Privacy Policy
Last updated: August 27, 2026
1. Who is responsible for your personal information
BetterForYourPocket is a platform operated by H&S Technologies Inc. from the Province of Québec, Canada, registered as H&S Technologies Inc. (Québec enterprise number 1182417445), 7615 rue des Métis, appartement 1013, Québec (Québec) G2K 2J6, Canada. BetterForYourPocket has its own Terms of Service, Privacy Policy, Refund and Cancellation Policy and Community Rules: these documents govern this platform only. Any other platform or service operated by the same company is a separate service with its own terms and its own personal-information holdings, and using one does not create an account, an entitlement or a data relationship on the other. We are responsible for the personal information you give us and that we collect when you use the Platform. This policy explains, in plain language, what we collect, why, who else sees it, where it goes, how long we keep it, and what you can ask us to do about it. It does not cover other websites we link to, or another platform operated by the same company — that platform has its own policy and its own separate records.
2. Person in charge of protecting your information, and how to reach them
The person accountable for the protection of personal information at BetterForYourPocket holds the function of Privacy Officer / Responsable de la protection des renseignements personnels. Write to that person at betterforyourpocket@gmail.com to ask a question about this policy, to exercise any of the rights in section 14, or to make a complaint — and, if you want it, to be told the name of the individual currently holding the function, which we will give you. Put "Privacy" in the subject line so it is routed correctly. We answer requests within 30 days.
3. What we collect, and how
Directly from you: your email address and password (kept only as a hash); an optional display name; your plan and purchase choices; onboarding answers; watchlists, tracked wallet addresses, private wallet nicknames, alert rules and portfolio positions you enter; questions and follow-ups you type into AI Research and the research threads they build; support tickets, contact-form and feedback messages; and, if you use the community, a public handle, display name, biography, interests, avatar image, posts, comments, theses, votes, reactions, reports you file, who you follow and block, and the direct messages you send. From your use of the Platform: pages and features used, requests to our servers, and standard technical logs including IP address, approximate request time, user agent and device or browser information. From our payment processor: your subscription status, plan, renewal date, payment and refund outcomes, disputes, and an opaque customer reference — we never see or store your full card number. If you switch them on: a push-notification subscription from your browser, or a Telegram chat identifier for alert delivery. We do not ask for, and you must never send us, banking or brokerage account numbers, card numbers, seed phrases, private keys or government identifiers.
4. Why we use it
To create and operate your account and authenticate you; to provide the features you use and remember your settings; to run AI Research and deliver the alerts, notifications, digests and reports you configure; to operate the community, including showing your public content to other members and delivering your private messages; to take payment, manage subscriptions and credits, and handle refunds and disputes; to keep the Platform secure — rate limiting, abuse and fraud detection, incident investigation, and audit logs of administrative actions; to provide support and answer you; to meet legal, tax and accounting obligations; and to maintain and improve the Platform using aggregated usage measurement. We use each category for the purpose it was collected for and for compatible purposes; if we ever want to use it for something materially different, we will ask you first.
5. The basis on which we process it, and your consent
We collect personal information because it is necessary to provide the service you asked for and to run our business lawfully and securely — that is the basis under Québec's Law 25 and Canada's federal privacy law. Where we ask for consent — for marketing email, for browser push notifications, for Telegram delivery, for anything optional — that consent is separate, specific, asked for in clear language, and never bundled into another action. You can withdraw it at any time, from the relevant setting, from the unsubscribe link in a marketing email, or by writing to us, and withdrawing it does not affect your account or your paid features. Where the GDPR or a comparable law applies to you, the equivalent bases are performance of our contract with you, our legitimate interests in securing and improving the Platform, your consent where we ask for it, and compliance with legal obligations.
6. Privacy by default, and what is public
Everything on the Platform starts private. A new account has no public presence at all: a community profile is created only when you first choose to publish, and nothing you keep in your account — watchlists, tracked wallets, nicknames, alerts, positions, research threads, support messages — is ever shown to another member. When you do publish in the community, these things become public and are visible to anyone who can see that page, including people who are not signed in where the page is public: your handle, display name, biography, interests and avatar, your posts, comments and theses and their revision history, your votes' effect on counts, your follower and following lists, and the counts on your profile. You control three things about this, from your profile, and they are the same on every plan — we do not sell privacy and your plan is never shown to another member or used to decide any of it. First, who may open your profile page: anyone, or only signed-in members. Second, whether you appear in the member directory, in member search, in room member lists and in suggestions of who to read or talk to; switching that off removes you from those lists and from their totals, and deletes nothing. Third, who may start a new conversation with you: anyone, only members you follow, or nobody. None of the three hides or deletes what you already published — your posts and comments stay where you wrote them, under your handle and avatar, readable by anyone who can read that page — and the only way to remove something you published is to delete it. Your own profile always remains reachable to you. Direct messages are visible only to you and the member you are writing to, and to us where we must examine a reported message to act on an abuse report; conversations that already exist continue after you change these settings, because they were agreed to when they began, and blocking a member stops contact in both directions regardless of any of them. Our moderators can still open a profile and examine reported content whatever these settings say, because a setting that could hide an account from moderation would protect the conduct these rules exist to stop. Reports you file are not shown to the member you reported. Deleting a post removes its body and its author attribution from the page; deleting your account removes your community profile and your published content.
7. Cookies, storage and measurement
We use two cookies, both strictly necessary: a signed session cookie that keeps you signed in, and a language cookie that remembers the interface language you chose. Your browser's local storage remembers your light or dark theme. We use Vercel Web Analytics for aggregated traffic measurement; it is served from our own domain, does not set an advertising cookie and does not build a cross-site profile of you, and we use it to count page views and a small number of product events such as reaching a checkout page. We do not use advertising cookies, advertising pixels, session-replay tools or cross-site tracking, we do not sell or share information for advertising, and we run no third-party tracker on the Platform. Because we set no non-essential cookies, there is no cookie banner to accept — if that ever changes, we will ask for your consent before setting one.
8. Profiling, location and automated decisions
We do not use any technology that identifies you, locates you physically or profiles you for advertising. We do not collect GPS or precise location, and we do not derive your location from your IP address; IP addresses are used for security, rate limiting and abuse investigation only. Inside the community, what you are shown is ordered using the interests you selected, the accounts you follow, the assets you look at and ordinary recency and activity signals — you can change your interests, unfollow, or stop using the community at any time, and none of it feeds an advertising profile or leaves the Platform. We do not make decisions about you based exclusively on automated processing. Automated systems rank what appears in your feed and in discovery, suggest members and topics from the interests you choose and the accounts you follow, apply rate limits, and queue reported content for review — but every decision that affects your account (removing content, restricting or suspending community access, disabling an account, granting or refusing a refund) is made by a person, is recorded in an audit log, and can be contested by writing to us. AI Research answers questions about market data; it makes no decision about you and no assessment of you.
9. AI processing
When you use AI Research, the question you type, the assets it resolves to, and the market and on-chain data assembled to answer it are sent to our AI providers (Anthropic and, as a failover, OpenAI) for processing on servers outside Québec. Your email address, password, session and billing identifiers are not sent with it. Do not type anything into AI Research you would not want processed by an external provider — in particular account numbers, credentials, government identifiers or another person's personal information. Your questions, the answers, and the evidence a turn stood on are stored in your account so that a conversation can be continued and exported, and are deleted with your account. We keep pseudonymous accounting records of AI usage — cost, credits, model, timing, and an opaque identifier — for billing integrity and abuse detection; those records are unlinked from you when your account is deleted. Automated checks reject AI output that reads as investment advice, as a guarantee or as invented personal experience before it is shown to you.
10. Who else processes it (service providers)
We use a small set of providers that act on our instructions under their own contractual security and confidentiality commitments, and each receives only what it needs: Vercel (application hosting, server logs, aggregated web analytics, and blob storage for images uploaded to the community); Neon (managed PostgreSQL database, hosting the application data described above); Upstash (Redis, used for rate limiting and abuse throttling — it holds counters keyed to an account or IP identifier, not content); Stripe (payments, subscriptions, refunds and disputes — Stripe is the controller of your payment-card data under its own policy); Resend (transactional, alert and, where you consented, marketing email); Anthropic and OpenAI (AI processing, as described in section 9); Telegram (only if you connect it, for alert delivery); and the push service of your own browser vendor (only if you enable push notifications). We also query third-party market, blockchain and filings providers — including CoinGecko, Tiingo, Etherscan, Alchemy, Helius, OpenFIGI, the U.S. Federal Reserve's FRED, Reddit and the SEC's EDGAR — from our servers, for public data about assets and addresses. Those queries are made by us, not by your browser, and your identity is not sent with them. This list is kept current; if we add a provider handling personal information we will update it here.
11. Communication outside Québec
Personal information is stored and processed outside Québec: our hosting, database, cache, payment, email and AI providers operate in the United States, in Canada outside Québec, and in the European Union. Before entrusting personal information to a service provider located outside Québec, we assess the privacy risk as Law 25 requires — what information is involved, its sensitivity, the purposes, the protection measures the provider commits to, and the legal framework of the destination — and we proceed only where the information would receive adequate protection, under a written contract containing confidentiality, security, purpose-limitation and sub-processing terms and, where offered by the provider, standard contractual clauses. Information stored outside Québec may be subject to the law of the country where it is held, including lawful access by authorities there. If you would like more detail about a specific provider, ask us.
12. How long we keep it
Account information, your settings and the content you create are kept while your account exists, and are deleted or anonymized when you delete the account, except where a record must be kept: payment, invoice, refund and dispute records are retained for the period required by tax and accounting law (seven years in Canada); records of moderation and abuse decisions and administrative audit logs are retained as the immutable record of what was decided and by whom; AI-usage accounting is retained pseudonymously without a link to you. Server and security logs are retained for a short operational period and then discarded or rotated by our hosting provider. Marketing consent and unsubscribe records are retained because they are the proof that we honoured your choice; a suppression entry outlives the account on purpose, so an unsubscribed address is never mailed again. Public community content you delete is removed from view immediately; deleting your account deletes your community profile and its content. Where information must be kept, it is kept only for the required period and for that purpose only.
13. How we protect it
Data is encrypted in transit. Passwords are stored only as salted hashes and are never recoverable. Session tokens are signed, expire, and can be revoked for every device at once by changing your password; changing a password or deleting an account requires re-entering the current password, so a stolen session alone is not enough. Access to production systems is restricted to the people who need it and administrative actions are recorded in an audit log. Secrets are never stored in the codebase and are stripped from error messages and stored logs. Requests are rate-limited and content-security policies are enforced. Uploaded images are type-checked, stored under content-addressed identifiers and served without executable permissions. No system is perfectly secure — do not reuse your Platform password anywhere else, and enable your email provider's own protections, because whoever controls your email can request a password reset.
14. Your rights
You can: ACCESS the personal information we hold about you, and get a copy of it — the Account page produces a machine-readable export immediately, and you can also write to us; CORRECT anything inaccurate, incomplete or ambiguous — most fields are editable in the product, and we will correct the rest on request; DELETE your account and your personal information, from the Account page or on request; PORT the digital information you gave us to another organisation, in a structured, commonly used technological format; WITHDRAW your consent to anything optional; ask us to STOP disseminating personal information about you, or to de-index a link, where the dissemination contravenes the law or a court order; be INFORMED about, and contest, a decision we made about you; and, where the GDPR or a comparable law applies to you, object to or ask us to restrict certain processing. We do not charge for these and we will never treat you differently for exercising one. We may need to confirm your identity before we act, and we will explain and cite our reason in writing if we cannot fully grant a request — for example where granting it would reveal personal information about someone else, or where a record must be kept by law.
15. Complaints
If you are not satisfied with how we handled your personal information or your request, write to us first at betterforyourpocket@gmail.com with "Privacy complaint" in the subject line. We will acknowledge it, examine it, and give you a written answer with our reasons and the recourse available to you. If our answer does not satisfy you and you are in Québec, you can file a complaint with, or ask for a review by, the Commission d'accès à l'information du Québec (CAI), 525, boulevard René-Lévesque Est, bureau 2.36, Québec (Québec) G1R 5S9 — cai.communications@cai.gouv.qc.ca. If you are elsewhere, you can complain to the Office of the Privacy Commissioner of Canada or to the privacy authority where you live.
16. Privacy incidents
We keep a register of confidentiality incidents involving personal information, as Law 25 requires. If an incident happens, we act promptly to reduce the risk of injury and to prevent further incidents of the same kind. Where an incident presents a risk of serious injury — judged on the sensitivity of the information, the likely consequences, and the likelihood that it will be misused — we notify the Commission d'accès à l'information du Québec and every affected person promptly, and we tell them what happened, what information was involved, what we have done, and what they can do to protect themselves. Where we are only a service provider or a processor for someone else, we notify them without delay instead.
17. Sensitive information, and what we ask you not to send
We do not seek sensitive personal information and the Platform is not designed to hold any. Do not put financial account numbers, card numbers, seed phrases, private keys, recovery codes, health or biometric information, government identifiers, or another person's personal information into a post, a comment, a message, a research question, a support ticket or your profile. If you send us something we do not need, we will delete it. Note that a wallet address you make public, and the on-chain history attached to it, can be linked to you by anyone — think about that before publishing one.
18. Children
The Platform is for adults and is not directed to children. We do not knowingly collect personal information from anyone below the age of majority where they live. If you believe a minor has given us personal information, write to us and we will delete it.
19. Changes to this policy
We may update this policy as the Platform changes. The "last updated" date at the top reflects the current version. If a change is material — a new purpose, a new category of information, a new kind of disclosure — we will take reasonable steps to tell you before it takes effect, and we will ask for your consent where the law requires it.
20. Contact
Privacy Officer / Responsable de la protection des renseignements personnels — betterforyourpocket@gmail.com. Write to us for any privacy request, question or complaint, for the name of the individual holding that function, or for the registered particulars and postal address of the operator named in section 1.