Privacy Policy
Last updated 2026-08-19
This Privacy Policy explains what personal data Capital Fortress: Stock Screener, operated by Furni Systems SRL, collects when you use it, how that data is used and shared, and what rights you have. It describes this application specifically — the other Capital Fortress products publish their own policies. We act as the data controller for everything described below.
1. Who we are
Capital Fortress, a service operated by Furni Systems SRL, a company organized under the laws of Romania. For any privacy question or request, write to support@capitalfortress.org.
The Stock Screener has no user accounts and no login. That shapes this entire policy: instead of identifying you by an account, we identify your browser by a random code we store in it. Everything below follows from that.
2. What we collect
2.1 A visitor code, from your first visit
The first time you do something the screener has to answer — run a search, open a company page, open your plan page, or start a checkout — we generate a random code, store it in a cookie named ss_vid in your browser, and keep it for 180 days. This happens before you have told us anything about yourself. The code then stays the same, so it links your activity across visits and across days.
Loading the front page and sorting or filtering the table does not, on its own, create this code — the company list is served without it.
This cookie is not purely a technical necessity, and we will not describe it as one. It does two jobs: it lets us tell one visitor’s activity apart from another’s in the records described below, and it is what meters your free company lookups. Deleting it does not delete the records already stored against it — it starts a new code, and it costs you any free allowance and any subscription recognition that browser was carrying.
2.2 What you search for, and which companies you open
When you type in the search box we record the text you typed, verbatim, up to 200 characters. When you open a company page we record which company. Each of those records also carries:
- your visitor code, and a short readable form of it;
- your name and email address, if you have already given them to us through the free-lookups form — so from that point on, the searches you make are stored next to your identity rather than only next to a code;
- how many companies the search matched, including when it matched none;
- which access tier you were on at that moment, and — for a company page — whether we showed it to you or held it behind the paywall, and why;
- the approximate country your request came from, as a two-letter code the hosting platform derives from your IP address at its network edge;
- the page or link that brought you to us, and a short label for it — the campaign name when you arrive through a tagged link, otherwise the website you came from, otherwise the page of ours you were on;
- the date and time.
We keep the queries that returned nothing as deliberately as the ones that worked: a search we could not answer is the most useful record in the set. Partial words typed on the way to a longer one are marked as superseded so they are not counted as separate questions, but they are not deleted.
Separately, every company page you open is written to a second, smaller record — your visitor code, the company, your email if we have it, and the time — which is the ledger the free allowance is counted from.
2.3 Your name and email, if you choose to give them
After your free anonymous lookups are used up, we offer more in exchange for your full name and email address. Giving them is your choice; the screener remains usable without them, within the anonymous allowance.
If you do submit that form, we store:
- your full name and email address;
- whether you ticked the marketing consent box;
- the work you had done up to that point — the filters you had applied to the screen and the companies you had opened during that visit;
- your browser’s user-agent string, the campaign parameters in the link you arrived through, and the fingerprint of your IP address described in 2.5.
Where this goes matters and we want to be plain about it: these details are written to a shared Capital Fortress contact store used across our products, tagged as having come from the screener — not to a store that belongs to this app alone. The screener itself sends no email at all. Capital Fortress may email you from that shared store, subject to the consent you gave and to your right to unsubscribe at any time.
Your name and email are also kept in your own browser’s local storage, so the form does not ask you again on your next visit. That copy is yours; clearing your browser data removes it.
2.4 Payment details, if you subscribe
Payments are taken by Stripe. Your card number is entered on a page hosted by Stripe and never reaches us — we do not receive, process or store card numbers.
What we do store when you subscribe:
- your Stripe customer and subscription identifiers;
- the email address on the subscription, the plan, its status, when the current period ends, and whether it is set to cancel;
- a copy of each subscription-related event Stripe sends us, as received. These event records contain the billing details Stripe collected for the transaction, such as the name and email on the payment. We keep them so that a payment problem can be traced and so the same event is never applied twice.
We also send your visitor code and, where we already hold it, your email address to Stripe when opening a checkout, so that the subscription can be matched back to your browser when you return. Stripe processes payments as an independent controller for its own compliance purposes; its handling of your data is governed by Stripe’s own privacy policy.
2.5 Your IP address
We do not store your IP address. We convert it to a shortened one-way fingerprint and store that instead, in place of the address itself. The fingerprint is used to count usage from one internet connection, so that the free allowance cannot be refilled indefinitely by clearing cookies.
We will not overstate what that protects. A fingerprint of this kind reduces the exposure of the underlying address but does not make it unrecoverable by a determined party, so we treat it as personal data and give it the same protection, retention and rights as everything else in this policy — we do not present it as anonymous. Separately, the hosting platform derives a two-letter country code from your IP at its network edge, and we store that country code with the records described in 2.2.
2.6 Cookies and browser storage
The screener sets no advertising or third-party cookies. It sets three cookies of its own, all restricted so that JavaScript in the page cannot read them, all cryptographically signed by our server so their contents cannot be altered, and all lasting up to 180 days:
- ss_vid — your visitor code (see 2.1).
- ss_use — the list of companies you have already opened, so that re-reading one you have seen is always free and does not cost another lookup.
- ss_ent — for subscribers, a signed pointer to your Stripe customer record, so your access survives a temporary failure of our database. It is a pointer, not the entitlement itself.
Your browser also stores, locally and for its own use: your light/dark theme choice, your language choice, whether you dismissed the “install this app” prompt, your name and email if you gave them (2.3), and — for the current visit only — the filters you applied and the companies you opened. These live in your browser, not on our servers, until a form sends them.
We do not use Google Analytics, the Meta Pixel, or any other third-party analytics, advertising or session-recording service. While you use the screener your browser makes no requests to any host other than ours.
2.7 What we do not collect
We do not ask for and do not hold your portfolio, your holdings, your account balances, your broker, your net worth, or any figure describing your own finances. The screener analyses public company filings, not you. We also do not knowingly collect personal data from anyone under 18; if you believe we have, write to support@capitalfortress.org and we will delete it.
3. How we use it
- To run the screener. Serve company data, remember your preferences, and keep a company you have already opened free to re-open.
- To meter free access and enforce the paid tier. The allowance is counted against your visitor code, your IP fingerprint and your email address together, and the strictest of those counts applies. This is deliberate: it is what stops the free allowance being refilled by clearing cookies or switching networks.
- To prevent abuse. We limit how often the free-lookups form can be submitted from one connection or one email address, and we cap how many companies can be opened from a single connection in a day.
- To understand demand and improve the tool. Which companies people research, and — above all — which searches we cannot answer, so we can add what is missing. This is the purpose the records in 2.2 principally serve.
- To take payment and support it. Start and renew subscriptions, apply cancellations and refunds, and investigate payment problems.
- To communicate with you. Reply to messages you send us, and — where you consented — send you Capital Fortress updates and educational content from the shared contact store described in 2.3.
- To meet legal obligations. Keep the tax and accounting records the law requires, and answer lawful requests.
We do not sell personal data, and we do not share it with advertising networks or use it for cross-context behavioural advertising.
4. Legal bases (for users in the EEA, UK, and similar regimes)
- Performance of a contract (Art. 6(1)(b)) — to provide the screener and, for subscribers, the service you paid for.
- Legitimate interests (Art. 6(1)(f)) — to enforce our free allowance, prevent abuse, keep the service secure, and understand which companies and searches our users need so we can improve the product. We have weighed these against your interests; the records involved are limited to what you searched and opened, and are not combined with data from any third party.
- Consent (Art. 6(1)(a)) — for marketing email. You can withdraw it at any time, and withdrawing does not affect processing already carried out.
- Legal obligation (Art. 6(1)(c)) — to retain invoices and tax records.
5. Who we share it with
We share personal data only with the following, and only as needed to run the service:
- Stripe, Inc. — payments, subscriptions and invoicing.
- Supabase, Inc. — the database in which everything described in section 2 is stored.
- Vercel, Inc. — hosting and request routing.
- Authorities — where we are legally required to disclose, or where disclosure is necessary to protect rights, safety or property.
- A corporate transaction — if we are involved in a merger, acquisition, financing or sale of assets, personal data may transfer as part of it, subject to the protections in this Policy.
Each provider acts under a written data-processing agreement. That is the complete list of third parties that receive personal data from this application.
6. International transfers
Our hosting, database and payment providers are United States companies, and the personal data described in this Policy is processed in the United States. Where we transfer personal data of users in the EEA or the UK, we rely on the Standard Contractual Clauses adopted by the European Commission, the UK International Data Transfer Addendum, or another lawful transfer mechanism. You may request a copy of the relevant mechanism by writing to support@capitalfortress.org.
7. How long we keep it
We would rather tell you what is true than publish a schedule we do not keep:
- Search and lookup records, and visitor records: there is currently no automatic deletion schedule for these. They are retained until we delete them or until you ask us to — see section 8, which we will act on.
- Billing and subscription records: retained for the period required by applicable accounting and tax law.
- Contact details you gave us: retained while you remain on our list, and removed on request.
- Backups: deleted data may persist in our providers’ encrypted backups until those backups expire on their normal rotation.
8. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you, and get a copy of it;
- have inaccurate data corrected;
- have your data deleted;
- object to or restrict processing, including for marketing;
- withdraw consent at any time where processing relies on it;
- complain to your local data-protection authority — in the UK the ICO, in California the CPPA, in Canada the OPC, in Australia the OAIC, in New Zealand the OPC, and in each EEA country its national supervisory authority;
- for California, Virginia, Colorado, Connecticut, Utah and similar US states: to know, delete, correct and limit; to opt out of any sale or sharing (we do neither); and not to be discriminated against for exercising these rights.
How to exercise them, given that there is no account: write to support@capitalfortress.org. If you gave us an email address, that address is enough for us to find your records. If you never did, your records are held only against your visitor code, and we will need that code from you in order to identify them — we cannot find you by name if we were never given one. We may ask you to confirm your identity before we act, and we handle these requests by hand rather than through an automated tool.
9. Security
Traffic is encrypted in transit. The records described in section 2 are written and read only by our servers, using a credential that is never present in your browser; row-level security is enabled on the tables that hold them, and on the search and lookup records the database additionally refuses read access and refuses to run the reporting queries for any role other than our server’s. The cookies we set are signed so their contents cannot be forged, and are marked so that scripts in the page cannot read them. Administrative access to the reporting screens is protected by a separate key and fails closed when that key is absent.
No method of transmission or storage is completely secure, and we do not claim otherwise.
10. Automated decisions
One decision in this product is automated: whether you have free lookups left, and therefore whether a company page is shown to you or held behind the paywall. It is a count against the allowances published on our pricing page — no profiling of you is involved, and it has no legal or similarly significant effect. The financial ratios and screens the product computes are deterministic calculations on public company filings; they are educational, they are not advice, and they are not decisions about you.
11. Changes to this Policy
We may update this Policy. The “Last updated” date at the top tells you when it last changed, and for a material change we will use reasonable means to bring it to your attention.
12. Contact
For any privacy question, request or complaint, write to support@capitalfortress.org.