LogicFourLegal ← Back to the site
Draft — not yet in force. This document is awaiting confirmation of the highlighted details and a review by our lawyers. It is published so it can be read and corrected, not relied upon.

LogicFour Privacy Policy

Last updated: TO CONFIRM: date

In short. We collect little: your Google sign-in details, the research you run, and a small set of product-usage events stored without your IP address. We do not run ads, do not sell data, and do not track you across the web. This policy lists everything we hold, why, for how long, and how to delete it.

Who is responsible

The data controller is TO CONFIRM: registered legal name, company code TO CONFIRM: registration number, registered address TO CONFIRM: registered address, Lithuania. Privacy enquiries: TO CONFIRM: contact address. You may complain to the Lithuanian supervisory authority, the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija), or to the authority in the EU country where you live.

What we collect and how long we keep it

CategoryWhat exactlyKept for
AccountEmail address, display name and profile picture URL, received from Google when you sign in, plus an internal account identifierUntil you delete your account, plus a 30-day recovery window
ResearchEach analysis you run: the ticker, the financial figures retrieved from SEC filings, the model's output, and any research notes or answers you type. Your answers are kept with the report they produced, because a verdict read without them is missing half of what made itUntil you delete the report or your account, plus a 30-day recovery window
Product analyticsUsage events, described below180 days
FeedbackYour message, your email address if signed in, and the page you were onTO CONFIRM: retention period for feedback
Failed analysesTicker, phase, model and error status — no user text90 days
Sign-in sessionsSession records7 days
Cost recordsCost and token counts per analysisKept as financial records TO CONFIRM: statutory accounting period
BackupsCopies of the above30 days
Server logsMay briefly contain IP addresses, for security and abuse preventionTO CONFIRM: log retention period

Sign-in is via Google only today. An email sign-in route exists in the code but is switched off; if we enable it, we will update this policy first.

Product analytics, in detail

Events come from a fixed list of names — page view, run started, report opened, phase opened, time spent on a phase, homework started, homework submitted, valuation requested, example opened, feedback opened, sign-in shown TO CONFIRM: complete event list. Each event stores the event name, your account identifier where signed in, a visit identifier that rotates each browser session, the page path, a run identifier, a phase number, a duration in milliseconds, and a small fixed metadata object. The browser cannot invent event names and cannot attach free text. No IP address is stored with these events.

What we deliberately do not collect

No mouse-movement or heatmap tracking. No session recording or replay. No keystroke logging. No cross-site tracking. No advertising identifiers. No data brokers. No profiles sold or shared for marketing. This is a design decision, not an oversight.

Why we process your data

PurposeLegal basis (GDPR Article 6)
Providing the service: your account, sign-in, running and storing your analyses, transactional emailContract, Article 6(1)(b)
Security, abuse prevention, error records and server logsLegitimate interests, Article 6(1)(f)
Product analytics, as described aboveLegitimate interests, Article 6(1)(f)
Keeping cost recordsLegal obligation, Article 6(1)(c)

We do not currently rely on consent for anything. If that changes, we will ask you first, and withdrawing consent will be as easy as giving it.

Who processes data for us

ProviderRoleWhat it receives
CloudflareHosting, storage, database, network security and DDoS protectionAll service data is stored on Cloudflare infrastructure
Google — Gemini APIRuns the analysisThe analysis prompt: the ticker, the company's public financial figures, and any research notes you type. We use a paid tier under which, per Google's terms, Google does not use this content to train its models
Google — Sign-InAuthentication onlyThe standard sign-in exchange
ResendTransactional emailYour email address and the content of sign-in links and service notices
SEC EDGAR and a public market-data sourceCompany filings and share pricesNothing. These are outbound requests only; no user data is sent to either

Do not put confidential or personal information into research notes. They are sent to the model provider as part of the analysis.

Who at LogicFour can see your reports

An administrator can open any report on the service. This is for support, for checking that the analysis is producing something worth reading, and for working out what went wrong when a run misbehaves.

Two things limit it. Every time an administrator opens a report belonging to someone else, that access is recorded — who looked, whose report, and when — and the record is kept. And a report includes the research notes you type into the homework boxes, so please do not put confidential or personal information there; the same warning applies as for the model provider below.

Nobody outside the company has this access.

International transfers

Cloudflare, Google and Resend process data partly outside the EEA, mainly in the United States. Transfers rely on the EU–US Data Privacy Framework where the provider is certified, and otherwise on Standard Contractual Clauses TO CONFIRM: transfer mechanism per provider. You can ask us for details.

Your rights and the controls that exist

In the product you can delete any individual report from the report list, delete your entire account and all associated data from account settings, and sign out, which invalidates your session.

Under the GDPR you can also ask us for access to your data, correction, erasure, restriction and portability, and you can object to processing based on legitimate interests. Write to TO CONFIRM: contact address. You can complain to the State Data Protection Inspectorate or your local supervisory authority.

The analysis makes judgements about companies, not about you. We make no automated decisions about you with legal or similarly significant effects.

What deletion actually does

Deleting a report or your account starts a 30-day recovery window, after which the data is removed. Backups are kept for 30 days, so deleted data leaves the backups within a further 30 days at most.

Children

The service is for adults 18 or over. We do not knowingly process children's data.

Changes

If this policy changes materially, we will update the date above and tell you in the product or by email.