Legal

Privacy Policy

This page describes exactly what Whalur stores about you, why it is stored, who else touches it, and how to get it back or get rid of it. It is written to be read, not to be skipped.

Last updated: 21 July 2026

1. Who we are

Whalur is a market research and signal discovery platform operated by Guud AI. When this policy says “we” or “Whalur”, it means the operator of the whalur.guud.ai service. You can reach us at [email protected].

2. What we collect

Account information

When you create an account we store the email address and name you give us, and a bcrypt hash of your password. We do not store your password itself, and a bcrypt hash cannot be reversed back into it — which is also why we cannot tell you what your password is if you forget it, only help you set a new one.

The research you create

Whalur stores the hypotheses, strategies, parameters, notes, backtest runs and results you create on the platform, along with which of them you marked public or private, and any alerts or watchlists you set up. Public hypotheses are visible to other users by design. Private hypotheses are visible only to you, to anyone you explicitly share them with (friends, or buyers if you sell access as a creator), and to Whalur administrators who can technically read any record in the database — see section 5.

Usage and analytics

We record ordinary server-side operational data: which pages and API endpoints were requested, timestamps, IP address, browser user agent, and errors your browser or our backend produced. We use this to keep the service running, to find bugs, and to understand which features get used. We do not sell this data, and we do not run third-party advertising trackers on the site.

Payment data

Payments are processed by PayPal. Whalur never sees, receives or stores your card number, bank details or PayPal password. When you subscribe, you are sent to PayPal to approve the subscription. PayPal sends us back a subscription identifier, a plan identifier, the subscription status, and the dates it started and renews. That is what we keep, and it is all we keep. PayPal's handling of your payment details is governed by PayPal's own privacy policy.

If you sell access to your research as a creator, we also store the PayPal email address you tell us to send your payouts to.

Email

Transactional email — account confirmation, password resets, alert notifications, billing notices — is delivered through the Guud AI platform's email provider. Your email address and the contents of those messages pass through that provider so it can deliver them. We do not sell your email address or rent it to anyone.

3. Cookies and local storage

Whalur does not use advertising or cross-site tracking cookies. When you log in, your session token is stored in your browser's localStorage under the key whalur.session, together with basic profile fields such as your name and email so the header can greet you without an extra request. That token is what keeps you signed in. It stays in your browser until you log out, until it expires, or until you clear your browser's site data. Logging out removes it.

4. Why we are allowed to hold it

We process your account and research data because it is necessary to provide the service you asked for. We process payment metadata to fulfil the subscription contract between us. We process usage and error data under our legitimate interest in keeping a working, secure product. Where we rely on your consent — for example optional notification emails — you can withdraw it at any time.

5. Who can see your data

  • You — everything in your account.
  • Other users — only what you made public, shared with a friend, or sold access to.
  • Whalur administrators — staff accounts flagged as administrators can read any record, including private hypotheses. This is an honest statement of how the system works, not a promise that we routinely read your research; we look at individual accounts to investigate abuse, fix bugs, or when you ask us for support.
  • PayPal — for payments and payouts.
  • Our email provider — to deliver messages to you.
  • Our hosting provider — the servers the application and database run on.

We do not sell your personal data. We will disclose data if we are legally required to, and we will tell you if we are permitted to.

6. Security

Traffic to and from the site is served over HTTPS. Passwords are stored as bcrypt hashes. Session tokens are signed and expire. Database backups are taken nightly and rotated. We make no claim to any external certification or audit — we have not been through one — and no online service can promise perfect security. If we discover a breach that affects your data, we will tell affected users by email.

7. How long we keep things

  • Account and research data — for as long as your account exists.
  • Server and error logs — typically a few weeks, then rotated away.
  • Billing records — subscription and payout records are kept for up to seven years after the transaction, because we may need them for tax and accounting purposes. This survives account deletion.
  • Database backups — the rotating backup set means deleted data can persist in backups for up to about a week before it ages out.

8. Your rights

You can, at any time:

  • Access your data — most of it is visible in the app; ask us for the rest.
  • Export your hypotheses and account data — email us and we will send you a machine-readable copy.
  • Correct anything wrong — your name and email can be changed from your account page, or ask us.
  • Delete your account and its contents.
  • Object to a particular use of your data, or withdraw a consent you gave.

Requesting deletion

Email [email protected] from the address on your account with the subject “Delete my account”. We will confirm, then remove your account, your hypotheses, your backtest history and your alerts. We aim to complete this within 30 days. Two things survive: billing records we are required to retain (section 7), and public hypotheses that other users have already built on, which are anonymised rather than removed so their research does not break. If you want those removed too, say so and we will discuss it. If you have an active subscription, cancel it first or ask us to cancel it as part of the deletion — deleting your account does not automatically stop a PayPal subscription that is billed on PayPal's side.

9. Children

Whalur is not intended for anyone under 18, and we do not knowingly collect data from anyone under 18. If you believe a minor has created an account, email us and we will remove it.

10. International transfers

Our servers, and those of PayPal and our email provider, are located in the United States. If you use Whalur from elsewhere, your data is transferred to and processed in the United States.

11. Changes to this policy

If we change this policy we will update the “Last updated” date at the top of this page. If the change materially affects how we use your data, we will email account holders before it takes effect. Continuing to use Whalur after a change means you accept the updated policy.

12. Contact

Questions, data requests, complaints and corrections all go to [email protected]. A human reads it.

See also the Terms of Service, which include the risk disclosure that applies to everything Whalur publishes.

Powered by guud.ai