Skip to content

Privacy Policy

Last updated 2026-09-25 · Provided in English only

This Privacy Policy explains how the Mavori team ("Mavori", "we", "us") handles personal information when you use the Mavori web and mobile applications and any related services (the "Service"). This policy covers the same account across the website and mobile apps; particular features may differ by platform.

1. Information we collect

We collect only what we need to operate the Service:

  • Waitlist email — if you join the waitlist before you have an account, we store the email address you submit so we can notify you when access opens. You can ask us to remove it at any time.
  • Account information you provide when you sign up — typically an email address and a password hash, or, if you sign in with Google, Apple, or GitHub, the basic profile information that provider returns (name, email, avatar URL, and a stable user ID).
  • Authentication and session data, including login timestamps, IP address, and the device or browser user-agent. This is standard auth telemetry used to keep your account secure and to debug sign-in failures.
  • Content you submit while using the Service — for example, the tickers you search for and the questions you ask the in-app AI assistant. Your AI chat turns (prompts and assistant replies) are stored against your account so the conversation persists across sessions.
  • Files you choose to attach to a conversation — images (including pasted screenshots) and documents. We store them against your account and pass their contents to the AI model so it can answer questions about them. Only files you explicitly attach are collected.
  • Portfolio information you enter, including manually recorded accounts, cash and positions, paper-account activity, and saved watchlists. This information is associated with your account so it can sync across devices.
  • If you choose to connect a brokerage or financial account where that feature is available, we access the account and position data returned under your authorization — such as balances, holdings, and order status. Depending on the broker, the connection may use OAuth, a trusted account aggregator, or API credentials you supply. We store connection credentials and tokens in protected server storage. Previously synced portfolio data may remain in your account and be visible on a platform that does not offer new broker connections. You can disconnect a connection where the feature is available.
  • If you place orders through the Service, we keep a record of each order, its approval, and the execution status your broker reports. This record powers your trade log and lets you (and we) reconstruct what the agent did on your behalf.
  • If you enable push notifications, we collect a device push token and your notification preferences so we can deliver the notifications you request. Your device and the push delivery services also process the notification payload.
  • Subscription and purchase information, such as the product, purchase or transaction identifier, subscription status, and entitlement, so we can provide paid features and reconcile purchases. We do not receive your full payment-card number.
  • Product-analytics events about how you use the Service — pages viewed, features used, and agent runs — tied to a pseudonymous identifier once you sign in. The signed-in web app can also record a masked session replay showing page layout and interaction locations; on-screen text, form values, and images are masked or omitted. Native mobile apps do not record session replay. You can opt out in Settings (see §7). We also collect error reports and performance information to diagnose failures.

2. Information we do not collect

  • Full payment-card numbers — web payments are handled by Stripe, and purchases made through a mobile store are handled by Apple or Google.
  • Brokerage login passwords for OAuth or aggregator connections. For brokers that use API credentials instead, we receive and protect the API key or secret you submit; those are separate from your brokerage login password.
  • Precise device location, contacts, microphone, or camera input. We do not browse your photo library or device files — we receive only the individual files you choose to attach to a conversation.

3. How we use information

We use the information above to:

  • Authenticate you, keep you signed in, and recover your account.
  • Render the research reports you request and remember which tickers you have viewed.
  • Generate and persist AI assistant responses about loaded report data.
  • Keep manually entered and paper portfolios available across your devices and, if you choose to link an account where supported, refresh and display its data.
  • Route the orders you approve to your linked brokerage and keep an accurate record of that activity.
  • Process subscription payments and meter usage against your plan's allowance.
  • Deliver notifications you enable and honor your notification settings.
  • Detect and fix bugs, monitor service health, and protect against abuse.
  • Comply with legal obligations and enforce our Terms of Service.

We do not sell your personal information or share it for cross-site advertising. We do not use your content to train a Mavori model. AI providers process the content needed to answer your request under their own terms, which differ by provider and may permit them to improve their services. See §4 and §8.

4. Third-party processors

We use service providers to operate the Service. The categories of data they receive and the reasons for sharing it are described below. We expect providers acting on our behalf to protect the data they handle under their agreements with us. Providers that act independently, such as app stores and sign-in providers, also have their own privacy terms.

  • Supabase (authentication, database, edge functions, file storage) — stores your account, sessions, and AI chat history.
  • Sign-in providers (Google, Apple, GitHub) — handle OAuth authentication when you choose those options. We receive only the profile fields you authorize.
  • Stripe (web billing) — processes web subscription payments and usage-credit purchases. Stripe handles your card details directly; we keep the customer reference, subscription status, and purchase history needed to manage billing.
  • Apple App Store and Google Play (mobile billing) — process purchases made in their respective apps. We receive transaction and entitlement information to verify and deliver purchases; your payment method is handled by the store.
  • Brokerages and account aggregators (your chosen broker, or an aggregator such as SnapTrade) — when you connect an account where supported, they process your authorization and return account, position, and order-status data. If you approve an order through a supported broker connection, the broker receives its details.
  • Market and financial data vendors (Financial Modeling Prep, the U.S. SEC EDGAR system, and other market data providers) — these are called server-side to fetch data about public companies. Personal information is not sent to them; only the public ticker symbol or filing identifier is.
  • Large-language-model providers (e.g. DeepSeek, Google Gemini, Moonshot/Kimi, Zhipu, Anthropic, or comparable vendors) — receive your prompt, attachments, and relevant context needed to answer, which may include holdings, transactions, watchlists, trading preferences, and saved memories. The app asks for consent before sending this information to third-party AI providers on mobile. Providers operate under their own terms; some are outside the United States and some may use API content to improve their services. The model handling a conversation is shown in the composer's model picker, and you can change it.
  • Error and performance monitoring (e.g. Sentry) — receives error reports, stack traces, and diagnostic metadata to help us fix bugs. We reduce direct identifiers in server reports, but diagnostics can contain technical information about a request or device.
  • Product analytics (PostHog, hosted in the United States) — receives pseudonymous usage events to help us understand and improve the product. Automatic element capture is off in the signed-in product. On web, session replay can record page layout, clicks, scrolling, and navigation, with signed-in text, entered values, and images masked or omitted. Native mobile apps send selected usage events but do not record replay. On public marketing pages, replay may include page text, while form inputs remain masked. Visitors from the EU, EEA, and UK are excluded from this processor by default, and anyone can opt out (see §7).
  • Hosting and CDN providers (e.g. Cloudflare) — serve the static web build and proxy API traffic.
  • Push delivery providers (Expo and the Apple or Google push service for your device) — receive the device token and notification content needed to deliver a notification you enabled.

5. Cookies and local storage

On the web, we use first-party cookies and browser storage to keep you signed in and remember preferences such as theme. On mobile, authentication sessions use device secure storage; non-secret preferences and recent items may use app-local storage. We do not use third-party advertising cookies or cross-site trackers.

If you reach our marketing site by clicking an ad, that platform appends a click identifier to the link. We store it in your browser and send it with your waitlist signup so we can tell which ad brought you here; it is not used to build a profile of you and is not shared onward. In the EU, EEA, and UK we ask your permission before storing it, and if you decline it is discarded without ever leaving your browser. Everywhere else you can clear it by clearing this site's storage in your browser.

6. Data retention

We retain account data while your account is active. You can delete individual conversations. When you delete your account, we remove the account and associated app data, subject to records we must keep for legal, tax, accounting, dispute, fraud-prevention, or audit reasons. These can include billing and order records. Deleting the app from a device does not delete cloud data; the account-deletion path below does. Operational logs and error reports follow the retention settings of the services that hold them; contact us for details about a specific record.

7. Your rights and account deletion

Depending on where you live, you may have the right to access, correct, export, or delete your personal information, to object to certain processing, and to withdraw consent. To exercise any of these rights, email us at hello@mavori.ai. We will respond within a reasonable timeframe and may need to verify your identity before making changes.

You can opt out of product analytics at any time from Settings → Security & Privacy. On the web we also honor Global Privacy Control and the older Do-Not-Track signal: if your browser sends either one, analytics never start.

To delete your Mavori account and its associated data, open Settings → Security & Privacy → Delete account in the app or web app. If you cannot access your account or have uninstalled the app, request deletion by emailing hello@mavori.ai. You do not need to reinstall the app. We may verify that you own the account. When you delete your account we remove your authentication record and chat history. Erasure of your pseudonymous analytics profile may require additional processing; contact us at the email above about a pending deletion request. Anonymized error telemetry and aggregated usage counts may persist.

8. International transfers

Mavori is operated from the United States, and your account, chat history, and portfolio data are stored there. Some of the vendors listed in §4 operate elsewhere, so information sent to them is processed outside the United States. In particular, the prompts and attachments you send to the AI assistant are processed by the provider serving the model you are using, which may be located in Singapore or mainland China. These countries have data-protection laws that differ from those of the United States and of your home country.

9. Children

The Service is not directed to children under 16 and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact hello@mavori.ai and we will delete it.

10. Security

We use industry-standard safeguards — TLS in transit, encrypted storage at rest, role-based database access, and short-lived authentication tokens — to protect personal information. No system is perfectly secure; if you become aware of a vulnerability, please report it to hello@mavori.ai.

11. Changes to this policy

We may update this Privacy Policy as the Service evolves. When we do, we will update the "Last updated" date above and, for material changes, surface a notice in-app or by email.

12. Contact

Questions or requests related to this Privacy Policy can be sent to hello@mavori.ai.