Visits are grouped under an identifier derived from your IP address and browser with a secret that changes every day and is never stored, so the same person cannot be recognised across two days and the records cannot be traced back to an address. We keep these counts for at most 400 days. Basis: legitimate interest in understanding how the Service is used.
4. AI processing and sub-processors
To produce reviews and explorations, the text you submit (paper content, topics) is sent to our AI provider Google (Gemini API) for processing. We also query Semantic Scholar and arXiv for literature search, and OpenAlex for venue matching, which means the title and abstract you enter there are sent to it. Payment processing and transactional email are handled by external providers. These act as processors / independent providers under their own terms.
5. International transfers
Some providers, for example Google, may process data outside the EEA. Where that happens we rely on appropriate safeguards such as Standard Contractual Clauses.
6. Retention
We keep account and content data while your account is active and as needed for legal, accounting and security purposes, then delete or anonymize it.
7. Your rights
Under the GDPR you can request access, rectification, erasure, restriction and portability, object to certain processing and withdraw consent. You may also lodge a complaint with the data protection authority in your EU country of residence. Email [email protected] to exercise any right.
8. Security
Passwords are stored hashed, sessions are signed, and access is restricted. No system is perfectly secure; report concerns to [email protected].
See also our Terms of Service and Cookie Policy.