Information we collect
Account information. When you create an account, we receive your email address, display name, account identifier, and, when supplied by your login provider, a profile image. Sign-in is handled through Google or GitHub using Auth.js. We do not receive your Google or GitHub password.
Google Sign-In information. Dolph requests only the Google scopes needed to sign you in: openid, email, and basic profile. We use this information to authenticate you, create your Dolph profile, and show your account identity. Dolph does not request access to Gmail, Google Drive, Google Calendar, contacts, or other Google services.
Research activity. We process the tickers, issuers, filing requests, analysis settings, and other inputs you submit. For signed-in users, we record analysis usage, timestamps, and plan information so we can enforce plan limits. Reports, charts, and related output are stored only when you choose to save them to your library.
Billing information. Stripe processes subscription payments. We store Stripe customer and subscription identifiers, your plan, and subscription status. Dolph does not store full card numbers or bank account details.
Technical information. We may process an IP address and basic request information for rate limiting, security, fraud prevention, and service operation. Essential authentication cookies keep you signed in. Your theme preference may be stored locally in your browser.
How we use information
We use information to:
- Create and secure your account.
- Run requested analyses and produce reports, charts, and exports.
- Save reports when you ask us to save them.
- Apply plan limits and maintain subscription status.
- Provide account support and respond to requests.
- Protect Dolph from abuse, fraud, and security threats.
- Maintain, troubleshoot, and improve the service.
- Comply with applicable law and enforce our terms.
Service providers and disclosures
We use service providers to run Dolph. These include Supabase for database services, Vercel for web hosting, Stripe for billing, and Google or GitHub when you choose social login. Research requests use public sources such as SEC EDGAR. Depending on the configured analysis mode, filing text and research context may be processed by a model provider such as OpenAI, Google, or Groq. We do not send your Google password, payment card details, or Google OAuth tokens to a model provider.
We may disclose information when required by law, needed to protect the service or its users, or involved in a business transfer. We do not sell personal information. We do not use Google user data for advertising.
Storage, security, and retention
Account records, usage records, and saved reports are stored in Supabase. Dolph checks the signed-in user on the server and scopes account queries to that user. Database access is restricted to server-side application code. We use reasonable administrative and technical controls, but no online service can guarantee absolute security.
We keep account information while your account is active. Saved reports remain until you delete them or delete your account. Billing, security, backup, and transaction records may remain for a limited period when needed for legal, accounting, fraud prevention, or operational purposes.
Your choices
You can edit your display name, delete saved reports, manage your subscription, and delete your account from the Account page. Account deletion removes the Dolph Auth.js identity record and the related profile, usage history, and saved reports. Any active Dolph subscription is canceled as part of that process.
You can also revoke Dolph's access from your Google or GitHub account settings. Revoking provider access does not by itself delete your Dolph account.
Children
Dolph is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
Changes to this policy
We may update this policy when the service or its data practices change. The date at the top of this page identifies the current version. Material changes will be presented through the site or another reasonable notice.
Contact
For privacy questions or account-data requests, use the public contact information linked from the About page. Do not include passwords, payment card numbers, or OAuth credentials in a message.