Privacy Policy
Last updated: October 5, 2026
1. Introduction
Sprint Zero UG (haftungsbeschränkt) ("FilingIQ," "we," "us," or "our"), the company behind the FilingIQ brand, is committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use the FilingIQ platform, website, and related services (the "Service").
We process personal data in compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable German data protection laws. By using the Service, you acknowledge that you have read and understood this Privacy Policy.
This Privacy Policy is also available in German at filingiq.io/de/datenschutz.
It applies to our website filingiq.io (including our blog), our web application at app.filingiq.io, our API at api.filingiq.io and our API documentation at docs.filingiq.io. Section 12 describes the personal data of people who appear in the public filings we analyse and who are not our users.
2. Data Controller
The data controller responsible for the processing of your personal data is:
Sprint Zero UG (haftungsbeschränkt)
Represented by its managing directors: Niklas Alexander Feldmann, Thomas Johannes Kraaibeek
Wienburgstraße 23, 48147 Münster, Germany
legal@filingiq.io
For all privacy-related inquiries, please contact us at legal@filingiq.io.
3. Data We Collect
We collect the following categories of personal data:
3.1 Account Data
When you create an account, we collect:
- Email address
- Hashed password credentials (we never store plaintext passwords). If you create your account with Google instead, we hold no password for you at all.
- Account creation date and last login timestamp
- If you sign in with Google: the identifier Google uses for your account with us, your name and the address of your Google profile picture, as described in Section 6.
- When your email address was verified.
- Where your sign-up came from, recorded once when the account is created: the campaign parameters of the link you followed (utm_source, utm_medium, utm_campaign, utm_content, utm_term), which sign-up button you used and on which page of filingiq.io, and the domain of the website that sent you, never its full address, and whether you signed up with email and password or with Google. Added October 2026.
- Your answers to the cookie banner while you are signed in, or reported when you next sign in: whether you accepted or declined analytics, which version of the wording you were shown and in which language, and when you decided. We keep this to be able to show what you agreed to, and to know whether our servers may send the analytics events described in Section 6. Added October 2026.
3.2 Usage Data
When you use the Service (web application), we automatically collect:
- IP address
- Browser type and version
- Device type and operating system
- Pages visited and features used
- Date and time of access
- Referring website or source
For each account we also record the days on which it used the Service, signed in to the web application or through one of its API keys: the date only (in UTC), without the time, the pages or the IP address. We use these days to count how many accounts are active per day, week and month. The days of an account are deleted after 90 days; we keep only the daily totals, which identify no one. Nothing is read from or stored on your device for this, and it does not depend on your answer to the cookie banner.
On our landing page (filingiq.io) we use a self-hosted instance of Plausible Analytics for privacy-friendly traffic measurement. Plausible does not use cookies, does not store anything on your device, and does not collect personal identifiers. The data processed (page views, referrer, country, browser and device type, and clicks on sign-up buttons together with the button and page) is aggregated and stored on EU-based infrastructure operated by us. No data is transmitted to third-party analytics providers from the landing page. When you click a sign-up button, the link itself carries the name of the button and the page, plus any campaign parameters in the address of the page you are on and the domain of the site that referred you; nothing is read from or stored on your device for this.
3.3 Financial Preferences
When you configure the Service, we store:
- Watchlist selections and ticker preferences
- Alert settings and notification preferences
- Custom filter and view configurations
3.4 Cookies and Storage on Your Device
Our landing page (filingiq.io) sets no cookies. Only if you switch the colour theme yourself does it keep that choice in your browser's localStorage (fiq-theme). In our web application (app.filingiq.io) we store the following on your device:
- The session cookie of our sign-in system (
better-auth.session_token, over HTTPS with the prefix__Secure-). It keeps you signed in for 7 days, is renewed once a day while you use the application, and is removed when you sign out. - If you sign in with Google, a short-lived cookie with the state of that sign-in, which is discarded once you land back with us.
- In localStorage: your answer to the cookie banner (
filingiq-consent,filingiq-consent-meta), your language (filingiq-language), your colour theme (theme), your table and score display settings (filingiq-table-preset,filingiq-show-cps-scores,filingiq-show-ifs-scores), whether you closed the getting-started checklist or the personalisation prompt, and your votes for planned features. These entries stay until you clear them in your browser. - Only after you accept the cookie banner: PostHog keeps an identifier for your browser in a cookie and in localStorage (names starting with
ph_), so that your visits can be linked (Section 6).
Everything except the PostHog entries is strictly necessary to provide the function you asked for, so it needs no consent (§ 25(2) No. 2 TDDDG). The PostHog entries are stored only with your consent (§ 25(1) TDDDG). Our Cookie Policy describes the same in more detail.
4. How We Use Your Data
We use the personal data we collect for the following purposes:
- Account management and authentication: To create and manage your account, verify your identity, and maintain account security.
- Service delivery and personalization: To provide, maintain, and improve the Service, including personalized features such as watchlists and alerts.
- Billing and subscription management: To process payments and manage subscriptions when these features are implemented in the future.
- Fraud prevention and security: To detect, prevent, and respond to security incidents, fraud, or other malicious activity.
- Service improvement and analytics: To analyze usage patterns, diagnose technical issues, and improve the Service.
5. Legal Basis for Processing
Under GDPR Article 6, we process your personal data based on the following legal grounds:
- Consent (Art. 6(1)(a)): Where you have given clear consent for us to process your personal data for specific purposes, such as product analytics and session recordings with PostHog in our web application, error reporting with Sentry in our web application, and the analytics events our servers send about your account (Section 6), or marketing communications. Where consent is the basis, you may withdraw it at any time. Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal (Art. 7(3) GDPR).
- Contract performance (Art. 6(1)(b)): Where processing is necessary for the performance of a contract with you, including account management and service delivery.
- Legitimate interests (Art. 6(1)(f)): Where processing is necessary for our legitimate interests, such as improving the Service, ensuring security, preventing fraud, measuring aggregate website traffic with our self-hosted Plausible Analytics instance, recording which campaign, page and button led to a sign-up, counting how many accounts use the Service per day, week and month from the days each account was active (Section 3.2), reporting errors and request timings of our API to Sentry, and analysing the public filings described in Section 12. These interests do not override your fundamental rights and freedoms; you may object at any time under Art. 21 GDPR.
You need to give us your email address to create an account: it is required for the contract, and without it we cannot open one. Everything else you give us is optional.
We do not make decisions about you based solely on automated processing, including profiling, within the meaning of Article 22 GDPR. Our scores rate securities transactions disclosed in public filings, not you.
6. Data Sharing
We do not sell your personal data to third parties. We may share limited data with the following categories of service providers, solely for the purposes described in this policy:
- Hosting (Hetzner, Germany): Our application servers, our database and its backups run on servers of Hetzner Online GmbH in a data centre in Germany. Hetzner provides the hardware and the network; everything stored on them, including your account data, therefore sits with Hetzner in Germany.
- Payment processor: When subscription billing is implemented, payment data will be processed by a third-party payment provider. We will not store full credit card numbers on our servers.
- Email service provider (MailerSend, EU): For transactional emails such as account verification, password resets, and service notifications. MailerSend is operated by MailerSend, Inc. and processes email content on EU-based infrastructure (ISO 27001 certified data center, Belgium). Data is processed under our Data Processing Agreement and Standard Contractual Clauses. Added April 2026, replacing Resend.
- Analytics (PostHog Cloud, EU): Our web application uses PostHog Cloud hosted on EU-based infrastructure for product analytics. When you are signed in, PostHog receives your account identifier, your email address, your name, your subscription tier, and your beta cohort, so that usage can be attributed to your account. It also receives the IP address your requests come from, the pages you visit, and the features you use; our PostHog project is set to discard IP addresses, so they are not kept with your events. With the same consent, PostHog records your sessions in the web application: it reconstructs the pages you see, including their text, together with your mouse movements, clicks, scrolling and window size, so that we can see how the application is used and where it fails. What you type into form fields is masked and not recorded. A recording also contains the messages your browser writes to its developer console and the timings of the network requests the page makes, without their content. From the same data PostHog derives heatmaps of clicks and scrolling, captures clicks and form submissions automatically (autocapture), and measures page performance (Web Vitals). Recordings are deleted automatically after 30 days. PostHog is not used on our landing page, and it is only initialised after you accept analytics cookies. If you accept, our servers also report events of your account to PostHog under your account identifier: your sign-up, with when it happened and where it came from (Section 3.1), when your email address was verified, the alerts and digests we deliver to you by email, in the app or on Telegram, webhooks you set up or replay and deliveries to them, the days on which you use the API, API keys you create or revoke, integrations you connect, and changes to your plan. These reports come from our servers, not from your browser, so they carry no IP address or device information of yours. Our servers send them only while your most recent answer to the cookie banner, which we store with your account, is to accept the current wording; declining, in the banner or later under Cookie preferences, stops them from the next event on. The one other report our servers make is a count of views of a shared signal card, with the card's identifier and the domain of the referring site, and nothing about the person viewing it. Data is processed by PostHog Inc. on EU-based infrastructure in accordance with their privacy policy and our Data Processing Agreement.
- Analytics (Plausible, self-hosted): Our landing page (filingiq.io) uses Plausible Analytics on infrastructure we self-host in the EU. Plausible does not use cookies, does not store data on your device, does not generate persistent identifiers, and does not track users across websites. Aggregate page-view data is processed on our own server and is never transmitted to a third party. No Data Processing Agreement is required because no third-party processor is involved.
- Error reporting (Sentry, EU): Our web application uses Sentry (Functional Software Inc., EU region) only after you accept the cookie banner; our API and background worker use it in any case. Both capture unhandled errors and exceptions so we can diagnose bugs quickly. Our API also sends Sentry the timings of a 10 % sample of its requests (traces), scrubbed in the same way, so we can find slow parts. Sentry receives your user ID, browser version, operating system, URL where the error occurred, and a stack trace. We do not send passwords, API keys, or other secrets to Sentry; the SDK is configured to scrub these fields automatically. Your email address, your username and your IP address are removed from the report before it is sent. Sentry data is hosted on EU-based infrastructure. Added April 2026.
- Application logging (Better Stack, EU): Our API and background worker send application logs to Better Stack (Better Stack s.r.o., EU ingestion endpoint) so we can diagnose faults. The logs record the HTTP method, the URL path without its query string, response status codes and timings, and error messages. They do not carry your account identifier. Authorisation headers, cookies, passwords and API tokens are stripped before a log line leaves our servers. So are email addresses, IP addresses and phone numbers: both where they appear as a named field, at any nesting depth, and where an address appears inside free text such as an error message. Log lines do not contain your email address or your IP address.
- Messaging integration (Telegram, third country): If you connect the optional Telegram integration, available on the Professional and Enterprise plans, we deliver your signal alerts to your Telegram chat through the Telegram Bot API. Telegram receives the identifier of that chat and the alert text: the ticker, the signal score and type, a one-line summary, the number of insiders, the market capitalization, and how long after the SEC release we sent it. For a congressional disclosure that summary names the Member of Congress, their chamber and party, whether they bought or sold, and the disclosed amount bracket. A link to the signal in our web application is attached as a button. When you connect, Telegram passes us the chat identifier together with your Telegram username, first name and language code, and we store those so we can address the chat later. Telegram is operated by Telegram Messenger Inc., registered in the British Virgin Islands, with group companies in Dubai. Neither jurisdiction is covered by a European Commission adequacy decision, and Telegram offers bot operators neither a data processing agreement nor Standard Contractual Clauses, so the only ground we have for this transfer is your explicit consent under Article 49(1)(a) GDPR. Before you connect, we show you the recipient, the countries, the fact that neither has an adequacy decision, what is sent, and what the absence of adequate protection can mean for you, and you have to agree to it in its own step. We keep a record of the wording you were shown and when. The integration stays off unless you start it yourself, and disconnecting it under Settings, Integrations withdraws your consent and ends all further delivery. Added May 2026.
- Product feedback relay (Discord, United States): When you send feedback from the in-app feedback dialog, we post a copy of it to a private channel of ours on Discord so that we see it the moment it arrives. Discord receives the feedback category, the free text exactly as you wrote it, your account identifier and the address of the page you were on. Your email address and your name are not included, and neither is your browser or screen size. Discord names Discord Netherlands BV, in the Netherlands, as the controller for people in the EEA, and Discord, Inc. in the United States is on the EU-U.S. Data Privacy Framework list, which we checked on 6 September 2026. Those are Discord's own arrangements. We hold no data processing agreement with Discord for this relay, and the Standard Contractual Clauses Discord publishes cover the transfers Discord makes, not the copy we post. Added April 2026.
- Sign-in with Google (Google, United States and Ireland): Signing in with Google is optional. Nothing reaches Google while you look at our login or sign-up page: the button is drawn by us, and we load no script, font or image from Google. Only when you press it does your browser go to Google's own sign-in page, and Google then sees your IP address, your browser, and that someone is signing in to FilingIQ. If you are already signed in to Google, it knows who you are. When you approve, Google sends us the account identifier it assigns for our application, your email address and whether Google has verified it, your name and the address of your profile picture, and we store those on your FilingIQ account. We send Google nothing about what you then do here: no filings you open, no watchlists, no alerts. Google acts as its own controller for this, not as our processor, so what it does with the sign-in on its side is governed by Google's privacy policy, not ours. Google Ireland Limited is Google's contracting entity for users in the EEA, and Google LLC in the United States is on the EU-U.S. Data Privacy Framework list, which we checked on 7 September 2026 (organisation 5780, EU-U.S. certification active). Using Google is never required: email and password does everything the same, and you can keep using it. Added September 2026.
- Blog illustrations (UploadThing, United States): The article-card images on our blog are generated by us and stored with UploadThing (Ping Labs, Inc., United States, delivered over Cloudflare). Your browser no longer fetches them from there. We download each image when we build the site and serve it from filingiq.io, so reading the blog reveals your address to nobody but us, and we send UploadThing no account data about you. Changed September 2026; until then your browser did fetch them directly.
We may also disclose personal data if required to do so by law, court order, or governmental request.
7. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes described in this policy:
- Account data: Retained for as long as your account is active. Upon account deletion, your data will be removed within 30 days. In our own database this happens immediately (see below). At the same moment we ask PostHog, our analytics processor (Section 6), to delete your analytics profile, the events recorded under it and any session recordings. PostHog removes the profile shortly afterwards and the events within seven days.
- Analytics data in PostHog: Events stay until you delete your account (then as described above) or until the retention period of our PostHog plan ends. Session recordings are deleted after 30 days.
- Error reports and logs: Sentry and Better Stack keep them for the retention period of our plan with each provider and then delete them automatically. The logs on our own server are rotated by size and overwritten.
- Activity days: the days on which an account was active (Section 3.2) are deleted after 90 days, and with the account. The daily totals made from them identify no one and are kept.
- Backups: We make one backup of our database a day and keep the three most recent ones, so a deleted account disappears from the backups within three days.
- Financial preferences: Deleted when you remove them or upon account deletion.
You may request deletion of your personal data at any time by contacting us at legal@filingiq.io, or by using the in-app account deletion button once your account is active. Deletion in our own database completes immediately, within minutes of the request, well within the 30-day GDPR SLA required by Article 17(1). When you delete your account, we erase every row of personal data we hold about you across all user-scoped database tables in a single atomic transaction, and then ask PostHog to delete your analytics data as described above; audit-trail records such as invitation provenance are anonymized (the deleted user's identifier is replaced with the literal value deleted-user) rather than removed, so the integrity of the invite flow is preserved without retaining any PII.
You may also download a complete copy of your personal data at any time via the in-app data export endpoint (Article 15, the right of access, and Article 20, the right to data portability). The export is delivered as a single JSON file containing your account profile, watchlists, preferences, alert settings, notifications, push-notification device metadata, feedback you have submitted, invitations you have received, your answers to the cookie banner, where your sign-up came from and the days your account was active in the last 90 days.
8. Your Rights Under GDPR
As a data subject under the GDPR, you have the following rights:
- Right of access (Art. 15): You may request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): You may request correction of inaccurate or incomplete personal data.
- Right to erasure (Art. 17): You may request deletion of your personal data ("right to be forgotten").
- Right to data portability (Art. 20): You may request a machine-readable copy of your personal data for transfer to another service.
- Right to restriction of processing (Art. 18): You may request that we restrict the processing of your personal data under certain circumstances.
- Right to object (Art. 21): You may object to the processing of your personal data based on legitimate interests.
- Right to withdraw consent (Art. 7(3)): Where processing is based on your consent, you may withdraw that consent at any time by contacting us at legal@filingiq.io.
To exercise any of these rights, please contact us at legal@filingiq.io. We will respond to your request within 30 days.
You also have the right to lodge a complaint with the competent supervisory authority. In Germany, this is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2-4, 40213 Düsseldorf, Germany, www.ldi.nrw.de. You may also contact the supervisory authority where you live or work.
9. International Transfers
Our application servers are hosted by Hetzner in Germany, and our landing page analytics (Plausible) runs on a server we operate in the EU. PostHog, Sentry, MailerSend and Better Stack receive and store your data on EU endpoints. PostHog Inc., Functional Software Inc. (Sentry) and MailerSend, Inc. are companies based in the United States, so access to that data from the United States, for example for support or because US law requires it, cannot be ruled out. The data processing terms we have with them include the Standard Contractual Clauses approved by the European Commission for such access. Our landing page loads its fonts, its scripts, its analytics, every portrait on our politician pages and every article-card image on our blog from servers FilingIQ operates. No page on filingiq.io reveals your address to anybody but us.
Three optional features send data outside the EU/EEA, each only once you choose it:
- Telegram alerts reach Telegram Messenger Inc. in the British Virgin Islands, with group companies in Dubai. Neither jurisdiction is covered by a European Commission adequacy decision, and no Standard Contractual Clauses are available to us for this route. We rely on your explicit consent under Article 49(1)(a) GDPR, which you give in a separate step before connecting and can withdraw at any time by disconnecting the integration. What crosses is the identifier of your Telegram chat and the alert described in Section 6.
- Product feedback reaches Discord. Discord names Discord Netherlands BV, in the Netherlands, as the controller for people in the EEA, and Discord, Inc. in the United States is on the EU-U.S. Data Privacy Framework list.
- Sign-in with Google, if you choose it, reaches Google. Google Ireland Limited is the contracting entity for users in the EEA, and Google LLC in the United States is on the EU-U.S. Data Privacy Framework list, checked on 7 September 2026. That is an adequacy decision under Article 45 GDPR, so this transfer needs no separate consent from you. What crosses is described in Section 6, and nothing crosses at all unless you press the button.
If you would rather nothing left the EU, sign in with your email address and password rather than with Google, use the Service without connecting Telegram, and leave the Discord box in the feedback dialog unticked. Everything else, including alerts by email and in the web application, is stored inside the EU, with the possible access from the United States described above. Section 12 describes the transfers that concern people in public filings, not our users.
For any further transfer outside the EU/EEA that may arise from another service provider, such as payment processing in the future, we put appropriate safeguards in place, in particular Standard Contractual Clauses (SCCs) approved by the European Commission.
10. Security Measures
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of all connections to the Service (TLS/HTTPS).
- Passwords stored only as salted hashes, never in plain text.
- Access to our servers and database restricted to the people who run FilingIQ.
- Monitoring of errors and availability.
- A daily backup of our database, of which we keep the three most recent (Section 7).
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the Service. We will notify you of material changes by posting the updated policy on the Service and updating the "Last updated" date. For significant changes, we may also notify you via email.
12. Data From Public Sources
The Service analyses filings that are public by law: the insider reports (Forms 3, 4 and 5) and institutional holdings reports (Form 13F) filed with the U.S. Securities and Exchange Commission (SEC EDGAR), and the periodic transaction reports that Members of the U.S. House of Representatives and Senate file with the Clerk of the House and the Secretary of the Senate. These filings contain personal data of people who are not our users (Art. 14 GDPR):
- Company insiders: name, SEC identifier (CIK), their role at the company and the transactions they report.
- Members of Congress: name, chamber, state and district, party affiliation, committee memberships, the transactions they disclose, including those of a spouse or dependent child, with their amount brackets, and the official portrait published by Congress.
We use these data to show, score and explain the transactions in the Service, in alerts, on our website and blog, and in posts and videos on our social media accounts. The legal basis is our legitimate interest, and that of our users and the public, in transparency about the trading of corporate insiders and legislators (Art. 6(1)(f) GDPR). Party affiliation, which Members of Congress make public themselves, is processed under Art. 9(2)(e) GDPR.
Recipients are our users and the readers of our website, blog and social media posts. In addition, two providers in the United States help us turn these data into texts and audio for our blog and social media: Anthropic, PBC receives names, roles and transactions to draft texts, and OpenAI, L.L.C. receives finished texts, which can contain those names, to produce and transcribe voice-overs. These transfers rely on the Standard Contractual Clauses in their data processing terms. We send them no data about our users.
We keep these records for as long as they are part of the public record we analyse and of the history the Service shows. If you appear in such a filing, you have the rights described in Section 8, in particular the right to object under Art. 21 GDPR; write to legal@filingiq.io.
13. Contact
If you have any questions or concerns about this Privacy Policy or our data processing practices, please contact us at:
Sprint Zero UG (haftungsbeschränkt)
Represented by its managing directors: Niklas Alexander Feldmann, Thomas Johannes Kraaibeek
Wienburgstraße 23, 48147 Münster, Germany
legal@filingiq.io