Mastermind操盘大脑

Privacy Policy

How MastermindX collects, uses, discloses, retains, and protects personal information, including analytics, AI interactions, and privacy rights.

Published发布 2026-07-25 ·Updated更新 2026-08-08

Plain-language summary. We use information to run accounts and subscriptions, save your research, answer support requests, secure and measure the Service, and provide the AI assistant. First-party product analytics operate automatically and can use a persistent visitor identifier, device signals, IP address, and IP-derived location and network attributes. AI prompts and responses may be retained in an internal evaluation and training-curation corpus. Do not submit secrets, regulated information, or personal information you do not have authority to provide. We do not currently exchange personal information for money or share it for cross-context behavioral advertising. This English text is the operative version; any translation is for convenience. 本英文版本为准,中文翻译仅供参考。

Effective date: 8 August 2026. This Privacy Policy explains how the provider identified as the seller or service provider in the applicable checkout, order form, invoice, or receipt ("MastermindX", "Mastermind", "we", "us") handles personal information when you use mastermind-x.com, the Mastermind Terminal at app.mastermind-x.com, and related products and services (collectively, the "Service"). For privacy questions or to identify the responsible legal entity for your account or region, contact privacy@mastermind-x.com.

Scope and our role

This Policy applies to visitors, account holders, subscribers, support contacts, and people who interact with our communications. In most cases, MastermindX decides why and how personal information is processed and acts as the controller or business. If an organization buys the Service for you and controls the information it submits, that organization may also be a controller; its privacy notice may apply to its own processing.

"Personal information" means information that identifies, relates to, describes, or can reasonably be linked to a person or household. It does not include information that applicable law treats as public, aggregated, or de-identified. We may use aggregated or de-identified information for lawful purposes and do not attempt to re-identify it except to test whether our de-identification measures work or as law permits.

Information you provide

  • Account and profile. Email address, optional display name, account identifier, authentication method, verification and account status, and preferences such as language, theme, and assistant depth. Our authentication provider stores password verifiers; we do not receive your plaintext password.
  • Subscription and transaction records. Plan, subscription status, billing interval, renewal or trial state, payment-processor customer and subscription identifiers, transaction status, and related customer-service records. Stripe collects payment-card details directly; we do not receive or store full card numbers.
  • Saved research and account content. Watchlists; portfolio or journal entries such as symbol, shares, entry price and date, status, notes, thesis, outcome, and reflections; saved threads; and other records you choose to synchronize. Some assistant features may read saved watchlists or open-position context to answer your request.
  • AI assistant content. Prompts, messages, uploaded images, thread titles, conversation text, and the responses generated for you. Standard conversation records may note that an image was attached without retaining the image bytes in that record; temporary image files may be removed after a request. Separate evaluation records are described under AI assistant data and evaluation.
  • Support and communications. Your email address, support topic, subject, message, language, account tier, technical context, and our correspondence. We also keep subscription, opt-out, delivery, bounce, and complaint records for operational and compliance purposes.

The Service is not designed to collect sensitive or special-category information such as government identifiers, health information, biometric templates, exact geolocation, confidential trading information, or information about another person. Please do not put that information in prompts, images, notes, portfolios, or support messages unless it is necessary, lawful, and you have authority to provide it.

Information collected automatically

  • Product usage and analytics. Pages and features viewed; symbols or tickers searched or opened; clicks and searches; referring page; dwell time; scroll depth; session and persistent visitor identifiers; and interactions used to understand performance and product adoption.
  • Device and network information. IP address, browser and device user-agent, language and screen characteristics, timestamps, request and security logs, and a browser or device fingerprint derived from available signals.
  • IP-derived attributes. Country, region, city, latitude and longitude estimates, time zone, network number and operator, and indicators associated with VPN, proxy, Tor, hosting, relay, or abusive traffic. These are estimates based on IP address, not GPS location.
  • Cookies and browser storage. Authentication and security cookies, a first-party analytics visitor cookie, and browser-stored preferences and session state. See Cookies and similar technologies.
  • Ephemeral chart context. When an authenticated Terminal user asks the assistant about a chart, the Service may temporarily make the active symbol, timeframe, indicators, visible range, chart capabilities, and drawings available to the assistant. That live context is held in process memory, normally expires after about 10 minutes, and is not written to the standard chart-context database or file store.

Information from other sources

We receive account and session information from our authentication and database provider; subscription and transaction status from Stripe; message-delivery status from email providers; IP and network enrichment from network-information providers; and fraud, security, or device information from infrastructure providers. If an organization provides your access, it may give us your business contact information and entitlement details.

How we use personal information

  • provide, operate, authenticate, personalize, support, and maintain the Service;
  • process subscriptions, enforce entitlements and usage limits, and maintain transaction and tax records;
  • save and synchronize research, preferences, watchlists, portfolios, journals, and conversations you choose to retain;
  • generate AI responses and supply the context you request;
  • measure traffic, product performance, feature adoption, content engagement, and reliability;
  • evaluate, debug, secure, moderate, and improve the Service, including internal evaluation and training-set curation described below;
  • detect and investigate fraud, credential sharing, scraping, abuse, security incidents, outages, and violations of our Terms;
  • answer support and privacy requests and communicate about service, billing, security, policy, and product updates;
  • send optional marketing where allowed and maintain opt-out, suppression, bounce, and complaint records;
  • comply with law, respond to lawful process, establish or defend claims, and enforce our agreements; and
  • create and use aggregated or de-identified statistics, evaluations, and research.

AI assistant data and evaluation

When you use the assistant, relevant prompts, images, saved account context, and recent conversation content may be sent to one or more model providers currently used by the Service, which can include DeepSeek, Anthropic (Claude), and OpenAI (Codex). The provider and model may vary by feature, plan, availability, and routing. Those providers process the request under their applicable terms and our arrangements with them. Provider retention, human-review, and model-improvement practices can vary; do not assume that a provider offers zero retention or that deleting a MastermindX thread automatically deletes every provider-side record.

After a response is delivered, we may create a separate internal evaluation record. Depending on the request, that record can include the full question and answer; a hashed stable user reference or a guest marker; thread and page context; symbol and timeframe; provider and model; system and quality flags; token and timing metrics; and limited diagnostic or reasoning excerpts made available by the model provider. It does not ordinarily include your plaintext account password or full payment-card number.

Evaluation records may be written to Cloudflare object storage and ingested into an access-restricted, append-only operational ledger. Authorized operators may review and export them for quality assurance, safety review, debugging, regression tests, evaluations, and internal training-set curation. This is separate from the conversation history visible in your account and can remain after you delete a visible thread. We do not promise that your content will never be used to improve our systems. Do not submit confidential, proprietary, regulated, or sensitive personal information, or material you are not authorized to provide.

A signed-in evaluation record uses a pseudonymous account reference. A guest record may use only a shared guest marker, not a person- or browser-specific lookup key. As a result, we may be unable to identify, verify, access, or delete a particular guest evaluation record unless you provide enough details to locate it without exposing another person's information. We will explain any applicable limitation when responding to a verified request.

Where the EEA or UK GDPR or similar law applies, our legal bases depend on the activity:

  • Contract. To create and administer your account, provide subscribed features, process requested AI interactions, save your content, and support you.
  • Legitimate interests. To secure and operate the Service, prevent abuse, measure performance, improve features, evaluate assistant quality, communicate about the product, and establish or defend legal claims, balanced against your rights and expectations.
  • Consent. Where the law requires and we obtain consent for a specific cookie, marketing message, or other optional processing. You may withdraw consent prospectively.
  • Legal obligation and vital interests. To maintain required records, respond to lawful requests, or protect a person in an emergency.

Our first-party product analytics currently load automatically when you visit the Service; the Service does not presently offer a site-wide analytics consent switch in every region. You can block or clear cookies and storage using browser controls, although this may reset preferences or impair account functions. The availability of a region-specific control can vary, and this disclosure is not a substitute for consent where applicable law requires consent before a technology operates.

How we disclose personal information

We disclose information for business and operational purposes to the following categories of recipients:

  • Authentication and database providers, including Supabase, to authenticate users and store account, saved research, preferences, and conversations.
  • Payment providers, including Stripe, to process subscriptions, prevent payment fraud, and provide a billing portal.
  • AI model providers, including DeepSeek, Anthropic, and OpenAI, to generate assistant responses and related model telemetry.
  • Cloud, hosting, storage, and content-delivery providers, including Cloudflare, to deliver the Service, store operational and evaluation records, and protect infrastructure.
  • Analytics and network-information providers, to measure first-party product use and derive approximate location, network, and risk attributes from an IP address. Our analytics tooling can include Umami.
  • Email, communications, and support providers, to send requested or operational messages and manage delivery and opt-outs.
  • Professional advisers and corporate counterparties, such as lawyers, auditors, insurers, lenders, and prospective buyers or investors, subject to appropriate confidentiality and only as reasonably necessary.
  • Authorities and affected parties, when we reasonably believe disclosure is required by law or necessary to protect rights, safety, security, and the integrity of the Service.

If ownership or operation of the Service changes through a financing, reorganization, merger, acquisition, insolvency, or asset transfer, personal information may be reviewed or transferred as part of that transaction, subject to applicable law and notice requirements.

Sale and cross-context advertising

Based on our current practices, we do not exchange personal information for money and do not sell or share it for cross-context behavioral advertising as those terms are defined by California privacy law. We do not use third-party advertising cookies to build advertising profiles across unrelated businesses. We may disclose information to service providers and contractors for the operational purposes above; privacy laws generally distinguish those restricted disclosures from a sale. If our practices change, we will update this Policy and provide any legally required notice and opt-out.

Cookies and similar technologies

  • Authentication and security. Session and anti-forgery cookies keep accounts signed in and protect requests. Blocking them can prevent account features from working.
  • First-party analytics identifier. We may set an HttpOnly, Secure, SameSite=Lax cookie named mm_aid to recognize a browser for up to two years. Servers associate it with page, click, search, dwell, scroll, device, IP, and network information.
  • Preferences and local state. The browser may store language, theme, feature preferences, cached interface state, and other local settings.

When you sign in, we may link the analytics identifier and its associated activity to your verified account, including earlier activity from the same browser.

You can delete or block cookies in your browser. Doing so does not necessarily delete server records already collected and may cause a new visitor identifier to be issued later. Ordinary "Do Not Track" signals do not currently change our first-party analytics. Because we do not currently sell or share information for cross-context behavioral advertising, a Global Privacy Control signal does not trigger a sale or sharing opt-out under our current practices; we will honor legally recognized signals where they apply to future practices.

Retention and deletion

We retain information for the period reasonably needed for the purposes described above, including these current practices:

  • account, saved research, preferences, and visible conversation history are generally kept while the account is active and until deletion, de-identification, or a lawful retention need applies;
  • transaction, subscription, tax, fraud, security, suppression, and dispute records may be kept for the period required by law or reasonably needed to protect the Service and enforce agreements;
  • ephemeral live chart context normally expires from process memory after about 10 minutes;
  • the mm_aid browser cookie can persist for up to two years, while associated server analytics and logs follow operational retention that can vary;
  • IP-derived location and network enrichment records currently have no fixed automatic expiry and may remain until they are no longer needed or are addressed through a verified request, subject to security and legal exceptions;
  • AI evaluation records and append-only ledgers may be retained for an extended period for evaluation, safety, debugging, audit, and training curation, including after a visible thread is deleted; and
  • backups and immutable or append-only records may persist until overwritten or aged out under the relevant storage process.

When retention is no longer justified, we delete, de-identify, aggregate, restrict, or disassociate information as appropriate. A deletion request may not remove every copy immediately where data must be retained by law, is needed for security or claims, resides in a backup or immutable log, or cannot reasonably be isolated; we will apply applicable legal requirements and explain material exceptions in our response.

International data transfers

We and our providers may process information in countries other than where you live, and those countries may have different privacy laws. Depending on the transfer and applicable law, a transfer may rely on adequacy, contractual clauses, your request to perform the Service, or another permitted mechanism. You may contact us for information about safeguards applicable to your personal information, subject to lawful confidentiality limits.

Your privacy rights

Rights vary by location and are subject to exceptions. Depending on applicable law, you may have the right to:

  • know whether and why we process personal information and obtain access to it;
  • correct inaccurate or incomplete information;
  • delete information or restrict its processing;
  • receive certain information in a portable format;
  • object to processing based on legitimate interests, including certain profiling or direct marketing;
  • withdraw consent without affecting earlier lawful processing;
  • opt out of a sale, cross-context sharing, targeted advertising, or certain automated decisions where those activities occur and the law provides the right;
  • appeal our response where applicable, use an authorized agent, and exercise rights without unlawful discrimination; and
  • complain to your local privacy, data-protection, or supervisory authority.

These can include rights under the EEA and UK GDPR, Canadian privacy law, and US state privacy laws. A right may not apply to a particular record—for example, where we must retain transaction records, protect another person's rights, preserve security evidence, or comply with law.

California notice at collection

For California residents, the categories collected in the preceding 12 months can include identifiers; customer-record and commercial information; internet or electronic-network activity; approximate geolocation and network inferences; account and professional information you provide; audio, visual, or similar content in uploaded material; and inferences drawn to operate, secure, personalize, and evaluate the Service. We collect them directly from you, automatically from browsers and devices, and from the providers described above. We use and disclose them for the business purposes listed in this Policy and retain them as described under Retention and deletion. We do not currently sell or share these categories for cross-context behavioral advertising. We do not intentionally collect sensitive personal information to infer characteristics about you; if you place sensitive information in User Content, we process it as described for that content.

How to exercise your rights

Email privacy@mastermind-x.com with the subject "Privacy request" and describe the right you want to exercise. You may also update some account information in your settings. We may ask for information reasonably necessary to verify your identity, account, residence, or an agent's authority. Do not send us your password, authentication code, or full payment-card number. We will respond within the period required by applicable law. If we deny a request, you may reply with the subject "Privacy appeal" where an appeal right applies.

How we protect information

We use measures designed to protect information, including encrypted transport, server-side credential and key storage, access controls, authentication, per-user database controls where supported, logging, and administrative restrictions. No system is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur. You are responsible for protecting your credentials and devices and for promptly reporting suspected compromise.

Children

The Service is intended for adults and is not directed to anyone under 18. We do not knowingly create accounts for children or knowingly collect their personal information. If you believe a child has provided personal information, contact us so we can investigate and take appropriate action.

The Service may link to or display material from third-party websites and services. Their privacy practices are governed by their own notices, not this Policy. Review those notices before providing information or following an external workflow.

Changes to this Policy

We may update this Policy as the Service, providers, or law changes. We will revise the Effective date and provide additional notice of material changes where required. Earlier versions may be requested from us. If a change requires consent, we will seek it as required by applicable law.

Contact us

Privacy questions, rights requests, or complaints: privacy@mastermind-x.com. General support: support@mastermind-x.com. If applicable law gives you the right, you may also contact the privacy or data-protection authority where you live.