Legal

Privacy policy

Effective September 28, 2026 · Safe Rate Inc., a Delaware C corporation, trading as Safe Rate Markets

What Safe Rate Markets holds about you, why, who else touches it, and what you can ask us to do about it. Written against the actual database schema rather than from a template.

1The short version

  • We do not sell your personal information. Our analytics tools may count as sharing under California law, so you can turn them off in one click and we honour Global Privacy Control automatically.
  • We use Google Analytics and Microsoft Clarity on our public pages only. Nothing third-party runs once you sign in: your dashboard, your usage and your API keys are never sent to an analytics vendor.
  • Our usage records note which route or tool you called, not the securities or dates you asked about.
  • We do not train models on your queries, and we do not sell them.

2Who this covers

Safe Rate Markets is a product of Safe Rate Inc., a Delaware C corporation with its office in Chicago, IL. Safe Rate Inc. is the data controller for everything described here.

It applies to saferate.markets, to the API and MCP server at api.saferate.markets, and to the email we send you. It does not apply to other Safe Rate products, which publish their own policies.

3What we collect about you

Every category corresponds to tables in our database, which are named so this page can be checked against the schema rather than taken on trust.

Account identity

user · account · verification

  • Your email address, which is required: it is how you sign in
  • A display name and avatar image, if you provide them
  • Whether the email address has been verified
Why
To create your account, sign you in, and tell one account from another.
Basis
Performance of our contract with you
Kept
For as long as the account exists, then deleted within 30 days of a deletion request.

Sign-in sessions

session

  • A session token stored in a cookie on your device
  • The IP address and browser user-agent the session was created from
  • When the session expires
Why
To keep you signed in, and to tell a legitimate session from a stolen one.
Basis
Our legitimate interests
Kept
Until the session expires or you sign out.

Organization and subscription

organizations · organizationMembers · organizationSubscriptions · subscription

  • Your organization's name, and that you are its member
  • Its plan, subscription status and any cancellation date
  • The identifiers of its customer and subscription at our payment processor
Why
An organization is the billing and API-key boundary, and its plan decides access and rate limit.
Basis
Performance of our contract with you
Kept
For the life of the organization.

API keys

apiKeys

  • The label you gave the key, and its first few non-secret characters
  • A SHA-256 hash of the key, never the key itself
  • Who created it, when it was last used, whether it is revoked or rotated out
Why
To authenticate requests and to let you recognise your own keys.
Basis
Performance of our contract with you
Kept
Revoked keys are kept as a record that they existed, for the life of the organization.

API usage records

apiUsageEvents · apiUsageMonthly

  • One record per request: REST or MCP, the route pattern or tool name, the response status and how long it took
  • Which API key made it
  • Monthly totals derived from those records
Why
To show you your usage and to operate and protect the service.
Basis
Performance of our contract with you
Kept
For as long as the organization exists, and deleted with it when you ask us to delete your account.

What we deliberately do not record

Our usage records store the route pattern, such as /v1/securities/:cusip, and for MCP the tool name, not the CUSIPs, dates or arguments you sent. Which securities you look at is commercially revealing, so it is not kept in our records.

Our hosting provider's request logs do contain full request URLs, as any web server's do. They are kept for a short period and used only to operate the service and investigate abuse.

Card details are entered on our payment processor's page and never reach us. We hold only the identifiers above.

4Cookies and tracking

Two strictly necessary cookies: the session token that keeps you signed in, and one that remembers if you turned analytics off. Neither does anything else.

On our public pages we also use the tools below. Refusing them changes nothing about the service you receive. Your privacy choices shows what is running for your browser and turns it off.

Google Analytics (Google LLC)

Which pages people visit and how they arrived.

Microsoft Clarity (Microsoft Corporation)

Aggregate heatmaps and session replays, to see where a page confuses people.

If your browser sends a Global Privacy Control signal, we treat that as turning them off and you do not have to tell us again.

Nothing third-party runs once you sign in

Analytics and session replay never load on /dashboard, /sign-in, /sign-out, /api/auth. This is a security control: a session recorder captures what is on screen, and an API key is shown in full exactly once, when you create it.

5Who else touches it

We do not sell your personal information. The vendors below process data on our behalf. The analytics vendors are the exception to "only on our behalf": their terms let them use what they collect for their own purposes, which is why section 9 treats them as sharing and why they are confined to public pages and can be turned off.

VendorRoleWhat it sees
Cloudflare, Inc.Hosting, database, and outbound emailEverything in section 3, and request logs. Sign-in emails are sent through it.
Stripe, Inc.Payments and subscriptionsYour email, payment details you enter on its page, and your subscription.
Google LLC (Google Workspace)Business emailAnything you choose to send us by email, including support and privacy requests.
Google LLC (Google Analytics)Website analyticsPages visited on our public pages, referrer, approximate location and device. Not the dashboard.
Microsoft Corporation (Clarity)Heatmaps and session replayHow our public pages are used: clicks, scrolling, layout. Never the dashboard or sign-in. Microsoft describes itself as a controller for this data.

Beyond those, we disclose personal information only when the law requires it, or to establish or defend a legal claim. If we are compelled to hand over your data we will tell you, unless we are legally prohibited from doing so. If Safe Rate Inc. is acquired or merged, your data would transfer with the business under this policy or one at least as protective.

6How long we keep it

Retention is stated per category in section 3. Our payment processor keeps billing records under its own obligations, including the tax and accounting rules that apply to it. Session replays expire on the vendor's own schedule, which Microsoft states as 30 days for most recordings.

7How we protect it

API keys are never stored. We keep a SHA-256 hash and a short non-secret prefix, which is enough to authenticate a request and to let you recognise your keys. A key is displayed in full exactly once, when you create it. If you lose it, rotate it: we cannot recover it for you, and that is the point.

Everything travels over TLS, and access to production data is limited to the people who need it. No system is perfectly secure, and we would rather say that plainly. If we discover a breach affecting your personal information we will notify you and the relevant regulators as the law requires.

8Your rights, and how to use them

Email team@saferate.com. We respond within 30 days, we will not charge you for a request, and we will not treat you differently for making one. You can ask for access to what we hold, correction, deletion of your account (within 30 days), a machine-readable copy, or to object to or restrict processing based on our legitimate interests. You may also complain to your supervisory authority or state Attorney General; we would rather you told us first, but that is your choice.

One limit on deletion we would rather state than bury: the session-replay provider offers no way to delete one person's recordings, only an entire project. They expire on their own; if you want them gone sooner, ask and we will delete the whole project.

9California

If you are a California resident, the CCPA as amended by the CPRA gives you the rights to know, delete, correct, and to opt out of sale or sharing, plus the right to limit the use of sensitive personal information.

We do not sell personal information. Our analytics tools set cookies their vendors may use for their own purposes, which California treats as sharing; we treat it as though it is. You can turn them off from your privacy choices, and we honour Global Privacy Control automatically, without asking where you live. We collect no sensitive personal information as the law defines it. You may use an authorised agent to exercise these rights.

10Europe and the UK

We sell in U.S. dollars and do not market in the EEA, the UK or Switzerland. So we do not treat the GDPR or the UK GDPR as applying to us, which is why analytics are opt-out rather than behind a consent banner. If we begin selling there, analytics move to prior opt-in.

That is no reason to hold your data differently, so we do not: the lawful basis for each category is in section 3, and the rights in section 8 are open to you wherever you live. Processing takes place in the United States. If you need a data processing agreement or European data residency, say so before you subscribe; today the honest answer is that we are not set up for it.

11Children

This is a business product, not directed at children, and you must be at least 18 to hold an account. If we learn we have collected personal information from anyone younger, we delete it.

12Changes to this policy

When we change this policy we update the effective date at the top. If a change materially reduces your rights or expands what we collect, we will email account holders before it takes effect. A new vendor in section 5 is a change we announce, not one you discover.

Contact

Questions about this document, or a request under it:

team@saferate.comSafe Rate Inc.515 N State St, Floor 13Chicago, IL 60654

See also our privacy policy, terms of service and your privacy choices.