At a glance

We store your data securely on our servers. Account info, saved filings, and preferences are held in our backend — not in your browser.

We do not sell your data. We do not run ads, and we never sell or share your information with advertisers or data brokers.

We use your data to run the service. Information you provide is used only to operate, improve, and secure Plainsheet.

You have meaningful rights. You can request access to, correction of, or deletion of your data at any time.

Contents

This Privacy Policy explains how Plainsheet ("we," "us," "our") collects, uses, stores, and shares information when you use our platform at plainsheet.app. By using Plainsheet you agree to the practices described here. If you do not agree, please stop using the service.

Chapter A

Who we are

Plainsheet is an independent research and educational platform that helps everyday investors understand SEC filings. We are not affiliated with, endorsed by, or sponsored by the U.S. Securities and Exchange Commission or any financial regulatory authority. We are the data controller for the personal information described in this policy.

A.1 Scope of this policy

This policy applies to all users of the Plainsheet platform, including visitors who browse without an account and registered users who create an account to access additional features. It covers information collected through our website, backend services, and any features of the platform.

Chapter B

Data we collect

We collect information you provide directly, information generated as you use the service, and limited technical data required to operate the platform securely. We collect only what is necessary to provide and improve Plainsheet.

B.1 Account and profile information

When you create an account, we collect:

  • Email address — used to create and identify your account, and to communicate with you about the service
  • Password — stored in hashed, non-recoverable form; we never store your password in plain text
  • Display name — if you choose to provide one
  • Account preferences — such as theme, notification settings, and similar configuration choices

Creating an account is required to save filings, maintain a watchlist, and use personalized features. Core research features may be accessible without an account, but results will not persist between sessions.

B.2 Research and usage data

When you use Plainsheet to research companies and filings, we store on our servers:

  • Filings you analyze — which companies and specific filings (10-K, 10-Q, 8-K) you have looked up
  • Extracted metrics and results — the financial data and signals generated from your filing analyses
  • Watchlist — companies you have saved for ongoing tracking
  • Comparison history — peer or year-over-year comparisons you have run

This data is stored in your account on our secure backend infrastructure so it persists across sessions and devices.

B.3 AI assistant interactions

If you use the optional AI filing assistant, we transmit your questions — along with the relevant filing context — to our third-party AI provider to generate an answer. This feature is entirely optional. If you do not use it, no questions are sent anywhere.

Important: AI-generated answers may contain errors. Always verify important figures against the original SEC filing, which Plainsheet links to directly on SEC.gov. Do not rely on AI responses for financial decisions.

B.4 Technical and security data

Our infrastructure automatically processes the following technical data to operate, secure, and improve the service:

  • IP address — used for rate limiting, abuse prevention, and approximate location for legal compliance purposes
  • Request logs — timestamps, HTTP methods, and endpoints accessed
  • Device and browser information — browser type, operating system, and screen resolution, used to optimize the interface
  • Error and performance logs — used to identify and fix bugs

This data is used solely for security, reliability, and service improvement. It is not used to build advertising profiles.

B.5 Data we do not collect

We do not collect:

  • Payment card numbers or bank account details (any future payment processing will be handled entirely by a certified third-party payment processor)
  • Government-issued identification numbers
  • Biometric data
  • Precise geolocation data
  • Information from your contacts, calendar, or other apps

Chapter C

How we use your data

We use the information we collect for specific, defined purposes. We do not use your data for purposes beyond those described here without your consent.

C.1 To provide and operate the service
  • Creating and maintaining your account
  • Storing and retrieving your saved filings, watchlist, and preferences
  • Processing your research requests and returning results
  • Enabling the AI assistant when you choose to use it
  • Displaying relevant financial data and metrics
C.2 To secure and improve the service
  • Detecting, preventing, and investigating fraud, abuse, or security incidents
  • Enforcing our Terms of Service
  • Monitoring performance and diagnosing technical issues
  • Analyzing aggregate, anonymized usage patterns to improve features
C.3 To communicate with you
  • Sending transactional emails — account verification, password resets, security alerts
  • Service announcements — material changes to the platform, new features, or policy updates
  • Responding to your support requests or inquiries

We do not send marketing or promotional emails without your explicit opt-in. If a marketing tier is introduced in the future, you will be given a clear choice before being enrolled.

C.4 To comply with legal obligations

We may use or retain data where necessary to comply with applicable laws, respond to lawful requests from government authorities, or protect our legal rights in a dispute.

Chapter D

How we share your data

We do not sell your personal information. We do not share it with advertisers or data brokers. We share data only in the limited circumstances described below.

D.1 Service providers and sub-processors

We use the following categories of third-party providers to operate the service. Each receives only the minimum data necessary for their specific function:

Provider type Function Data received
Cloud infrastructure & security Hosting, content delivery, DDoS protection, and bot mitigation IP address, request metadata
Backend database Secure storage of account data, saved filings, and preferences Account information, research history, watchlist
AI provider Powers the optional AI filing assistant Your question + relevant filing text (no personal account data)
Market data provider Live and delayed stock price quotes Ticker symbol only
SEC EDGAR (U.S. Government) Source of all public company filings Company name or ticker you search
Transactional email provider Delivers account verification, password resets, security alerts Your email address and the relevant message content
D.2 Legal disclosures

We may disclose your information if we believe in good faith that disclosure is necessary to:

  • Comply with a valid legal obligation, court order, or government request;
  • Protect the rights, property, or safety of Plainsheet, our users, or the public;
  • Detect, prevent, or address fraud, security, or technical issues; or
  • Enforce our Terms of Service.

Where legally permitted, we will attempt to notify you of such requests before complying.

D.3 Business transfers

If Plainsheet is involved in a merger, acquisition, asset sale, or bankruptcy proceeding, your information may be transferred as part of that transaction. We will notify you via email or a prominent notice on the service before your data becomes subject to a materially different privacy policy.

Chapter E

Data retention

We retain your data for as long as your account is active and for a defined period thereafter. We do not hold data longer than necessary.

E.1 Retention periods
Data type Retention period
Account and profile data For the life of your account, plus up to 90 days after deletion to allow recovery from accidental deletion
Saved filings, watchlist, research history For the life of your account; deleted within 30 days of account deletion
IP addresses and request logs Up to 30 days, then deleted or anonymized
AI assistant queries Transmitted to our AI provider for real-time processing; we do not retain a separate copy after the session ends
Security and error logs Up to 90 days
Legal hold data Retained for the duration required by applicable law or active legal proceedings

Chapter F

Security

We implement industry-standard technical and organizational measures to protect your information against unauthorized access, loss, or misuse.

F.1 Measures we take
  • Encryption of data in transit using TLS (HTTPS)
  • Encryption of sensitive data at rest
  • Hashed, salted password storage — your password is never stored in readable form
  • Rate limiting and abuse detection to prevent unauthorized access
  • Access controls limiting which personnel can access user data

No service can guarantee absolute security. If you have reason to believe your account has been compromised, contact us immediately at support@plainsheet.app.

Chapter G

Cookies and tracking

Plainsheet does not use advertising cookies, behavioral tracking cookies, or third-party analytics that profile you across the web.

G.1 What we use
Cookie / storage type Purpose Required?
Session / authentication token Keeps you signed in during and between sessions Yes — core function
Security cookies DDoS protection and bot mitigation provided by our infrastructure layer Yes — security
Preference storage Remembers UI settings such as theme No — convenience only

We do not use Google Analytics, Meta Pixel, or any other cross-site behavioral tracking tools. We do not serve advertising of any kind.

G.2 Do Not Track signals

Some browsers transmit "Do Not Track" (DNT) signals. Because Plainsheet does not conduct cross-site behavioral tracking or advertising, DNT signals do not materially change how we operate. Under California law (CalOPPA), we disclose that we do not currently respond to DNT signals in a technically differentiated way — because we do not engage in the tracking activities DNT is designed to prevent.

Chapter H

International data transfers

Plainsheet is operated from the United States. If you access the service from another country, your data may be transferred to and processed in the United States or other countries where our service providers operate.

H.1 Safeguards for EEA and UK users

For users in the European Economic Area (EEA) or United Kingdom, international transfers of your data are made under appropriate legal safeguards, which may include:

  • Adequacy decisions by the European Commission recognizing equivalent protection in the destination country;
  • Standard Contractual Clauses (SCCs) approved by the European Commission; or
  • Other lawful transfer mechanisms recognized under GDPR or UK GDPR.

Our infrastructure and AI providers operate under their own GDPR-compliant transfer mechanisms. You may request details of the specific mechanisms applicable to any transfer by contacting us.

Chapter I

Your rights and choices

Regardless of where you are located, you have meaningful controls over your data. Additional jurisdiction-specific rights are described in Chapters J and K.

I.1 Controls available to all users
  • Update your account information — you can edit your email address, display name, and preferences at any time from within your account settings
  • Delete individual data — you can remove individual saved filings, watchlist entries, or comparison history from within the app
  • Delete your account — you can permanently delete your account and all associated data from your account settings or by contacting us; deletion is completed within 30 days
  • Opt out of the AI assistant — simply do not use the feature; no AI data is transmitted if you do not initiate a query
  • Control transactional emails — while we require the ability to send essential account emails (security alerts, password resets), you can manage other notification preferences in your account settings

Chapter J

California residents — CCPA/CPRA

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you the following specific rights.

J.1 Your rights under California law
Right to know
Request disclosure of the categories and specific pieces of personal information we have collected, used, disclosed, or sold about you.
Right to delete
Request deletion of personal information we have collected from you, subject to certain legal exceptions.
Right to correct
Request correction of inaccurate personal information we hold about you.
Right to opt out
Opt out of the sale or sharing of your personal information. We do not sell or share your data — no action is required.
Right to limit sensitive data use
Limit use of sensitive personal information. We do not collect sensitive personal information as defined by CPRA.
Right to non-discrimination
We will not discriminate against you — in pricing, service quality, or any other manner — for exercising any of these rights.

Do Not Sell or Share My Personal Information: Plainsheet does not sell or share your personal information with third parties for advertising or cross-context behavioral advertising, as defined by CCPA/CPRA. This applies to all users.

To exercise your California rights, email support@plainsheet.app with the subject line California Privacy Request. We will respond within 45 days. We may ask you to verify your identity before fulfilling a request.

Chapter K

EEA & UK residents — GDPR

If you are located in the European Economic Area or United Kingdom, the General Data Protection Regulation (GDPR) or UK GDPR applies to our processing of your personal data.

K.1 Lawful basis for processing
Processing activity Lawful basis
Operating your account and delivering the service Performance of a contract (Art. 6(1)(b))
Security, fraud prevention, rate limiting Legitimate interests (Art. 6(1)(f))
Sending transactional emails Performance of a contract / legitimate interests
Compliance with legal obligations Legal obligation (Art. 6(1)(c))
AI assistant query processing Performance of a service you have requested (Art. 6(1)(b))
K.2 Your rights under GDPR
Access (Art. 15)
Request a copy of the personal data we hold about you.
Rectification (Art. 16)
Request correction of inaccurate or incomplete personal data.
Erasure (Art. 17)
Request deletion of your personal data ("right to be forgotten"), subject to certain conditions.
Restriction (Art. 18)
Request that we restrict processing of your data in certain circumstances.
Portability (Art. 20)
Receive your data in a structured, machine-readable format.
Objection (Art. 21)
Object to processing based on legitimate interests at any time.

Right to complain: You have the right to lodge a complaint with your local supervisory authority — in the EU, your national Data Protection Authority; in the UK, the Information Commissioner's Office (ICO) at ico.org.uk. We would, however, appreciate the opportunity to address your concern first.

To exercise any GDPR right, email support@plainsheet.app with the subject line GDPR Request. We will respond within 30 days and may ask you to verify your identity.

Chapter L

Children's privacy

Plainsheet is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13.

L.1 COPPA compliance

If we become aware that a child under 13 has provided us with personal information, we will promptly delete that information from our systems. If you are a parent or guardian and believe your child under 13 has created an account or otherwise submitted personal information, please contact us at support@plainsheet.app with the subject line Child Privacy. We will respond promptly and take appropriate corrective action.

Chapter M

Data breach notification

We take data security seriously. In the event of a breach, we are committed to acting quickly and transparently.

M.1 Our breach response commitment

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required under GDPR;
  • Notify affected users without undue delay if the breach poses a high risk to their rights and freedoms;
  • Follow applicable U.S. state breach notification laws, which typically require user notification within 30–72 days depending on the state; and
  • Provide a clear description of the breach, the data involved, and the steps we are taking to address it.

Notifications will be delivered to the email address associated with your account and, where appropriate, posted prominently on the service.

Chapter N

Changes to this policy

N.1 How we notify you of changes

We may update this Privacy Policy as the service evolves or as legal requirements change. We will indicate any change by updating the "Last updated" date at the top of this page. For material changes, we will make reasonable efforts to notify you — through the service interface, by email, or both — before the change takes effect.

Your continued use of the service after a change becomes effective constitutes acceptance of the revised policy. If you disagree with a material change, you may delete your account before it takes effect.

Chapter O

Contact us

O.1 How to reach us

For any questions, concerns, or formal data requests, please use the appropriate subject line below so your message is routed correctly: support@plainsheet.app

Plainsheet is a research tool — not financial advice.

Everything on Plainsheet is based on historical data that companies have already filed publicly. We help you read and understand that information — but we never tell you what to buy, sell, or hold. The AI assistant can make mistakes and should always be checked against the original filing. For financial decisions that matter, consult a licensed professional. See our Terms of Service for the full detail. Plainsheet is an educational and research platform; information provided is for informational purposes only and should not be considered financial, investment, legal, or tax advice.