🔒 Privacy Policy
As of / Last updated: July 2026 · Version 1.3
The US Aktien Screener is provided solely for informational and analytical purposes. No license under the Austrian WAG 2018.
1. Controller (Art. 4 No. 7 GDPR)
Robert Thalhammer · Sole proprietor
Grabengasse 13/3/2 · 2630 Ternitz · Lower Austria, Austria
Email: info@us-aktien-screener.com
Website: https://us-aktien-screener.com
No legal obligation to appoint a Data Protection Officer.
2. What data is processed?
2.1 Login data (6-digit email-code login)
- Email address (required)
- Internal user ID (UUID)
- 6-digit email code (temporary, single-use, expires after 60 minutes)
- Access/refresh JWT tokens (in Streamlit session)
2.2 Usage data (table screening_usage)
user_id, used_at, tier_at_use, stocks_scanned, hits_count. Purpose: free-tier limit check, abuse prevention.
2.3 Subscription & payment data (table user_profiles)
tier, payment_subscription_id, payment_transaction_id, timestamps. Credit card data is never stored — all payment via Lemon Squeezy.
2.4 Server log files
IP address, timestamp, page, referrer, browser — for security and error-analysis purposes. For the landing page (IONOS) deleted after max. 7 days; for the app (Streamlit Community Cloud) the retention follows the hosting provider's own practice.
2.5 Watchlist data
When you add stocks to your personal watchlist, we store the ticker symbols you select (e.g. "AAPL", "MSFT") together with the timestamp when they were added, linked to your user ID. Purpose: displaying and automatically screening your saved stocks. Legal basis: Art. 6 (1) (b) GDPR (performance of contract). Storage location: Supabase (Frankfurt, EU). Retention: until you remove the entries or your account is deleted.
2.6 Reach measurement (IONOS WebAnalytics)
For the landing page we use IONOS WebAnalytics for statistical reach measurement. This analysis is cookieless and server-based: it relies on server access data, sets no cookies, and builds no cross-device user profiles. The data is evaluated in aggregate only. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in a needs-based design of our offering). The processed statistics are retained for up to 30 days; this is distinct from the pure security server logs (max. 7 days, see 2.4).
2.7 Reach measurement (Cloudflare Web Analytics)
Additionally, for the landing page we use Cloudflare Web Analytics (Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA). The service is cookie-free, sets no identifiers in the browser, builds no cross-device profiles and does not track individual visitors; only aggregated statistics (e.g. page views, approximate region, referrer, browser/device type) are collected, without any personal reference. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in privacy-friendly reach measurement). As no cookies are set and no device information is read, no separate consent is required. US transfer based on the EU-US Data Privacy Framework (DPF) / SCCs. cloudflare.com/privacypolicy
3. Legal bases
| Purpose | Legal basis |
|---|---|
| Login via 6-digit email code | Art. 6 (1) (b) GDPR (contract performance) |
| Subscription + tier | Art. 6 (1) (b) GDPR |
| Payment processing | Art. 6 (1) (b) GDPR |
| Free-tier limit check | Art. 6 (1) (b) GDPR |
| Watchlist (saved tickers) | Art. 6 (1) (b) GDPR |
| Reach measurement (IONOS WebAnalytics) | Art. 6 (1) (f) GDPR (legitimate interest) |
| Reach measurement (Cloudflare Web Analytics, cookie-free) | Art. 6 (1) (f) GDPR (legitimate interest) |
| Server log files | Art. 6 (1) (f) GDPR (legitimate interest, IT security) |
| Invoice retention | Art. 6 (1) (c) GDPR (BAO § 132) |
4. Recipients and processors
Supabase — database + auth, server region Frankfurt (eu-central-1), DPA in place. supabase.com/privacy
Lemon Squeezy — payment Merchant of Record. A DPA with Lemon Squeezy is in place. lemonsqueezy.com/privacy
Streamlit Community Cloud (Snowflake Inc. / Streamlit) — web-app hosting, servers in the USA. Only technical connection data (e.g. IP address on page load) is processed in the USA; personal usage data (email, watchlist) stays with Supabase in Frankfurt, EU. US transfer based on the EU-US Data Privacy Framework (DPF) / Standard Contractual Clauses (SCCs), Art. 46 GDPR. streamlit.io/privacy-policy
IONOS — landing page + email, Germany. A DPA with IONOS is in place (active since 31 March 2023). ionos.de/terms-privacy
Cloudflare, Inc. — cookie-free web analytics for the landing page, servers in the USA. Aggregated reach measurement only, no personal reference (see 2.7). DPF-certified; transfer based on DPF/SCCs. cloudflare.com/privacypolicy
Alpha Vantage, Wikipedia — external stock-data sources. The stock metrics (price, P/E, EPS, analyst ratings, price targets) come from Alpha Vantage Inc. (USA), the S&P 500 company list from Wikipedia. These sources are queried exclusively by an automated background process of the provider, not when the user loads the page. Only stock ticker symbols (e.g. "AAPL", "MSFT") are transmitted — no personal user data. Since no personal data is transmitted to these providers, no transfer of personal data to a third country takes place in this respect. When the app itself is used, the stock data is only read from the database (Supabase, Frankfurt).
GitHub Actions (GitHub Inc. / Microsoft Corporation, USA) — the automated background process described above runs on GitHub Actions. It fetches the stock data from Alpha Vantage several times a day and stores it in the database (Supabase, Frankfurt). Only stock tickers and public market data are processed — no personal user data. github.com/privacy
5. Retention periods
| Category | Retention |
|---|---|
| Email, user ID | as long as account exists |
| Watchlist (saved tickers) | as long as account exists |
| Active subscription | as long as active |
| Closed subscriptions / invoices | 7 years (BAO § 132) |
| Usage logs | 12 months rolling |
| Login code (OTP) | max. 60 minutes |
| Server logs | max. 7 days |
6. Third-country transfer
Personal usage data (Supabase) and IONOS are processed in the EU (Frankfurt). App hosting via Streamlit Community Cloud (technical connection data, e.g. IP address), the cookie-free Cloudflare Web Analytics (landing page) and, where applicable, Lemon Squeezy (payment) process data in the USA — based on the EU-US Data Privacy Framework (DPF) / Standard Contractual Clauses (SCCs), Art. 46 GDPR. Streamlit (Snowflake), Cloudflare and Lemon Squeezy are DPF-certified.
7. Your rights as a data subject
- Right of access (Art. 15 GDPR)
- Right to rectification of inaccurate data (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR) — unless a legal retention obligation applies
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent with effect for the future
To exercise: simple email to info@us-aktien-screener.com. Response within 30 days.
8. Right to lodge a complaint
Austrian Data Protection Authority
Barichgasse 40–42, 1030 Vienna, Austria · www.dsb.gv.at
9. No automated decision-making (Art. 22 GDPR)
No automated decision-making or profiling within the meaning of Art. 22 GDPR. The filters are pure data displays based on user-chosen metrics.
10. Affiliate links to crypto exchanges
Within the service, links to crypto exchanges (Bitget, Hyperliquid, Pionex, Bitpanda, Bybit) are displayed — these are affiliate / referral links. Only Coinbase is not an affiliate link.
When a user clicks an affiliate link, the user is redirected directly to the website of the respective exchange operator. From that point on, only the privacy policy of the third-party provider applies — the provider has no influence on the data processing taking place there.
What happens technically on click:
- The referral code in the URL is read by the exchange operator.
- If the user registers there, the signup is attributed to the provider's commission account.
- The provider stores no personal data related to clicks on these links.
Details on the commercial disclosure of these links — see Terms § 16.
11. Cookies and tracking
No tracking or advertising cookies. Only technically necessary Streamlit session cookies (no consent required under § 165 (3) TKG 2021). No Google Analytics, Meta Pixel etc. For the landing page we only use cookieless reach measurement (IONOS WebAnalytics, see 2.6, and Cloudflare Web Analytics, see 2.7), which sets no cookies and builds no cross-device profiles.
12. Data security
- HTTPS / TLS for all connections
- Row Level Security in Supabase — users only see their own data
- Passwordless authentication (6-digit login code)
- EU data storage (Frankfurt) for email + watchlist; app hosting in the USA via DPF/SCC
- No personal data in the software: the filter logic processes only listed-company data
13. Changes to this Privacy Policy
Material changes are communicated by email. Current version always available via the "Privacy" footer link.
As of / Last updated: July 2026 · Version 1.3