Privacy Policy
Last updated: 18 August 2026
This policy explains what FilingSmith collects, why, where it is stored, who else sees it, how long it is kept, and how to have it deleted. It is written to be read, not to be survived.
It applies to the FilingSmith service and this website. FilingSmith is operated from Australia and handles personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth).
The short version
- We collect your email address, your push device token, the companies you follow, and your delivery preferences. That is essentially the whole list.
- We do not collect your name, your address, your portfolio, your holdings, your trades, or your location.
- Card details never reach our servers — payments are handled by Stripe.
- Your personal information is never sent to a language model. The model only ever receives a structured diff of public SEC filings.
- This website sets no cookies and runs no analytics or tracking scripts.
- We do not sell or rent personal information, ever, to anyone.
What we collect, and why
Account information
| What | Why |
|---|---|
| Your email address | It is your account identifier, the address sign-in codes are sent to, and the address email alerts are delivered to |
| A one-time sign-in code | To verify you control the mailbox before granting access. The code itself is never stored — only a one-way cryptographic hash of it, which expires after about ten minutes and is invalidated on use |
| An access token for your device | So the app can stay signed in without re-entering a code |
| Your subscription tier | To determine whether your alerts include the full diff |
Device information
| What | Why |
|---|---|
| Push notification token, and whether it is an Apple or Google token | To deliver push notifications to your device. This is issued by Apple or Google, is specific to this app on this device, and is not a device serial number or advertising identifier |
Your preferences
| What | Why |
|---|---|
| The companies you follow (by SEC CIK) | To know which filings to alert you about |
| Delivery channel per company, severity threshold, quiet-hours window, timezone | To deliver alerts the way and at the times you asked for |
Your list of followed companies is the most sensitive thing we hold. It is used to route alerts, and for nothing else. It is not shared, sold, aggregated into a product, or used to infer anything about you.
Delivery records
We keep a record of the alerts generated for you — which filing, which channel, whether it was sent, suppressed by your own preferences, or failed. This exists so alerts are not sent twice, so failures can be retried, and so support can answer “why didn’t I get this one”.
Billing information
If you subscribe to a paid tier, payments are processed by Stripe. Card numbers are entered on Stripe’s own hosted checkout page and never pass through, or get stored on, FilingSmith’s servers. We store only what is needed to know whether your subscription is active: Stripe’s identifiers for your customer and subscription record, the subscription’s status, and when the current period ends.
Technical logs
Our servers keep standard operational logs — request metadata, IP address, timestamps, and error detail — for security, debugging and abuse prevention. These are retained for a limited period and are not used to build a profile of you.
This website
This site is static. It sets no cookies, runs no analytics, embeds no third-party trackers or social widgets, and does not attempt to identify visitors. Reading it leaves nothing behind.
What we do not collect
- No name, postal address or phone number.
- No portfolio, holdings, positions, trades, or brokerage connection. FilingSmith never asks what you own, and cannot know.
- No location data.
- No contacts, photos, calendar, or device storage.
- No advertising identifiers, and no cross-app or cross-site tracking.
The language model never sees your data
FilingSmith uses a language model to write the sentence around figures its own engine has already computed. What is sent to that model is a structured diff of a public SEC filing — categories, metric names, and values read from SEC’s XBRL data.
No email address, no device token, no list of followed companies, and no other personal information is included in any request to a model provider. This is a structural property of how the system is built, not a policy setting: a filing’s diff is generated once and served identically to everyone following that company, so it cannot contain anything specific to a person.
Who else sees your information
We use a small number of service providers to run the product. Each receives only what it needs.
| Provider | What it receives | For what |
|---|---|---|
| Amazon Web Services | All service data, stored and processed | Hosting, database, storage |
| SendGrid (Twilio) | Your email address and the content of emails to you | Sending sign-in codes, alerts and digests |
| Apple (APNs) / Google (FCM) | Your push token and the notification content | Delivering push notifications |
| Stripe | Your email address and the payment details you enter on their page | Processing subscription payments |
| Anthropic | Structured diffs of public filings — no personal information | Generating narrative text |
We do not sell, rent, or trade personal information, and we do not share it for advertising. We will disclose information if required by law, and will tell you where we are permitted to.
Where your information is stored
FilingSmith’s infrastructure runs on Amazon Web Services in the United States (us-east-1), chosen for proximity to SEC’s systems. Our email, push and payment providers may also process data in the United States and other countries where they operate.
If you are in Australia, this means your personal information is disclosed to overseas recipients under Australian Privacy Principle 8. By using FilingSmith you consent to that transfer.
How long we keep it
| Data | Retention |
|---|---|
| Account, followed companies, preferences | While your account exists |
| Sign-in codes | Minutes — they expire quickly and are single-use, and are stored only as a hash |
| Delivery records | While your account exists |
| Billing records | While your account exists, then as long as tax and financial-records law requires |
| Technical logs | A limited operational period |
When you ask for deletion, your account and its associated data are deleted within 30 days, except where we are legally required to retain records (financial records being the usual case).
Your rights
You can ask us to:
- give you a copy of the personal information we hold about you,
- correct anything that is wrong,
- delete your account and its data,
- stop sending you notifications — which you can also do yourself, at any time, from the app.
Email support@filingsmith.com from the address on your account. We will respond within 30 days.
If you are unhappy with how we handle a privacy request, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
Security
Access to the service requires a code sent to your email address; possession of the address alone is not enough, and a sign-in code is never stored in a form that could be replayed. Traffic is encrypted in transit, and data is encrypted at rest. Payment card details are never handled by our systems.
No system is perfectly secure. If you believe an account has been compromised, or you have found a security issue in FilingSmith, email support@filingsmith.com — security reports are read first.
Children
FilingSmith is not directed at children and is not intended for anyone under 16. We do not knowingly collect information from anyone under 16; if we learn that we have, we will delete it.
Changes to this policy
If this policy changes materially, the date at the top changes and — for anything that affects how your information is used — we will tell you by email before it takes effect.
Contact
support@filingsmith.com — privacy questions, access requests, corrections, and deletions. Entity details are on the about page.