Privacy Policy

Last updated: June 29, 2026

Your data, in plain English

Chartlas is a stock-screening tool — not a broker. We never see your brokerage account, your balances, your holdings, or your trades. A watchlist or report is just a list of ticker symbols you typed: it reflects what you're interested in, not money or positions you hold.

Four promises about anything you do store with us:

  • We never sell or share it. Not to advertisers, not to data brokers, not to anyone — except the few service providers needed to run the product (listed below).
  • Your reports and watchlists are private to you. They are visible to you in your account, and to us only for operating and supporting the service (see below).
  • We never act on your activity. We do not trade on, copy, or commercially exploit what you screen, watch, or click.
  • You can leave clean. Export everything we hold, or permanently delete your account and all your content, any time — both are one click in your account, no email required.

Prefer not to create an account at all? The public pages (Breadth, Explorer, Regime, and the preset screens) work with no login and store nothing about you.

1. What we can & can't see (the honest version)

We want to be straight about two places where your data is, by necessity, not hidden from us. Neither is sold, shared, or used commercially — but pretending they don't exist would be dishonest.

Your saved reports & watchlists are stored unencrypted, and we can read them.

To run a screen on our server, the system must read your report and watchlist configuration — so this content cannot be end-to-end encrypted. That means the operator can, in principle, see your saved reports and watchlists via direct database access. We restrict this to operations and support tasks (debugging, abuse prevention), never sell or share it, and never use it to inform any trading. If that's a dealbreaker for you, use the no-account public pages above.

Report emails pass through our email provider.

When we email you a daily report, the email — including the list of tickers that triggered — is sent through our email provider, Resend, and is visible in Resend's dashboard and retained according to their policy. Resend is named as a subprocessor in Section 5 and a Data Processing Agreement is in place. If you'd rather your tickers never appear in an email, turn on “Don't include my tickers in emails” in Settings → Email Notifications: we'll then send a content-free notice with a link to view the report in-app, so your symbols never reach the email provider.

2. Who we are

Chartlas ("we", "our", "us") is an independent project operated by Aleksej, based in Vilnius, Lithuania. Chartlas operates the https://chartlas.com website and service. This Privacy Policy explains how we collect, use, and protect your personal data when you use our service.

3. Data we collect

  • Account information: Email address, full name, and a hashed password when you register.
  • Your content: The reports (screens) and watchlists you create — i.e. ticker lists and filter settings you type. These are not brokerage data; they are configuration you author.
  • Usage data: Reports created, signals viewed, exports downloaded, and login timestamps, for product analytics.
  • Settings: Preferences such as timezone, email notification settings, and delivery mode.
  • Technical data: IP address, browser type, and device information collected automatically via server logs.

4. How we use your data

We process your data based on the following legal grounds (GDPR Article 6):

  • Contract performance: To provide and maintain the service — running your reports, delivering email reports, authenticating your account, and sending transactional emails (password resets, account notices).
  • Legitimate interest: To improve the product based on aggregated usage analytics and to communicate product updates (you can opt out at any time).

We do not use your reports, watchlists, or activity for advertising, profiling, resale, or any trading or investment decision of our own.

5. Service providers (subprocessors)

We rely on a small number of vetted providers to run the service. Each processes only what it needs:

  • Resend (email delivery) — sends your transactional and report emails. Report emails contain the triggered tickers unless you enable the "notify only" option (Section 1). A Data Processing Agreement is in place; Resend is GDPR-compliant and EU-U.S. Data Privacy Framework certified. See Resend's own subprocessor list at resend.com/legal/subprocessors.
  • Hetzner Cloud (hosting) — our application and PostgreSQL database run on Hetzner's servers in Germany (EU).
  • Cloudflare (DNS & CDN) — routes and protects web traffic.
  • Umami (analytics) — self-hosted, cookieless, privacy-focused. Collects no personal data and sets no cookies.

6. Data storage & security

Your data is stored in a PostgreSQL database hosted on secure European servers (Hetzner Cloud, Germany). Passwords are hashed using PBKDF2-SHA256 with per-user salts. All data in transit is encrypted using TLS/HTTPS. Your report and watchlist content is stored unencrypted at rest (see Section 1 for why it cannot be end-to-end encrypted).

7. Your rights (GDPR)

If you are in the European Economic Area, you have the right to:

  • Access & portability: Download a copy of everything we hold for your account in a machine-readable JSON file — one click via your account ("Download my data").
  • Erasure ("right to be forgotten"): Permanently delete your account from your account. This deletes your reports, watchlists, and delivery history, and anonymizes your account record.
  • Rectification: Correct inaccurate personal data.
  • Objection: Object to processing for specific purposes.

Export and deletion are self-service and require no email. For anything else, or if a self-service option isn't working for you, contact us at the email below.

8. Data retention

We retain your account data for as long as your account is active. When you delete your account, we remove your content (reports, watchlists, delivery history) and anonymize your account record (email and name). Anonymized usage records may be retained for aggregate product analytics. Server logs are retained for 90 days.

9. Cookies & local storage

Chartlas does not use cookies. Authentication tokens (JWT) are stored in your browser's local storage and are used solely for session management. We do not use advertising, tracking, or third-party cookies. Our analytics tool (Umami) is cookieless and collects no personally identifiable information.

10. Changes to this policy

We may update this Privacy Policy from time to time. We will notify registered users of significant changes via email. Your continued use of the service after changes constitutes acceptance of the updated policy.

11. Contact

For privacy-related questions or to exercise your GDPR rights, contact us at: [email protected]