Privacy Policy
This Privacy Policy explains how Blotter Inc. collects, uses, stores, and discloses information in connection with Rallies.ai and related websites, applications, portfolio connectivity features, research tools, and paid subscription services.
Last updated: March 21, 2026
1. Scope
This Policy applies to information we collect directly from you, automatically through your use of the service, from connected portfolio providers, from payment and authentication providers, and from other third parties that help us operate Rallies.
This Policy does not apply to third-party services that may integrate with or be linked from Rallies, except to the extent we receive information from them or disclose that we use them as service providers.
2. Information We Collect
Depending on how you use Rallies, we may collect the following categories of data:
- Account and identity data, such as your name, email address, login method, and account identifiers.
- Profile and preference data, such as watchlists, saved settings, alert criteria, notification preferences, onboarding responses, feature choices, and device or push notification tokens where applicable.
- Portfolio and connectivity data, such as holdings, positions, balances, transactions, account metadata, and connection status returned through SnapTrade or other connectivity providers.
- Prompts, messages, uploads, feedback, and other content you submit through chat or other research workflows.
- Subscription and billing data, such as plan type, billing status, renewal dates, invoices, and limited payment metadata provided by payment processors. We do not store full payment card numbers processed by Stripe or Apple.
- Usage, device, and technical data, such as IP address, device identifiers, browser type, operating system, app events, crash logs, referral URLs, and interaction data.
- Cookie, local storage, and similar data used for authentication, security, preferences, analytics, and service performance.
3. How We Use Information
- Provide, maintain, secure, and improve the service.
- Create and manage your account and authenticate access.
- Power portfolio-aware research features, analytics, digests, screeners, watchlists, alerts, notifications, and related automations.
- Generate, rank, summarize, and deliver AI-assisted outputs based on your inputs and available data.
- Process subscriptions, payments, renewals, refunds, and account support requests.
- Detect fraud, abuse, security incidents, and violations of our Terms.
- Measure product usage, improve reliability, and develop new features.
- Comply with legal obligations and enforce our rights.
We may combine information collected from different sources to operate the service more effectively, personalize product functionality, detect abuse, and improve reliability.
4. Portfolio Data and Brokerage Connectivity
When you choose to connect a brokerage account, connectivity is currently provided through SnapTrade and related providers. We use connected portfolio data to support research, analytics, summaries, alerts, portfolio-aware chat, and other features you request.
Current portfolio connectivity is designed to be read-only from the Rallies side. We do not use connected portfolio data to place trades on your behalf through the current service.
Brokerage data may be delayed, incomplete, or inconsistent with your broker's official books and records. You should rely on your broker and custodian for official account information.
5. Alerts and Notifications
If you create alerts or enable push, email, SMS, or in-app notifications, we may use your alert settings, watchlists, portfolio context, device tokens, communication preferences, and other relevant product data to generate and deliver those messages.
Notification delivery may rely on third-party messaging, mobile platform, email, or infrastructure providers. Messages may be delayed, suppressed, fail to arrive, or be affected by your device, carrier, browser, operating system, permissions, or network conditions.
6. How We Share Information
We may share information in the following circumstances:
- With service providers that help us operate Rallies, such as hosting, infrastructure, analytics, customer support, authentication, payment, communications, OpenAI for current AI features, and portfolio connectivity vendors.
- With market-data, public-data, and content providers as needed to power product features.
- When you direct us to connect an account, export information, or use a third-party integration.
- If required by law, subpoena, court order, regulation, or legal process, or if we believe disclosure is necessary to protect rights, safety, or the integrity of the service.
- In connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of all or part of our business.
We may also disclose de-identified or aggregated information that does not reasonably identify you, subject to applicable law.
7. What We Do Not Sell
We do not sell your connected portfolio holdings or transaction history at an individually identifiable level.
We may create and use aggregated or de-identified analytics, trends, benchmarks, and product insights that do not reasonably identify you, subject to applicable law.
If applicable privacy law treats certain sharing for analytics or advertising as a "sale" or "sharing," your rights may depend on your jurisdiction and the specific data involved. You can contact us for more information about how those laws may apply.
8. OpenAI and Automated Processing
Current Rallies features that process your prompts, messages, portfolio context, and other user-specific inputs use OpenAI models. OpenAI acts as a service provider or processor for those features under its applicable terms.
Because AI features are part of the service, your prompts, messages, and related context may be processed to generate responses, improve reliability, monitor abuse, and support feature quality. Do not submit information you do not want processed for those purposes.
Rallies may also reference, display, compare, or discuss outputs from other model providers in public, editorial, benchmark, or experimental product surfaces. Those references do not by themselves mean your private prompts, messages, or connected portfolio data are sent to those providers.
9. Cookies, Analytics, and Tracking Technologies
We use cookies, local storage, SDKs, and similar technologies for authentication, session management, security, remembering preferences, measuring product usage, and understanding performance.
You can control certain cookie settings through your browser or device settings, though disabling them may affect service functionality.
Our websites and apps may not respond to every browser-based do-not-track or similar preference signal unless required by applicable law.
10. Data Security
We use administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, or alteration. Those measures may include encryption in transit, access controls, environment segregation, logging, and vendor management.
No security program is perfect, and we cannot guarantee absolute security or that unauthorized access will never occur.
11. Retention
We retain information for as long as reasonably necessary to provide the service, maintain security, comply with legal obligations, resolve disputes, enforce agreements, and support legitimate business operations.
Retention periods vary by data type, user settings, subscription status, backup cycles, and legal requirements. Some information may persist in backups or archives for a limited period after deletion.
We may also retain information needed to detect fraud, prevent abuse, enforce our agreements, resolve disputes, or comply with tax, accounting, recordkeeping, and legal obligations.
12. Your Choices and Rights
Depending on your location and applicable law, you may have rights to:
- access, correct, or delete certain personal information
- disconnect connected accounts or request deletion of associated portfolio data
- request a copy of certain information you provided to us
- object to or limit certain processing where permitted by law
- manage subscription renewals through the applicable billing provider
To make a privacy request, contact support@rallies.ai. We may need to verify your identity before fulfilling certain requests.
Some rights are subject to exceptions under applicable law. For example, we may need to retain certain records for billing, security, fraud prevention, legal compliance, or internal business purposes permitted by law.
13. International Processing
Rallies and our service providers may process and store information in the United States and other jurisdictions where privacy protections may differ from those in your home jurisdiction.
By using the service, you understand that your information may be transferred to and processed in those jurisdictions, subject to applicable law.
14. Account Closure and Deletion
If you close your account or request deletion, we will take reasonable steps to delete or de-identify eligible information within a commercially reasonable timeframe, subject to backups, technical constraints, legal obligations, dispute resolution needs, and fraud-prevention requirements.
Disconnecting a brokerage account will stop future synchronization, but it may not automatically remove historical data already stored in Rallies unless you also request deletion where available.
15. Children
Rallies is not intended for children under 18, and we do not knowingly collect personal information from children under 18.
16. Future Regulated Services
If we later offer services that require separate legal notices, financial privacy notices, brokerage disclosures, advisory disclosures, or regulated-account agreements, those services may be governed by additional or different privacy disclosures.
17. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will post the updated version here and update the effective date above.
18. Contact
Privacy questions can be sent to support@rallies.ai.
