Skip to main content

Privacy Policy

Oxford Ledge LLC, a New York limited liability company ("Oxford Ledge", "we", "us", "the Service"), is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights.

Changes in the April 16, 2026 update: (a) age-verification logs no longer store your raw date of birth — only the derived age integer is retained for audit; (b) error-monitoring events sent to our observability provider are automatically scrubbed of personally identifiable fields before transmission; (c) real-time quote access is gated to paid subscribers only (free-trial users see the same 15-minute-delayed data as the free tier). Note added September 26, 2026: item (c) was incorrect. Stock quotes are delayed on every plan, free or paid, and no plan receives a faster feed; see the September 26, 2026 update to the Terms of Service.

1. What We Collect

We do not collect: financial account credentials, brokerage logins, Social Security numbers, payment card numbers (handled entirely by Stripe), or any sensitive financial identifiers.

2. How We Use Your Data

3. What We Don't Do

3a. One opt-in exception: reader-submitted reading-list notes

If you choose to publish a note on a reading-list entry via the Make this public toggle at /reading-list/<slug>/, the note body + your username become readable at /reading-list/<slug>/notes/<your-username> to anyone with the link, including search engines and AI crawlers. This is the one place on the platform where reader content is publicly attributed under a chosen handle.

Specifically, when the toggle is on:

By default, every note is Private — you have to affirmatively flip the toggle and confirm an 18+ attestation before the URL becomes public. There is no silent or background path that publishes notes without your consent.

Our role as a host of reader-submitted content, and the process for reporting it, is described in our Terms of Service §10a.

4. Cookies

We use a small number of first-party cookies — to keep you signed in, protect your session against CSRF, and remember interface state (such as the welcome-back note). We do not use third-party tracking cookies or advertising cookies, and none of these cookies are shared with third parties. Our server-side usage analytics are first-party and may be linked to your account when you are signed in; they are used only to understand and improve the product, are never shared with third parties, and are never used for advertising. We also load Cloudflare Web Analytics for privacy-first page-view measurement (see Web Analytics below) — it does not set cookies and does not identify you.

5. Third-Party Services

We do not use Google Analytics, Facebook Pixel, or any cross-site tracking, advertising, or remarketing services.

Web Analytics

We use Cloudflare Web Analytics to understand how visitors find and use Oxford Ledge. Cloudflare Web Analytics is cookie-less and does not track individual visitors across sites. The aggregated data we see includes page views, referring sites, country (not city), and device class (desktop / mobile / tablet). No personally-identifiable information is collected, no cookies are set, no fingerprinting is performed, and no session recordings are made. Because nothing about you is identified or stored — only anonymous aggregated counts — there is no individual opt-out (there is nothing about you to opt out of). See Cloudflare's Privacy Policy for the underlying technical commitments.

6. Data Source Attribution

Oxford Ledge aggregates financial data from the following third-party providers. Each provider has its own privacy policy governing how they collect and process data:

Oxford Ledge does not share your personal data (email, watchlists, portfolios) with any of the five data providers in the table above. Data flows with these providers are one-directional: we fetch public market data from them, and we transmit nothing about you in return. That is a statement about this table, not about every service provider Oxford Ledge uses. Section 5 above covers the providers that do receive text you type — your Ask AI question, and the text of an SEC-filing search — and says what each one gets.

7. Data Storage & Security

8. Data Retention

9. Your Rights

You have the right to:

To exercise any of these rights, email oxfordledge@gmail.com or use the account settings on Oxford Ledge.

For calls to our AI assistant tools made without an API key or connected account, the only record this measurement keeps is a daily count of calls to each tool, with no IP address, user agent, account or other identifier. Separately, when you open our AI assistants page from a link elsewhere on Oxford Ledge, the page view records which part of the site the link was on, as one word from a fixed list and never text you typed; like our other usage analytics it is linked to your account when you are signed in, and it follows the usage-analytics opt-out above.

10. Minimum Age & Children's Privacy

You must be at least 13 years old to use Oxford Ledge. Users aged 13 to 17 may create an account only with verifiable consent from a parent or legal guardian. We do not knowingly collect personal data from individuals under 13. If you believe a minor under 13 has created an account, please contact us immediately at oxfordledge@gmail.com for account removal and data deletion within 48 hours.

In compliance with the Children's Online Privacy Protection Act (COPPA) and equivalent international regulations, Oxford Ledge does not target, market to, or design features for children under 13.

11. International Users

The Service is operated from the United States. If you access the Service from outside the US, your data will be transferred to and processed in the United States. By using the Service, you consent to this transfer.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated with at least 30 days notice via email or a prominent notice on the Service.

13. Data Processing Basis

We process your data under the following legal bases as defined by the General Data Protection Regulation (GDPR):

14. Data Retention Periods

15. Your Rights Under GDPR

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation:

Right to Access (Art. 15) — You have the right to request a copy of all personal data we hold about you. We will provide this in a structured, commonly used, machine-readable format within 30 days of your verified request.

Right to Rectification (Art. 16) — You have the right to request correction of any inaccurate or incomplete personal data we hold about you.

Right to Erasure (Art. 17) — You have the right to request deletion of your personal data. Upon receiving a verified request, we will delete all personal data within 30 days, except where retention is required by law (e.g., billing records). This includes your account data, usage logs, watchlists, portfolio data, and any other personally identifiable information.

Erasure of published reading notes. If you delete a public reading note (or your account), the note is removed from our systems immediately and its former address permanently returns "410 Gone" — a signal that tells search engines to drop the page from their indexes quickly. As a further reasonable step under Art. 17(2), we also submit removal requests to major search engines for the former address. Cached or archived copies held by third parties (search engines, AI crawlers, archive services) are outside our control and may persist for a period after deletion; the 410 signal and removal requests are how we actively shorten that window.

Right to Restrict Processing (Art. 18) — You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest its accuracy.

Right to Data Portability (Art. 20) — You have the right to receive your personal data in a structured, commonly used, and machine-readable format (JSON or CSV). This includes your watchlists, portfolio configurations, account preferences, and usage history. You may also request that we transmit this data directly to another controller where technically feasible.

Right to Object (Art. 21) — You have the right to object to processing based on legitimate interest, including anonymous analytics. If you object, we will cease processing unless we demonstrate compelling legitimate grounds.

Right to Withdraw Consent (Art. 7(3)) — Where processing is based on consent (e.g., non-essential cookies), you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing performed before withdrawal.

Data Retention for GDPR Purposes. Account data is retained for the duration of your account plus 30 days after account deletion or closure. Application-level API request logs have the IP address and user agent removed after 90 days; the remaining request record (endpoint, method, status code, timestamp) is kept for security analytics, as Section 14 describes. Request URLs in our route handlers do not encode email, password, or other identifying query parameters, so access logs retained by our hosting provider (Render, typically 7–30 days depending on plan) do not contain direct PII beyond IP addresses. Billing records are retained for 7 years to comply with tax obligations. Browser-side AI conversation history (the Ask AI panel) is stored locally in IndexedDB and is not stored on our servers; a signed-in bring-your-own-key question is relayed through our server to your provider and not persisted. Your own AI provider key, if you connect one, is stored encrypted at rest and is deleted immediately when you remove it or delete your account. Server-side Ask AI queries (POST /api/ai/ask) are forwarded to the selected AI provider (Anthropic, OpenAI, or Google) for completion under that provider's retention terms; we do not persist question text in our database, but we log anonymized refusal-event metadata (matched safety patterns and question length, never the question text itself) for 90 days for advisory-refusal safety review.

To exercise any GDPR right, email oxfordledge@gmail.com with the subject line "GDPR Request". We will verify your identity and respond within 30 days. If we need additional time (up to 60 additional days for complex requests), we will notify you within the initial 30-day period.

Privacy Contact. For data protection inquiries, contact us at oxfordledge@gmail.com. (Oxford Ledge LLC is a small operator and is not currently required to designate a formal Article 37 Data Protection Officer; this contact serves as our privacy point of contact.)

EU/UK Representative. Oxford Ledge LLC is established in the United States. Where processing activities fall within the scope of GDPR Art. 3(2) and require an EU/UK representative under Art. 27, such representative will be designated and their contact information published here. EU/UK data subjects may in the meantime contact us directly at oxfordledge@gmail.com.

Right to Lodge a Complaint. You have the right to lodge a complaint with your local supervisory authority (e.g., your national Data Protection Authority in the EU, or the ICO in the United Kingdom) if you believe our processing of your personal data violates applicable data protection law. A list of EU supervisory authorities is available at edpb.europa.eu.

International Data Transfers. Personal data is processed and stored in the United States. Where personal data of EU/UK residents is transferred to the United States, we rely on Standard Contractual Clauses (SCCs) adopted by the European Commission as the transfer mechanism under GDPR Art. 46. A copy of applicable SCCs is available upon request.

16. Your Rights Under CCPA

If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) provide you with the following rights:

Right to Know — You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which the information was collected, the business purpose for collecting the information, and the categories of third parties with whom we share the information.

Right to Delete — You have the right to request deletion of your personal information. We will delete your data and direct any service providers to delete your data as well, subject to certain legal exceptions.

Right to Opt-Out of Sale — Oxford Ledge does not sell your personal information. We have never sold personal information and have no plans to do so. Therefore, no opt-out mechanism for data sales is necessary.

Right to Non-Discrimination — We will not discriminate against you for exercising any of your CCPA rights. You will not receive a different level of service or pricing for making a rights request.

Right to Correct — You have the right to request correction of inaccurate personal information.

Right to Limit Use of Sensitive Personal Information — We do not collect sensitive personal information as defined by the CCPA (Social Security numbers, financial account credentials, precise geolocation, etc.).

Categories of Personal Information Collected. Under the CCPA, we collect the following categories of personal information:

To exercise any CCPA right, email oxfordledge@gmail.com with the subject line "CCPA Request". We will verify your identity using the email address associated with your account and respond within 45 days. You may also designate an authorized agent to make requests on your behalf.

CCPA Metrics (Annual Disclosure): Oxford Ledge will publish annual metrics regarding the number of requests received, complied with, and denied, as required by the CCPA.

17. Your Rights Under Virginia (VCDPA) and Colorado (CPA) Law

If you are a resident of Virginia or Colorado, you have rights similar to the CCPA under the Virginia Consumer Data Protection Act (VCDPA, effective January 1, 2023) and the Colorado Privacy Act (CPA, effective July 1, 2023). These include:

To exercise any VCDPA or CPA right, email oxfordledge@gmail.com with the subject line "VCDPA Request" or "CPA Request". We will verify your identity using the email associated with your account and respond within 45 days.

18. Contact

For privacy-related questions or data requests:

We aim to respond to all data rights requests within 30 days (GDPR) or 45 days (CCPA) of receiving a verified request.