隐私政策

生效日期:2026 年 7 月 31 日 · 上一次更新:2026-08-10(新增第 5 章「社区(公开内容)」)

1. 这份政策是写给谁的

包租公("我们")是一个让散户用 Covered Call / Cash-Secured Put / Wheel 策略可视化"出租"美股的分析工具。这份政策说明:当你使用 baozugong.app 时我们怎么处理你的数据。

非交易工具。我们不接入你的券商账户、不存你的密码、不代你下单。所有"持仓"都是你手动输入的,用来出推荐和评分。

2. 我们收哪些数据

2.1 账号信息(仅登录用户)

  • 邮箱地址:通过 Google OAuth 或邮箱密码方式注册 / 登录。用邮箱密码时,密码由 Supabase Auth 加密(哈希)管理,我们看不到明文密码
  • 显示名 / 头像:Google profile 公开字段(可选)。你建社区身份时,我们会把这张头像照片复制一份到我们自己的存储当作你的社区头像(建身份那一步会先给你看一眼,你可以选择不用);你也可以自己上传一张,或随时在社区资料里移除。
  • account ID:Supabase 分配的 UUID,纯内部 key。

2.2 你输入的内容

  • 持仓数据:你手动录入的股票 / 期权(ticker、合约、张数、入场价)。
  • 持仓笔记 / Trade journal:你写的复盘和备注(自由文本)。
  • 偏好设置:语言、主题、默认风格、"愿接货 / 不接货"清单、UI 选项等。

2.3 行为日志

  • 登录 / 推荐 / 早安简报 / 复盘等动作的时间戳和聚合 metadata(ticker、策略类型、是否报错),用来排查问题和判断功能使用情况。
  • 限流命中记录:触发频率限制时记 IP 的哈希前 12 位(不存原始 IP)+ user agent 头 120 字符 + 触发的端点。
  • MCP / API 访问:如果你用自己的 AI agent 通过 MCP / API 连接,我们记录调用元数据(API 密钥标识、时间、调了哪个工具、参数)用于安全、限流与审计。你的 agent 和它用的 LLM 是你自己的——它读到的仅限你本就存在包租公里的数据,不会额外把你的信息发给我们或第三方。

2.4 错误监控

  • 后端 500 错误、前端 JS 异常会被 Sentry 收集(堆栈、报错信息、URL)。PII 模式已关闭send_default_pii=False),不发送邮箱、IP、用户 ID。

2.5 我们收的

  • 不收券商账户、密码、社保号、信用卡。
  • 不读你的浏览器历史、通讯录、麦克风、摄像头、定位。
  • 不存原始 IP(只存哈希用于限流统计)。
  • 不卖、不出租、不分享数据给广告商。

3. 数据用来干什么

  • 提供产品功能:推荐引擎、风险评估、Greeks 计算、早安简报、复盘报告。
  • 多设备同步:登录后你的持仓 / 偏好在所有设备实时同步。
  • 反滥用 / 反爬虫:限流、阻挡自动化 scraping。
  • 错误排查:Sentry 报警 → 我们修 bug → 你下次少踩坑。
  • 聚合产品决策:知道哪个功能在用、哪个没人用,决定接下来做什么。

我们用你的数据做 ad targeting、profile 销售、信用评分、或任何超出"运行这款工具"目的的事。

4. 数据存哪、谁能看到

  • 数据库:Supabase(位于美国 AWS),用 Row-Level Security 限制——每条记录只有 auth.uid() = user_id 的会话能读 / 写。即使我们运维登录后台,也只能看你授权的范围。
  • 后端运行环境:Vercel Serverless(美国边缘节点)。
  • 谁有访问权:项目所有者 congyang(hi@baozugong.app),用于运维和客服。无其他员工,无外包。

5. ⭐ 社区(公开内容)

社区是本产品唯一公开的部分。你的持仓、账户资料、愿接清单、watchlist、笔记 —— 这些始终是私有的,只有你自己能看到(行级安全,我们也不主动读)。唯一的例外是你主动发布到社区的内容。

发布到社区意味着什么。你发布的帖子、评论、交易卡,以及你的社区昵称、头像、简介和公开统计:对所有登录用户可见不会进搜索引擎 —— 公开可索引的只有社区介绍页、社区守则和个股页,这三种都不含任何用户内容。当你把一条帖子分享到 X / 微信等平台时,社交预览卡会显示这条帖子的标题和一句摘要(没有配图时用一张只含标题的卡图);未登录的人点开链接,看到的是标题、一句摘要和登录入口,完整的正文、交易卡和讨论仍然要登录社区才看得到,帖子页也不会被搜索引擎收录。

我们在你的公开主页上展示什么。昵称 · 头像 · 简介 · 加入时间 · 你发布的内容 · 由我们后端按统一口径计算的收租统计(如已落袋笔数、胜率、房东等级、里程碑徽章)。不展示:你的邮箱、持仓明细(除非你自己发了)、watchlist、收藏、账户资料、愿接清单。

交易卡只带单价,从不带总额。你分享一笔持仓时,会露出标的 · 买卖方向 · 行权价 · 到期日 · 当前有效张数 · 权利金单价 · 来源标记;不会露出你的账户资金、可用保证金、总收益金额、持仓总市值或仓位占账户比例。这不是设置项,是写在代码里的行为。

昵称与真名。我们不会拿你登录时带过来的显示名(如 Google 账户名,那通常是你的真名)当社区昵称的默认值。首次发帖前你必须自己填一个社区昵称,之后可随时改。改名后新内容用新名字;已被搜索引擎抓取的旧快照可能仍显示旧名,这不在我们控制之内。

删除。你可以随时删除自己的任何内容,或删除整个账号。删除后内容立即从社区下线。⭐ 但别人可能已经看过、截了图,那部分我们无法追回。

关于搜索引擎。你不需要为此做任何设置 —— 你写的东西不会进搜索引擎个人主页对未登录访客只显示登录提示;帖子页会显示这条帖子的标题和一句摘要(供 X / 微信等的分享预览卡用),完整正文和评论仍需登录才看得到,且两者都不会被搜索引擎收录。个股页是一处例外:它对所有人公开的是我们自己算的市场数据(现价、IV 分位、趋势位置、财报日),不含任何会员内容;那只票下面的帖子和收租记录,仍然只对登录用户可见。

社区数据存哪。与现有数据同处一个数据库(Supabase,美国区),差别只在于权限:社区内容对所有人可读,其余数据只有你自己可读。写入一律经过我们的后端校验,客户端不能直接写社区数据。

在发布之前想清楚,比发布之后删除有效得多。我们会在发布界面上明确提示这一点。完整规则见 社区守则

6. 第三方分包商(Sub-processors)

为了让产品跑起来,下面这些第三方会处理你的部分数据。每家都有自己的隐私政策,我们只把最少必要的数据发出去:

第三方用途能看到什么
GoogleOAuth 登录你的 Google 账号信息(必要)
Supabase数据库 + Auth + Realtime你的全部持仓 / 偏好 / 邮箱
Vercel网站托管 + 边缘计算请求日志(路径、状态码、IP)
Anthropic每日早安简报生成(Claude API)你 top 3 持仓 + P&L + 市场上下文。不发邮箱 / user_id / 个人信息
Sentry错误监控堆栈 + 错误信息。已禁用 PII(不含邮箱 / IP)
Charles Schwab市场数据(行情 / 期权链)只发 ticker 查询,不发用户数据
Google Analytics (GA4)产品行为分析(哪些功能在用)匿名事件 + 设备 / 来源。不发持仓 / 邮箱明文
Meta(Pixel + 转化 API)广告投放归因(落地 / 注册转化)页面事件 + 注册转化信号(邮箱经哈希后发送,用于衡量投放效果)

这些公司都签了数据处理协议或受其服务条款约束。我们使用 Google Analytics(GA4)和 Meta(Pixel + 转化 API)做产品分析与广告归因——见下方第 9 节的 cookie / 退出说明。我们不使用 TikTok Pixel 等其它追踪工具,也不把你的数据卖给广告商。

7. 保留期限

  • 账号在用:持仓 / 偏好 / 笔记保留到你删除为止。
  • 账号 12 个月不活跃:我们会发邮件提醒,14 天后无响应则按"用户删除"流程处理。
  • 行为日志:聚合统计保留 24 个月,之后只保聚合的 metric 不保单条记录。
  • 错误日志:Sentry 默认 90 天滚动删除。
  • 备份:Supabase 自动每日备份,保留 7 天,到期自动覆盖。

8. 你的权利(含删除账号)

7.1 访问 / 导出

登录后在右上角头像菜单选「导出 JSON 备份」,可下载你全部的持仓 + 偏好 + 笔记,JSON 格式,可被 Excel / Google Sheets / 任何工具读。

7.2 删除账号

登录后在右上角头像菜单选「删除账号」,确认后:

  • 立即:你的数据被标记为"待删除",账号无法继续使用,自动登出。
  • 30 天宽限期:如果你后悔了,在 30 天内用同一个账号(Google 或邮箱)重新登录,可一键 Restore。
  • 30 天后:自动硬删除——所有 user_data 行 + auth.users 记录 + usage_events(级联删除)从数据库永久清除。这是不可逆操作。

如果你想立刻硬删(跳过 30 天宽限),发邮件到 hi@baozugong.app,我们 7 个工作日内人工处理。

7.3 修正

你可以在 App 里随时直接改你的持仓 / 笔记 / 偏好。改完会实时同步。

7.4 反对处理 / 撤回同意

登出 = 立即停止收集新数据。已收的数据按上面的删除流程处理。

7.5 投诉

觉得我们处理不当?先发邮件给我们。如果你在欧盟,可以向你所在国的 Data Protection Authority 投诉。

9. Cookies & 分析

  • 登录 cookie:必要——Supabase 的 session token,不登录就没有。
  • localStorage:保存未登录用户的持仓和偏好(不上云)。
  • Vercel Web Analytics / Speed Insights:第一方匿名分析 + 性能指标,不设追踪 cookie、不跨站。
  • Google Analytics(GA4):产品行为分析,会设置第一方 cookie / 客户端标识,用来区分会话与回访。
  • Meta Pixel:广告投放归因,可能设置或读取 Meta 的 cookie 并涉及跨站追踪,用来衡量落地 / 注册转化效果。

想退出这些分析 / 广告追踪?你可以:在浏览器里阻止第三方 cookie 或用隐私模式;装 Google Analytics 退出扩展;在 Meta 广告偏好 里调整。退出不影响你正常使用产品。我们不使用其它第三方广告 SDK,也不把你的数据卖给广告商。

10. 儿童

本服务面向18 岁以上有合法投资能力的成年人。如果我们发现 18 岁以下用户的数据,会立刻删除。

11. 政策变更

如果我们改了这份政策,会在页面顶部更新"生效日期"。涉及实质性扩大数据收集的改动,会通过 App 内 banner 提前通知。继续使用即视为接受新版本;不同意可以删除账号。

12. 联系方式

隱私政策

生效日期:2026 年 7 月 31 日 · 上次更新:2026-08-10(新增第 5 章「社群(公開內容)」)

1. 這份政策是寫給誰的

包租公(「我們」)是讓散戶用 Covered Call / Cash-Secured Put / Wheel 策略可視化「出租」美股的分析工具。這份政策說明:當你使用 baozugong.app 時我們怎麼處理你的資料。

非交易工具。我們不接入你的券商帳戶、不存你的密碼、不代你下單。所有「持倉」都是你手動輸入,用來出推薦和評分。

2. 我們收哪些資料

2.1 帳號資訊(僅登入用戶)

  • 電子信箱:透過 Google OAuth 或信箱密碼方式註冊 / 登入。用信箱密碼時,密碼由 Supabase Auth 加密(雜湊)管理,我們看不到明文密碼
  • 顯示名 / 頭像:Google profile 公開欄位(可選)。你建社群身分時,我們會把這張頭像照片複製一份到我們自己的儲存當作你的社群頭像(建身分那一步會先給你看一眼,你可以選擇不用);你也可以自己上傳一張,或隨時在社群資料裡移除。
  • account ID:Supabase 分配的 UUID,純內部 key。

2.2 你輸入的內容

  • 持倉資料:你手動輸入的股票 / 選擇權(ticker、合約、口數、進場價)。
  • 持倉筆記 / Trade journal:你寫的複盤和備註(自由文本)。
  • 偏好設定:語言、主題、預設風格、「願接貨 / 不接貨」清單、UI 選項等。

2.3 行為日誌

  • 登入 / 推薦 / 早安簡報 / 複盤等動作的時間戳和聚合 metadata(ticker、策略類型、是否報錯),用來排查問題和判斷功能使用情況。
  • 限流命中記錄:觸發頻率限制時記 IP 的雜湊前 12 位(不存原始 IP)+ user agent 標頭 120 字元 + 觸發的端點。
  • MCP / API 存取:如果你用自己的 AI agent 透過 MCP / API 連接,我們記錄呼叫元資料(API 密鑰標識、時間、呼叫了哪個工具、參數)用於安全、限流與稽核。你的 agent 和它用的 LLM 是你自己的——它讀到的僅限你本就存在包租公裡的資料,不會額外把你的資訊發給我們或第三方。

2.4 錯誤監控

  • 後端 500 錯誤、前端 JS 例外會被 Sentry 收集(stack、報錯訊息、URL)。PII 模式已關閉send_default_pii=False),不發送信箱、IP、user ID。

2.5 我們收的

  • 不收券商帳戶、密碼、社安號、信用卡。
  • 不讀你的瀏覽器歷史、通訊錄、麥克風、攝影機、定位。
  • 不存原始 IP(只存 hash 用於限流統計)。
  • 不賣、不出租、不分享資料給廣告商。

3. 資料用來做什麼

  • 提供產品功能:推薦引擎、風險評估、Greeks 計算、早安簡報、複盤報告。
  • 多裝置同步:登入後你的持倉 / 偏好在所有裝置即時同步。
  • 反濫用 / 反爬蟲:限流、阻擋自動化 scraping。
  • 錯誤排查:Sentry 警報 → 我們修 bug。
  • 聚合產品決策:知道哪些功能在用、哪些沒人用,決定下一步做什麼。

我們用你的資料做 ad targeting、profile 銷售、信用評分、或任何超出「運行這款工具」目的的事。

4. 資料存哪、誰能看到

  • 資料庫:Supabase(位於美國 AWS),用 Row-Level Security 限制——每筆記錄只有 auth.uid() = user_id 的 session 能讀 / 寫。
  • 後端運行環境:Vercel Serverless(美國邊緣節點)。
  • 誰有存取權:項目擁有者 congyang(hi@baozugong.app),用於運維和客服。無其他員工,無外包。

5. ⭐ 社群(公開內容)

社群是本產品唯一公開的部分。你的持倉、帳戶資料、願接清單、watchlist、筆記 —— 這些始終是私有的,只有你自己能看到(列級安全,我們也不主動讀)。唯一的例外是你主動發布到社群的內容。

發布到社群意味著什麼。你發布的文章、留言、交易卡,以及你的社群暱稱、頭像、簡介和公開統計:對所有登入使用者可見不會進搜尋引擎 —— 公開可索引的只有社群介紹頁、社群守則與個股頁,這三種都不含任何使用者內容。分享出去的連結,未登入的人打開只會看到「登入後可見」。

我們在你的公開主頁上展示什麼。暱稱 · 頭像 · 簡介 · 加入時間 · 你發布的內容 · 由我們後端按統一口徑計算的收租統計(如已入袋筆數、勝率、房東等級、里程碑徽章)。不展示:你的信箱、持倉明細(除非你自己發了)、watchlist、收藏、帳戶資料、願接清單。

交易卡只帶單價,從不帶總額。你分享一筆持倉時,會露出標的 · 買賣方向 · 履約價 · 到期日 · 目前有效口數 · 權利金單價 · 來源標記;不會露出你的帳戶資金、可用保證金、總收益金額、持倉總市值或倉位佔帳戶比例。這不是設定項,是寫在程式碼裡的行為。

暱稱與真名。我們不會拿你登入時帶過來的顯示名(如 Google 帳戶名,那通常是你的真名)當社群暱稱的預設值。首次發文前你必須自己填一個社群暱稱,之後可隨時改。改名後新內容用新名字;已被搜尋引擎抓取的舊快取可能仍顯示舊名,這不在我們控制之內。

刪除。你可以隨時刪除自己的任何內容,或刪除整個帳號。刪除後內容立即從社群下線。⭐ 但別人可能已經看過、截了圖,那部分我們無法追回。

關於搜尋引擎。你不需要為此做任何設定 —— 你寫的東西不會進搜尋引擎。貼文頁與個人主頁對未登入訪客一律只顯示登入提示。個股頁是一處例外:它對所有人公開的是我們自己算的市場數據(現價、IV 分位、趨勢位置、財報日),不含任何會員內容;那隻股票底下的貼文與收租記錄,仍然只對登入使用者可見。

社群資料存哪。與現有資料同處一個資料庫(Supabase,美國區),差別只在於權限:社群內容對所有人可讀,其餘資料只有你自己可讀。寫入一律經過我們的後端校驗,客戶端不能直接寫社群資料。

在發布之前想清楚,比發布之後刪除有效得多。我們會在發布介面上明確提示這一點。完整規則見 社群守則

6. 第三方分包商(Sub-processors)

為了讓產品跑起來,下面這些第三方會處理你的部分資料。每家都有自己的隱私政策,我們只把最少必要的資料送出:

第三方用途能看到什麼
GoogleOAuth 登入你的 Google 帳號資訊(必要)
Supabase資料庫 + Auth + Realtime你的全部持倉 / 偏好 / 信箱
Vercel網站託管 + 邊緣運算請求日誌(路徑、status code、IP)
Anthropic每日早安簡報生成(Claude API)你 top 3 持倉 + P&L + 市場上下文。不發信箱 / user_id / 個資
Sentry錯誤監控stack + 錯誤訊息。已禁用 PII(不含信箱 / IP)
Charles Schwab市場資料(行情 / 選擇權鏈)只發 ticker 查詢,不發用戶資料
Google Analytics (GA4)產品行為分析(哪些功能在用)匿名事件 + 裝置 / 來源。不發持倉 / 信箱明文
Meta(Pixel + 轉換 API)廣告投放歸因(落地 / 註冊轉換)頁面事件 + 註冊轉換訊號(信箱經雜湊後發送,用於衡量投放效果)

我們使用 Google Analytics(GA4)和 Meta(Pixel + 轉換 API)做產品分析與廣告歸因——見下方第 9 節的 cookie / 退出說明。我們不使用 TikTok Pixel 等其它追蹤工具,也不把你的資料賣給廣告商。

7. 保留期限

  • 帳號使用中:持倉 / 偏好 / 筆記保留到你刪除為止。
  • 帳號 12 個月不活躍:我們會發信提醒,14 天後無回應則按「用戶刪除」流程處理。
  • 行為日誌:聚合統計保留 24 個月,之後只保聚合 metric 不保單筆記錄。
  • 錯誤日誌:Sentry 預設 90 天滾動刪除。
  • 備份:Supabase 每日自動備份,保留 7 天。

8. 你的權利(含刪除帳號)

7.1 訪問 / 匯出

登入後在右上角頭像選單選「匯出 JSON 備份」,可下載你全部的持倉 + 偏好 + 筆記。

7.2 刪除帳號

登入後在右上角頭像選單選「刪除帳號」,確認後:

  • 立即:你的資料被標記為「待刪除」,帳號無法繼續使用,自動登出。
  • 30 天寬限期:用同一個 Google 帳號重新登入,可一鍵 Restore。
  • 30 天後:自動硬刪——所有 user_data + auth.users + usage_events 永久清除。不可逆。

想立刻硬刪(跳過 30 天寬限)?發信到 hi@baozugong.app,7 個工作日內人工處理。

7.3 修正

你可以在 App 裡隨時直接改你的持倉 / 筆記 / 偏好。

7.4 反對處理 / 撤回同意

登出 = 立即停止收集新資料。已收的資料按上面的刪除流程處理。

7.5 投訴

覺得我們處理不當?先發信給我們。若你在歐盟,可向所在國的 Data Protection Authority 投訴。

9. Cookies & 分析

  • 登入 cookie:必要——Supabase 的 session token,未登入沒有。
  • localStorage:保存未登入用戶的持倉和偏好(不上雲)。
  • Vercel Web Analytics / Speed Insights:第一方匿名分析 + 效能指標,不設追蹤 cookie、不跨站。
  • Google Analytics(GA4):產品行為分析,會設置第一方 cookie / 客戶端識別,用來區分工作階段與回訪。
  • Meta Pixel:廣告投放歸因,可能設置或讀取 Meta 的 cookie 並涉及跨站追蹤,用來衡量落地 / 註冊轉換效果。

想退出這些分析 / 廣告追蹤?你可以:在瀏覽器裡阻止第三方 cookie 或用隱私模式;裝 Google Analytics 退出擴充;在 Meta 廣告偏好 裡調整。退出不影響你正常使用產品。我們不使用其它第三方廣告 SDK,也不把你的資料賣給廣告商。

10. 兒童

本服務面向18 歲以上有合法投資能力的成年人。如發現未滿 18 歲用戶的資料,會立即刪除。

11. 政策變更

政策變更時會在頁面頂部更新「生效日期」。實質擴大資料收集的變更會在 App 內 banner 提前通知。

12. 聯絡方式

Privacy Policy

Effective: July 31, 2026 · Last updated: 2026-08-10 (added section 5, Community)

1. Who this policy is for

Baozugong / Landlord ("we", "us") is an analytical tool that helps retail investors visualize Covered Call / Cash-Secured Put / Wheel strategies on US equities. This policy describes how we handle your data when you use baozugong.app.

Not a trading tool. We do not connect to your brokerage, store your passwords, or place orders on your behalf. All "positions" are entered by you manually, and we use them only to score positions and generate recommendations.

2. What data we collect

2.1 Account info (signed-in users only)

  • Email address: via Google OAuth or email/password sign-up / sign-in. With email/password, the password is managed (hashed) by Supabase Auth — we never see the plaintext password.
  • Display name / avatar: public fields from your Google profile (optional). When you create a community identity we copy that photo into our own storage to use as your community photo (you see it first, and can decline); you can also upload your own, or remove it at any time from your community profile.
  • Account ID: a Supabase-issued UUID, internal key only.

2.2 Content you enter

  • Position data: stocks / options you manually enter (ticker, contract, count, entry price).
  • Notes / trade journal: free-text notes you write per position.
  • Preferences: language, theme, default persona, willing-to-own list, UI options.

2.3 Activity logs

  • Timestamps and aggregated metadata for sign-in / recommend / morning-brief / review actions (ticker, strategy, error status), used for debugging and product decisions.
  • Rate-limit hits: when rate-limited, we log the first 12 chars of a hash of your IP (raw IP never stored), 120 chars of user agent, and the endpoint.
  • MCP / API access: if you connect via your own AI agent over MCP / API, we log call metadata (API-key identifier, time, which tool, parameters) for security, rate limiting, and audit. Your agent and its LLM are your own — it reads only the data you already stored in Landlord, and does not send additional information about you to us or any third party.

2.4 Error monitoring

  • Backend 500s and frontend JS exceptions are captured by Sentry (stack, error message, URL). PII mode is off (send_default_pii=False) — no emails, IPs, or user IDs are sent.

2.5 What we don't collect

  • No brokerage credentials, passwords, SSN, or credit cards.
  • No browser history, contacts, microphone, camera, or location.
  • No raw IPs (hashed only, for rate-limit stats).
  • We never sell, rent, or share data with advertisers.

3. How we use it

  • Provide the product: recommendation engine, risk scoring, Greeks, morning brief, review reports.
  • Multi-device sync: when you sign in, your positions / preferences sync in real time across devices.
  • Anti-abuse: rate limiting, blocking automated scraping.
  • Fixing errors: Sentry alerts → we fix bugs → you run into fewer of them.
  • Aggregate product decisions: see which features are used, decide what to build next.

We do not use your data for ad targeting, profile sales, credit scoring, or anything outside running this tool.

4. Where it lives, who can see it

  • Database: Supabase (hosted on AWS US), with Row-Level Security — only sessions with auth.uid() = user_id can read / write a given row. Even backend operators only see what you authorize.
  • Backend runtime: Vercel Serverless (US edge).
  • Who has access: project owner congyang (hi@baozugong.app), for operations and support. No other employees, no contractors.

5. ⭐ Community (public content)

The community is the only public part of this product. Your positions, account profile, willing-to-own list, watchlist, and notes are private, always — only you can see them (row-level security, and we don't read them either). The single exception is content you choose to publish to the community.

What publishing means. The posts, comments, and trade cards you publish, along with your community display name, avatar, bio, and public stats, are visible to every signed-in member and are kept out of search engines — the only indexable pages are the community overview, the community guidelines, and the per-ticker pages, none of which contains anything you wrote. When you share a post to X, WeChat, or similar, the social preview card shows that post's title and a one-line excerpt (a title-only card image when the post has no image of its own); someone who opens the link while signed out sees the title, the excerpt, and a sign-in prompt, while the full body, trade card, and discussion still require signing in, and the post page is never indexed by search engines.

What we show on your public profile. Display name · avatar · bio · join date · the content you published · rent statistics computed by our backend on one consistent basis (closed trades, win rate, landlord level, milestone badges). Not shown: your email, position details (unless you published them yourself), watchlist, saved items, account size, or willing-to-own list.

Trade cards carry a per-share premium, never a total. When you share a position, the card shows the ticker · side · option type · strike · expiration · contracts currently open · premium per share · source label. It does not show your account balance, buying power, total dollars collected, total position value, or position size as a percentage of your account. This is not a setting — it is how the feature is built.

Display names and real names. We do not use the display name that came from your login (e.g. your Google account name, which is usually your real name) as a default for the community. Before your first post you must enter a community display name yourself, and you can change it at any time. New content uses the new name; snapshots already crawled by search engines may still show the old one, which is outside our control.

Deletion. You can delete any of your content, or your entire account, at any time. Deleted content goes offline immediately. ⭐ But other members may already have read it or taken a screenshot, and that we cannot claw back.

About search engines. There is nothing for you to configure — nothing you write goes into search engines. Member profiles show signed-out visitors nothing but a sign-in prompt; post pages show that post's title and a one-line excerpt (for social preview cards), while the full body and comments still require signing in — and neither page is indexed by search engines. Per-ticker pages are the one exception: what they show publicly is market data we compute ourselves (last price, IV percentile, trend position, earnings date) and no member content whatsoever. The posts and trade records filed under that ticker remain visible only to signed-in members.

Where community data lives. In the same database as everything else (Supabase, US region). The only difference is permissions: community content is readable by everyone; the rest is readable only by you. All writes go through our backend for validation — clients cannot write community data directly.

Thinking it through before you publish works far better than deleting it afterward. We say so plainly in the composer. Full rules: Community Guidelines.

6. Third-party sub-processors

To operate the product, the following third parties process some of your data. Each has its own privacy policy; we send the minimum necessary:

VendorPurposeWhat they see
GoogleOAuth sign-inYour Google account info (required)
SupabaseDatabase + Auth + RealtimeAll your positions / preferences / email
VercelHosting + edge computeRequest logs (path, status, IP)
AnthropicDaily morning brief (Claude API)Your top-3 holdings + P&L + market context. No email / user_id / PII sent
SentryError monitoringStack + error message. PII disabled (no email / IP)
Charles SchwabMarket data (quotes / options chains)Only ticker queries, no user data
Google Analytics (GA4)Product usage analytics (which features are used)Anonymous events + device / referrer. No positions or plaintext email
Meta (Pixel + Conversions API)Ad-attribution (landing / signup conversions)Page events + signup conversion signal (email sent hashed, to measure ad performance)

These vendors are bound by their terms of service and applicable data-processing agreements. We use Google Analytics (GA4) and Meta (Pixel + Conversions API) for product analytics and ad attribution — see the cookie / opt-out details in Section 9 below. We do not use TikTok Pixel or other trackers, and we never sell your data to advertisers.

7. Retention

  • Active accounts: positions / preferences / notes are retained until you delete them.
  • 12-month inactivity: we send a reminder email; if you don't sign back in within 14 days, we treat it as a deletion request and run the same flow.
  • Activity logs: aggregated stats kept 24 months, then only the aggregates remain.
  • Error logs: Sentry rolls off after 90 days by default.
  • Backups: Supabase daily backups kept 7 days, then overwritten.

8. Your rights (including delete account)

7.1 Access / export

While signed in, open the avatar menu (top right) and choose "Export JSON backup". You'll download all your positions, preferences, and notes as a JSON file.

7.2 Delete account

While signed in, open the avatar menu and choose "Delete account". After you confirm:

  • Immediately: your data is marked as pending-deletion, the account is locked, you're signed out.
  • 30-day grace period: if you change your mind, sign back in within 30 days with the same Google account and click Restore.
  • After 30 days: automatic hard delete — all user_data rows + auth.users record + usage_events (cascading) are permanently removed. This is irreversible.

Want immediate hard delete (skipping the 30-day grace)? Email hi@baozugong.app and we'll process it manually within 7 business days.

7.3 Correction

Edit your positions / notes / preferences anytime in the app; changes sync in real time.

7.4 Object / withdraw consent

Sign out — we stop collecting new data immediately. Existing data follows the deletion path above.

7.5 Complain

Think we got something wrong? Email us first. If you're in the EU, you may also complain to your country's Data Protection Authority.

9. Cookies & analytics

  • Sign-in cookie: required — Supabase session token, only set when you sign in.
  • localStorage: stores positions and preferences for signed-out users (never sent to our servers).
  • Vercel Web Analytics / Speed Insights: first-party anonymous analytics + performance metrics — no tracking cookies, no cross-site tracking.
  • Google Analytics (GA4): product-usage analytics; sets a first-party cookie / client ID to distinguish sessions and returning visitors.
  • Meta Pixel: ad-attribution; may set or read Meta cookies and involves cross-site tracking, used to measure landing / signup conversions.

Want to opt out of this analytics / ad tracking? You can: block third-party cookies or use private browsing; install the Google Analytics opt-out add-on; adjust your Meta ad preferences. Opting out does not affect your normal use of the product. We use no other third-party ad SDKs and never sell your data to advertisers.

10. Children

This service is for adults 18 or older with legal capacity to invest. If we discover data from a user under 18, we delete it immediately.

11. Changes to this policy

If we update this policy, we'll update "Effective" at the top. Material expansions of data collection will be announced via an in-app banner before they take effect. Continuing to use the service means you accept the new version; if you disagree, delete your account.

12. Contact