What's Moving

Privacy Policy

Last updated: September 1, 2026

What we collect

Account: when you sign up, our authentication provider (Clerk) collects your email address and, if you sign in with Google or Apple, the basic profile your provider shares. We use it to identify your account and to show you your own profile in the app.

Subscription: purchases are processed by Apple or Google, and subscription state is managed through RevenueCat. We store only your entitlement status and its expiry — receipts stay with the stores and RevenueCat, and we never see your card number.

Follows: the tickers, categories, and themes you follow are stored so the app can filter and highlight what you see.

We do not collect brokerage accounts, positions, or trading activity, and we do not use advertising trackers.

Your watchlist never shapes our content

Published analysis is generated from market data and public news only. Your identity and your follows are never inputs to content generation — they are used solely to filter which published items are shown to you. This separation is structural in our system, not a policy promise.

Third parties

Clerk (authentication), RevenueCat (subscription management), tawk.to (support chat and support email) and Crisp (support chat in older app versions) process data on our behalf; Apple and Google process your payments as store operators. This site sets no cookies and loads no third-party resources. We do not sell personal data and we do not share it with advertisers.

Connecting an AI assistant

You can connect What's Moving to an AI assistant such as Claude or ChatGPT. Connecting one signs you in through Clerk, our authentication provider, and grants that assistant access to the published archive on your behalf — the same content your account can already see, under the same subscription tier. You can revoke that access at any time from the assistant's own settings. Revoking stops any further access being granted; an access token already issued keeps working until it expires, which is within 24 hours.

What the assistant receives is what it asks for: published market records — moves, their cited news sources, sector and narrative associations, price bars and company figures. It is the same content for everyone. The one exception is the tool that filters the archive by what you follow: when your assistant calls it, your followed tickers, sectors and narratives are part of the answer, because that is what you asked it to filter by.

We record one line per tool call: which tool ran, whether it succeeded, how long it took and how large the answer was. We do not record the question you asked, the answer we returned, or your access token. The caller on that line is a one-way keyed digest of your account identifier, not the identifier itself. These lines live in our server logs and rotate out with them.

Once the assistant has our records, what it does with them is governed by its own operator's privacy policy — Anthropic's for Claude, OpenAI's for ChatGPT — not by this one. We send them nothing on our own initiative: every exchange begins with a request your assistant made.

Retention and deletion

Account data is kept while your account exists. You can delete your account from inside the app, or by email if you no longer have it — see Support for both routes and for what deletion does and does not cover.

Deleting in the app deletes the account at Clerk, our authentication provider, which then notifies our servers — normally within seconds — and that notification is what removes your data here and starts deletion of your customer record at RevenueCat. While that is being processed we keep a one-way digest of your account identifier and the deletion time, so a sign-in token issued just before deletion cannot recreate the account; the digest stops having any effect 26 hours later — it has to outlast the longest-lived token we accept — and the record itself is removed by our next cleanup pass, which runs at least daily. We also hold the identifier RevenueCat addresses that record by — a digest cannot route a deletion — and repeat the deletion daily before erasing the identifier — normally a day or two, and longer for as long as RevenueCat has not accepted it — because an app still signed in on another device can put the record back from its own cache before it notices the account is gone. Copies can also outlive deletion in database backups, until those backups rotate out of our backup set. We restore one only to recover from data loss, never to bring an account back; if we ever had to, anything deleted after that backup was taken would come back with it, and we would delete it again. Support conversations held by tawk.to or Crisp are deleted on request. Apple and Google keep their own payment records under their own policies, and we keep records the law requires us to keep.

Changes

If this policy changes, the new version is published on this page with an updated date.

Questions or deletion requests: [email protected]