The short version
We collect the account details you give us and the billing details needed to take payment. We use them to run the service — not to build advertising profiles. We do not run third-party analytics, advertising, or session-recording trackers. You can ask for a copy of your data or have it deleted at any time.
1.Who this covers
This policy explains how Prometheus Finance (“Prometheus”, “we”, “us”) handles personal information when you visit our website or use our platform (the “Service”). It applies to visitors, registered users and subscribers.
We are the controller of that personal information. It does not cover third-party sites we link to, which have their own policies.
2.What we collect
We collect only what we need to operate the Service.
Information you give us
| Account identity | Email address, and optionally your display name, first and last name, avatar image, and phone number. |
| Profile preferences | Country, city, timezone and preferred language, used to present dates, figures and content correctly. |
| Content you create | Watchlists, saved workspaces and similar items you build in the product. |
| Correspondence | Messages you send us for support or enquiries. |
Information created when you use the Service
| Authentication data | A user identifier issued by Amazon Cognito, our authentication provider, and session tokens stored in your browser to keep you signed in. |
| Subscription and billing records | Your plan, subscription status, renewal date, and the customer and subscription identifiers issued by Stripe. We do NOT store your card number, expiry, or security code — those go directly to Stripe. |
| Technical and security logs | Server logs generated when you make requests, which may include IP address, timestamps, requested URL, and browser user-agent. Used for security, abuse prevention, debugging and reliability. |
3.Why we use it
Under Canadian privacy law we rely on your consent, and, for users in the EU/UK, on the corresponding lawful bases noted in brackets.
- To provide the Service — create and authenticate your account, deliver the features you ask for, and save your watchlists and workspaces. [Performance of a contract]
- To take payment — manage subscriptions, process charges and renewals, and prevent payment fraud. [Performance of a contract; legal obligation]
- To keep the Service secure and working — detect abuse, enforce usage limits, diagnose faults, and protect our infrastructure and our users. [Legitimate interests]
- To communicate with you — send service and billing notices, respond to support requests, and (only if you opt in) send product updates. [Performance of a contract; consent for marketing]
- To meet legal obligations — including tax, accounting and lawful requests. [Legal obligation]
You can withdraw consent to marketing at any time, without affecting the Service itself.
4.What we don't do
To be specific, rather than merely reassuring:
- We do not sell your personal information, and we never have.
- We do not share it with advertisers or data brokers, and we do not use it for behavioural advertising.
- We do not run third-party analytics, advertising pixels, or session-recording tools on the Service.
- We do not use your personal information, your watchlists, or your workspaces to train machine-learning models.
If this ever changes, we will update this page and, where the law requires it, ask for your consent first.
7.Company data is not personal data
Most of what Prometheus analyses is public corporate disclosure — regulatory filings, earnings-call transcripts, market prices and public economic statistics. This material is about companies, not about you.
That material can contain the names and statements of company executives, spoken in their professional capacity on public earnings calls and quoted verbatim with attribution. We process this limited professional information to analyse and evidence what public companies have said, which is a legitimate interest in research and financial transparency. It is drawn from sources those individuals and their companies published publicly. If you are such an individual and wish to raise a concern, contact us at privacy@prometheus.finance.
8.Where your data is stored
Our infrastructure is hosted with providers whose facilities are located in [REGION — e.g. the United States and Canada]. Your personal information may therefore be stored and processed outside your province or country, and may be accessible to courts and law enforcement in those jurisdictions under their local laws.
Where we transfer personal information out of the EEA or the UK, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum.
9.How long we keep it
- Account and profile data — for as long as your account is open, and then deleted or anonymised within 90 days of closure.
- Content you create (watchlists, workspaces) — deleted with your account.
- Billing and tax records — retained for as long as required by tax and accounting law (typically six to seven years), even after account closure.
- Security and server logs — retained for a short period for security and debugging, then rotated out.
10.Your rights
You have the right to:
- ask what personal information we hold about you and get a copy of it;
- have inaccurate information corrected;
- have your information deleted;
- withdraw consent, including to marketing, at any time;
- ask us to restrict or object to certain processing; and
- receive your data in a portable, machine-readable format.
To exercise any of these, email privacy@prometheus.finance. We will respond within 30 days. We may need to verify your identity first. We will not charge you or degrade your service for exercising your rights.
If you are in the EU or UK, you also have the right to lodge a complaint with your data protection authority. If you are in Canada, you may complain to the Office of the Privacy Commissioner of Canada — but we would appreciate the chance to resolve it with you first.
11.Security
We protect personal information with measures appropriate to its sensitivity, including encryption in transit (HTTPS/TLS), encryption at rest for our databases and object storage, managed authentication through Amazon Cognito, and access controls that limit which personnel can reach production data.
No system is perfectly secure, and we cannot guarantee absolute security. If a breach occurs that poses a real risk of significant harm, we will notify you and the relevant regulator as the law requires.
12.Children
The Service is not directed at anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has given us personal information, contact us and we will delete it.
13.Changes
We may update this policy as the Service evolves. If we make a material change — for example, adding a new category of data, a new sub-processor, or a new purpose — we will update the “Effective” date and take reasonable steps to notify you, such as by email or an in-product notice. Where the law requires it, we will ask for your consent.
14.Contact and complaints
Privacy questions, access requests and complaints go to privacy@prometheus.finance, or by post to our Privacy Officer at Prometheus Finance, 1050 King St W, Toronto, Ontario, Canada.