Privacy Policy
Sumalist is a private workspace for financial analysts and the people who consult them. This page explains what data we collect, how we use it, where it's stored, who can see it, and how to delete it.
1. What we collect
- Account details. Email, display name, company (optional), profile photo (optional), Apple Sign-in identifier when used.
- Chat content. Questions you ask, answers generated by analyst personas, replies between teammates in group chats, optional attachments.
- Research artifacts. PDFs you upload, emails ingested from a Microsoft Outlook folder you explicitly bind, and the LLM-extracted text + tags derived from them.
- Push notification token. The Apple Push Notification service device token, used solely to deliver notifications to your own device. Deleted on sign-out.
- Mailbox connection token. If you connect Microsoft Outlook, we store an encrypted OAuth refresh token used only to poll the folder you selected for new research emails.
- Operational logs. Audit log (who did what, for admin forensics), cost ledger (LLM spend per question), server access logs. No third-party analytics, no fingerprinting, no advertising trackers.
2. How we use it
Your data is used to operate the service. Specifically: to serve your chat history back to you, to answer your questions using analyst personas you have access to, to deliver push notifications, and to keep the analyst's persona current based on the research you ingest. We don't sell data, we don't share it with advertisers, and we don't use your chat content to train models for anyone outside your own tenant.
3. Where it lives
- Application database (PostgreSQL) + object store (MinIO) run inside an AWS EC2 instance in the EU (Frankfurt, eu-central-1).
- LLM inference is provided by Anthropic (Claude). Embeddings by Voyage AI. Both receive only the text needed to fulfil the specific request; neither retains your inputs to train their public models per their published policies.
- Apple Push Notification service delivers push messages to your device. Microsoft Graph delivers the contents of the Outlook folder you bound.
- Nightly encrypted backups in AWS S3 (same region) with a 365-day retention.
4. Who can see your data
Inside Sumalist, only the owner of an analyst can see its articles + persona. Subscribers and explicitly-shared users can ask the analyst questions and read its public answers, but can't edit or download the underlying source. Group chats are visible only to active members. The Sumalist operator (Roee Feingold) has admin access to all data for operational reasons and is the data controller for GDPR purposes.
5. How long we keep it
Indefinitely while your account is active. After you delete your account (Profile → Delete account), all attributable rows are hard-deleted from the database via cascade and the corresponding files are removed from the object store within 24 hours. Backups containing the data roll out over the 365-day backup retention window. Audit log + cost ledger rows survive with your user id anonymized; we never re-link them.
6. Your rights
- Access. You can download your full chat history via the API at any time.
- Delete. Profile → Delete account. Within the app. Irreversible.
- Correct. Profile → Edit profile. Or write to [email protected].
- Portability. Email us; we'll send a JSON export of everything tied to your account within 30 days.
7. Children
Sumalist is not intended for users under 16 and we do not knowingly collect data from minors.
8. Contact
Roee Feingold — [email protected].
Last updated: 2026-06-13.