Effective date: June 1, 2026 · Last updated: July 14, 2026
Concentration of Risk ("we", "us", or "our") operates the Concentration of Risk website and related services (the "Service"), which provide research tools built on concentration-of-risk disclosures extracted from public SEC EDGAR filings. Concentration of Risk is the data controller responsible for the personal information described in this policy. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have. By using the Service you agree to this policy.
Account information. You can create an account two ways. If you sign in with Google, we receive and store your name, email address, and profile picture from Google; we never receive or store your Google password. If you sign in with an email link ("magic link"), we store your email address and send you a single-use sign-in link; the link expires after 15 minutes and we never create or store a password for you.
Session data. We set an essential session cookie (session_token) so you stay signed in. Sessions expire automatically after 7 days. This cookie is strictly necessary for the Service and is never used for advertising.
Messages you send us. If you join the waitlist, use the contact form, or reply to one of our emails, we store the name, email address, and message you provide so we can respond and notify you of updates you requested.
Alert preferences. If you configure filing alerts, we store the tickers, dimensions, and thresholds you choose so we can deliver them.
Usage logs. Like most web services, our servers record basic technical logs (IP address, request path, timestamp) for security and reliability. These logs are retained only as long as operationally necessary.
We use two categories of cookies and similar technologies:
Essential. The session_token cookie described above. The Service cannot keep you signed in without it.
Analytics. We use Google Analytics 4 and PostHog to understand how the Service is used — pages viewed, features clicked, general device and browser type, and approximate location derived from IP address. We use this strictly to improve the product; we do not use it to serve advertising, and we do not build advertising profiles. Analytics identifiers are pseudonymous; where you are signed in, we may associate product events with your account so we can understand and improve your experience.
Specific cookies we set: session_token — essential; keeps you signed in; expires after 7 days. _ga / _ga_* — Google Analytics; distinguishes visitors; up to 24 months. ph_* — PostHog; product analytics; up to 12 months.
Your choices. You can block or delete analytics cookies in your browser settings or with a content blocker without losing access to the Service; only the essential session cookie is required to stay signed in. Google also offers a browser add-on that opts you out of Google Analytics everywhere.
We send three kinds of email: (a) transactional — sign-in links and a one-time welcome message; (b) alerts you configure — notifications about filings matching criteria you set; and (c) occasional product updates. You can stop alerts by deleting them in the app, and unsubscribe from product updates via the link in any such email. We do not send third-party marketing, and we never share your email address for others' marketing.
We do not collect government identifiers, precise geolocation, or any special-category personal data. If and when paid plans are offered, payments are processed by Stripe; your card details go directly to Stripe and never touch our servers — we receive only a payment confirmation, the plan purchased, and billing metadata needed for receipts and support.
We use the information above solely to: (a) operate the Service and keep you signed in; (b) deliver alerts and emails you asked for; (c) respond to messages you send us; (d) understand aggregate usage so we can improve the product; (e) secure the Service and prevent abuse; and (f) comply with legal obligations. We do not sell personal information, and we do not use it for third-party advertising.
Legal bases (EEA/UK users). Where the GDPR or UK GDPR applies, we process your data on these bases: performance of a contract (providing the Service, your account, and features you request); legitimate interests (securing the Service, preventing abuse, and analyzing aggregate usage to improve the product — balanced against your rights); consent (optional communications, which you can withdraw at any time); and legal obligation (where we must retain or disclose information by law).
We share personal information only with the service providers required to run the Service, each acting on our instructions: Google LLC (sign-in and analytics), PostHog (product analytics), Resend (transactional email delivery), our cloud hosting and database providers, and — if you purchase a paid plan — Stripe (payment processing). We may also disclose information where required by law, or as part of a merger, acquisition, or asset sale (in which case this policy continues to apply to your data). We do not sell, rent, or trade your personal information.
The company data displayed on the Service is derived from filings publicly available on SEC EDGAR. It concerns corporate issuers, not private individuals, and is not "personal information" under this policy.
The Service is operated from the United States and information is processed on servers located there. If you access the Service from outside the U.S., you understand your information will be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction. Where required for EEA/UK data, our providers rely on recognized transfer safeguards such as standard contractual clauses or Data Privacy Framework certification.
Account data is retained while your account is active. Session tokens expire after 7 days; magic-link tokens expire after 15 minutes and are deleted automatically. Analytics data is retained per our providers' standard retention settings. You may request deletion of your account and associated personal data at any time via the contact page; we will complete verified requests within 30 days unless we are legally required to retain specific records.
European Economic Area & United Kingdom (GDPR / UK GDPR). You have the right to access, rectify, erase, and receive a portable copy of your personal data; to restrict or object to processing (including processing based on legitimate interests); and to withdraw consent at any time without affecting prior processing. You also have the right to lodge a complaint with your local supervisory authority (or the UK Information Commissioner's Office), though we'd appreciate the chance to resolve your concern first.
California (CCPA/CPRA). You have the right to know the categories and specific pieces of personal information we collect (they are listed in Section 1: identifiers such as name and email, internet activity, and inferences limited to product usage), to delete it, to correct it, and to not be discriminated against for exercising your rights. We do not "sell" or "share" personal information as defined by the CCPA/CPRA, we do not use or disclose sensitive personal information, and we have not done so in the preceding 12 months — accordingly, no opt-out is required.
Other U.S. states. If you reside in a state with a comprehensive privacy law (including Virginia, Colorado, Connecticut, Utah, Texas, and others), you have comparable rights of access, correction, deletion, and portability, and the right to appeal a refusal — reply to our response and we will re-review it, or you may contact your state Attorney General.
Exercising rights. Use the contact page from the email associated with your account (or provide information sufficient for us to verify you). Authorized agents may submit requests with proof of authorization. We respond within the timeframe the applicable law requires (typically 30–45 days) and never discriminate against you for exercising a right.
Do Not Track and Global Privacy Control. Because we do not sell or share personal information or run cross-site advertising, there is nothing for these signals to opt you out of; our essential cookie is required for sign-in regardless. We disclose, per California law, that the Service does not otherwise respond to browser "Do Not Track" signals. You can block analytics cookies at any time as described in Section 2.
We do not use your personal data to make automated decisions that produce legal or similarly significant effects about you. Analytics are used only in aggregate to improve the product.
We use industry-standard safeguards: HTTPS everywhere, httpOnly secure session cookies, single-use expiring sign-in links, and access controls on our infrastructure. No method of transmission or storage is 100% secure, but we work to protect your information proportionate to its sensitivity. If we learn of a breach affecting your personal data, we will notify you as required by applicable law.
The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.
We may update this policy from time to time. Material changes will be reflected by a new "last updated" date at the top of this page, and, where appropriate, additional notice on the Service or by email. Continued use after changes take effect constitutes acceptance.
Questions about privacy, or want to exercise a data right? Reach us through the contact page.