Privacy Policy
This Privacy Policy explains how Argos Insight AI LLC, a Delaware limited liability company qualified to do business in California (doing business as “Argos AI”) (“Argos”, “we”, “us”) collects, uses, and protects personal information when you use argosinsight.ai, argospredict.com, and the related dashboards, APIs, and emails (the “Services”). Contact for anything in this policy: [email protected].
The short version: we collect the minimum needed to run a subscription service — your email, name, and password hash for your account; subscription metadata via Stripe; security logs; and cookieless, first-party product analytics with no advertising identifiers. We do not sell or share personal information for advertising, we do not run third-party ad or tracking pixels, and we do not track you across other sites.
1. Information we collect
| Category | What | Why |
|---|---|---|
| Account | Email address, display name, password (stored only as a salted PBKDF2 hash — we cannot read it), subscription tier, optional MFA secrets (encrypted) | Create and secure your account; provide tiered features |
| Billing | Processed by Stripe: payment method and billing details go to Stripe directly. We store your Stripe customer ID and subscription status — never full card numbers | Subscription billing |
| Security logs | An append-only audit log of authentication and account events (login attempts, password resets, admin actions) including IP address and a coarse browser/OS family | Account security, abuse prevention, incident response |
| Product analytics | Cookieless, first-party events (page/panel views, feature usage) keyed to a random identifier stored in your browser’s localStorage; user agents are coarsened to a browser/OS family; referrers are reduced to host-only; no advertising IDs, no cross-site tracking | Understand which features are used; improve the product |
| API usage | API-key usage records (request counts, rate/quota accounting); keys themselves are stored only as SHA-256 hashes | Operate and meter the API |
| Alerts & preferences | Alert rules and delivery targets you configure (e.g. a destination email or webhook URL), notification preferences | Deliver the notifications you asked for |
| Correspondence | Emails you send us (e.g. access requests, support) | Respond to you |
We do not knowingly collect information from anyone under 18, and the Services are not directed to children.
2. What we do not do
- We do not sell or share personal information for cross-context behavioral advertising (no “sale” or “share” as defined by the California Consumer Privacy Act).
- We do not use third-party advertising or social-media tracking pixels.
- We do not set third-party cookies. Our only cookie is the essential, signed session cookie that keeps you logged in.
- We do not make automated decisions about you with legal or similarly significant effects.
3. Cookies and local storage
We use one essential session cookie (HttpOnly, Secure) to keep you signed in. During login and signup, our bot-protection provider (Cloudflare Turnstile) may set an essential security cookie as part of its challenge. We use browser localStorage for product preferences (e.g. theme, dismissed banners) and for a random, first-party analytics identifier that is not linked to advertising networks and does not follow you to other sites. Clearing your browser storage resets these.
4. How we use information
To provide and secure the Services; authenticate you; bill subscriptions; deliver the alerts and emails you request; monitor for abuse and outages; measure feature usage in aggregate; comply with law; and enforce our Terms. Where the GDPR or similar laws apply, our legal bases are: performance of our contract with you (account, billing, features), legitimate interests (security, abuse prevention, product analytics as configured above), consent where required (which you may withdraw), and legal obligations.
5. Who we share information with
Only service providers (processors) that run the Services, under their own security and confidentiality obligations:
| Provider | Purpose |
|---|---|
| Cloudflare | Hosting, edge network, caching |
| Neon | Database (system of record) |
| Stripe | Payment processing |
| Resend | Transactional and notification email delivery |
We may also disclose information if required by law or legal process, to protect the rights, safety, or property of Argos or others, or as part of a merger, acquisition, or sale of assets (with notice where required). We have never sold personal information.
6. Data retention
Account data is kept for the life of your account. Security audit logs are retained for up to 2 years. Product-analytics events are retained for 180 days. Alert/notification delivery records are retained for up to 90 days. Cached market data is not personal data. When you delete your account, personal data is removed under a documented erasure procedure (account row and linked records deleted; security log entries may be retained for the remainder of their window where required for security or legal purposes).
7. Your rights
Depending on where you live (including California and the EEA/UK), you may have rights to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to withdraw consent. To exercise any of these, email [email protected] from the address on your account; we will verify and respond within the time required by law. We do not discriminate against you for exercising privacy rights. California residents: we do not sell or share personal information, so there is nothing to opt out of; we honor this policy regardless of any Global Privacy Control signal. EEA/UK residents: you may also lodge a complaint with your local supervisory authority.
8. Security
We use industry-standard safeguards: TLS encryption in transit; encryption at rest via our infrastructure providers; salted PBKDF2 password hashing; encrypted MFA secrets; hashed API keys and tokens; least-privilege access; append-only audit logging; and continuous monitoring. No system is perfectly secure; if we learn of a breach affecting your personal information we will notify you as required by law. Security researchers: see the responsible-disclosure policy in our repository’s SECURITY.md.
9. International transfers
The Services are operated from the United States and information is processed in the U.S. by the providers listed above. If you use the Services from outside the U.S., you understand your information will be processed in the U.S.
10. Changes to this policy
We may update this policy as the Services evolve. Material changes will be announced (for example by email or an in-product notice) before they take effect, and the “Last updated” date above always reflects the current version.
11. Contact
Argos Insight AI LLC, a Delaware limited liability company qualified to do business in California (doing business as “Argos AI”)
Privacy and data requests: [email protected]