Overview
This policy explains how Stockli (“we”, “us”) handles information when you use mystockli.com and related services.
You can browse much of Stockli without an account — market prices, funds, news, and many analysis tools. Creating an account lets you save portfolios, watchlists, and alerts. This policy covers both anonymous browsing and signed-in use.
Information we collect
We limit collection to what is necessary to provide and improve the service.
Account information
- Email address and authentication credentials (passwords are hashed — we never store plain-text passwords).
- Optional display name and profile avatar if you upload one.
- Sign-in and security events needed to keep your account safe.
Portfolio and app content you create
- Portfolios, holdings, transactions, and performance history you enter or import.
- Watchlists, price alerts, dividend alerts, and notification preferences.
- Cookie consent timestamp and push notification subscription endpoints if you opt in.
Technical and usage data
- Session cookies required to keep you signed in.
- Browser type, approximate region, and security signals (e.g. rate limiting) to protect the service from abuse.
- Server and error logs that may include IP address and requested URLs — retained briefly for reliability and security.
Information we do not intentionally collect
We do not ask for your CNIC, bank account, brokerage login, or payment card details.Stockli is not a broker and does not execute trades.
How we use your information
We use data only to operate Stockli — not to profile you for advertising.
- Authenticate you and keep your session secure.
- Store and display your portfolios, watchlists, and alerts.
- Send transactional email (sign-up verification, password reset) and, if you contact us, replies to your enquiry.
- Deliver browser push notifications you explicitly enable.
- Protect the platform through rate limits, abuse detection, and incident investigation.
- Improve reliability by measuring errors and performance (aggregated where possible).
AI-assisted features
Some screens send structured market or portfolio context to third-party AI providers to generate summaries.
When enabled, features such as news sentiment tagging, stock analysis narratives, technical summaries, portfolio health notes, and prediction commentary may transmit non-secret inputs — for example public ticker symbols, aggregated metrics, news headlines, or anonymised portfolio statistics — to external model providers under their respective terms.
We do not send your password or raw authentication tokens to AI providers. AI output is cached for a limited time to reduce cost and latency. You should treat AI text as informational only; see About for scope and limitations.
Storage, location, and security
We apply industry-standard practices, but no online service can guarantee absolute security.
- Account and portfolio data is stored in a PostgreSQL database with row-level security so each user can access only their own rows.
- Connections to the site use HTTPS in production.
- Access to production systems is restricted to the operator and essential automation.
- Market data (prices, NAVs, fundamentals) is largely public information and is not linked to your identity unless you save it inside a portfolio.
Infrastructure providers may process data in regions outside Pakistan. By using the service you acknowledge that cross-border processing may occur subject to those providers' safeguards.
How long we keep data
We retain information only as long as needed for the purposes above.
- Account and portfolio data — until you delete your account or ask us to delete it.
- Server logs — typically rolling off within weeks unless needed for an active security investigation.
- AI caches — short-lived (hours to days) depending on the feature.
- Public market datasets — refreshed continuously; not tied to your account.
Your choices and rights
- Access or export — contact us to request a copy of personal data we hold about you.
- Correction — update profile fields in the app or ask us to fix inaccurate account data.
- Deletion — request permanent account deletion; we will remove associated portfolio data within a reasonable time barring legal retention needs.
- Push notifications — revoke in browser settings or inside the app at any time.
- Cookies — session cookies are required for login; clearing them signs you out.
Children
Stockli is not directed at children under 13 (or the minimum digital consent age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will delete it.
Changes to this policy
We may update this policy when features or legal requirements change. The “Last updated” date at the top will change accordingly. Continued use after an update means you accept the revised policy.
Contact
Privacy questions or deletion requests: use the Contact form or email [email protected].