← StockPopover

StockPopover

Privacy policy

Effective July 18, 2026 · Private beta

StockPopover recognizes public-company and security mentions while you browse and opens company research in a popover and side panel. This policy explains the private beta's data boundary. It applies to the Chrome extension, its hosted support pages, and the related IR Atlas public-company research site.

What stays on your device

  • Page scanning, security-name matching, and highlight placement run locally.
  • Ordinary official-source enrichment does not send raw page text, browsing history, cookies, or surrounding private messages to StockPopover servers.
  • Settings, pause scopes, bounded caches, and remembered highlight records remain local. Page text and highlight ranges are not persisted to Chrome storage.

Information handled when you use cloud features

  • Account: Google/Firebase identity, verified email, Firebase user ID, and bounded profile metadata establish the approved beta account, data owner, and server quota. Short-lived access and ID tokens are not stored in ordinary local storage.
  • Official-source research: the canonical public security identity, requested research card or question, official-domain constraints, citations, safe result data, timing, quota, and cache metadata. Raw page text is not part of this request.
  • Ask Official Docs: company-scoped conversation and message identifiers, questions, cited answers or unavailable states, and timestamps. These records belong to the signed-in user.
  • Issue reports: only after confirmation, a report can include the description, expected security, bounded diagnostics, normalized page address without query or fragment, optional short context, and an optional screenshot that is visible and removable before submission.
  • Operations and security: bounded request, authentication, App Check, quota, failure, and audit metadata needed to operate and protect the service. StockPopover does not run silent client analytics.

How information is used

Information is used only to provide identity-matched research, cited official-source answers, user-requested support, abuse prevention, security, reliability, and the private beta's required audit trail. It is not sold, used for personalized advertising, or used to build an unrelated browsing profile. StockPopover and IR Atlas do not access brokerage accounts or execute trades.

Service providers and transfers

Firebase and Google Cloud provide authentication, callable services, private storage, screening, and bounded AI processing. Exa retrieves official-source research after server authorization. TradingView renders attributed market-information widgets in isolated hosted frames and receives the normal network information needed to serve them. Gmail sends report receipts and approved resolution notices. These providers are used only for the related user-facing feature or service protection.

User-confirmed issue evidence is de-identified and screened before a bounded projection can be reviewed through the private support workflow. Local Codex transcript deletion is verified where implemented, but the Codex service does not currently provide a remote task-deletion API; StockPopover therefore does not claim that remote transcript deletion is verified.

Retention and deletion

  • Local settings and caches remain until you clear them, reset the extension, or uninstall it.
  • Ask conversations remain until you delete a conversation or choose delete all Ask data. Callable authorization prevents one user from reading or deleting another user's threads.
  • Resolved issue evidence becomes eligible for deletion after 30 days; unresolved evidence is capped at 180 days. Bounded content-free audit metadata can remain for up to 24 months.
  • You can request deletion of your beta account and user-owned data through the support page. Some security, fraud-prevention, legal, or already-scheduled issue-audit records may follow the disclosed exception and retention period rather than immediate deletion.
  • Automatic deletion after one year of inactivity is planned but is not active in this beta. This policy will be updated before that behavior is enabled.

Your controls

You can pause scanning by site, disable cloud enrichment, sign out, delete Ask threads, remove optional issue context or screenshots before sending, and choose not to submit a report. Chrome permissions can be reviewed or revoked through Chrome's extension settings.

Security and beta limits

StockPopover uses authenticated, App Check-protected, quota-limited server endpoints and keeps provider secrets out of the extension package. IR Atlas uses the same protected boundary for signed-in official-source enrichment. No system is risk-free. This private beta can change as testing reveals defects; material data-practice changes will be disclosed before new collection begins.

Children and financial decisions

StockPopover and IR Atlas are not directed to children. They provide research assistance, not investment advice, current-price guarantees, or brokerage execution.

Contact

For privacy questions or a deletion request, use Support and account deletion or email carlmalartre@minibiz.com. Never send passwords, authentication tokens, brokerage credentials, or unnecessary page content.