Privacy notice
Effective 2026-10-09. This explains what Pip collects and what you can do about it.
What we collect
- If you join the waitlist: your email address, the ticker you chose, and which signup form you used.
- If you request a ticker: the ticker symbol you asked for, and your email address so we can tell you when it's covered.
- If you subscribe by email: your email address, chosen ticker, confirmation time, signup source and campaign tags, subscription status, and feedback you submit.
- If you use the bot: your Telegram chat ID and handle, the stocks you own, the reasons ("why") you gave for each, your risk preference, and logs of your interactions with Pip.
- Email signup protection: a hashed network address and recent request times to limit repeated signup attempts.
- Basic analytics: standard usage analytics. When you submit the signup form, analytics records which form you used and whether you picked Telegram or email. It never records your email address.
How we use it
To generate your briefings, to operate and improve Pip, and to contact you about the beta. We do not sell your data.
Who receives your data
Running Pip means some of your data passes through providers we use:
- Cloudflare — hosting, and the waitlist form on this site, which also takes ticker requests (it holds the waitlist and ticker requests). Cloudflare also stores email signup and consent records and feedback awaiting import into Pip.
- Resend — sending confirmation, welcome and briefing emails. It processes the recipient address and message content, and keeps delivery records and suppression information for failed or stopped delivery. We do not enable open pixels or rewrite your source links for click tracking.
- Google Analytics — usage analytics.
- PostHog (EU servers) — usage analytics, without cookies.
- Telegram — delivering your briefings; it handles your chat ID and the message itself.
- OpenAI (the company that makes ChatGPT) — its AI model writes the wording of your briefing. It receives the stock, the reason you gave for holding it, and the evidence Pip gathered. It is not given your name, your email address, your Telegram handle, or your chat ID — the text it writes is assembled with your identity kept out of it. Your reason is passed as you wrote it, so leave personal details out of it. OpenAI keeps this data for up to 30 days to monitor for abuse, and does not use it to train its models.
- OpenRouter — the service Pip uses to reach OpenAI's model. It receives the same information, and handles each request temporarily to pass it to OpenAI; its terms don't say for how long. Pip has set it to send requests only to OpenAI, never to another provider, with its "deny data collection" setting switched on. OpenRouter does not use what passes through it to train models, and Pip has not turned on its optional logging of requests.
- Google (Gemini) — the alternative AI model Pip may switch to for writing your briefing. When it is in use, it receives the same information instead of OpenAI and OpenRouter: the stock, the reason you gave for holding it, and the evidence Pip gathered. It is not given your name, your email address, your Telegram handle, or your chat ID — the text it writes is assembled with your identity kept out of it. Your reason is passed as you wrote it, so leave personal details out of it.
Where Pip reads from
To find out what happened to a company, Pip queries public and licensed data sources: SEC EDGAR for filings, plus market-data and news providers for prices and coverage.
These sources receive nothing about you. Pip asks them about a ticker symbol — never your name, your chat ID, your email, or the reason you gave for holding anything. They cannot tell that a question came from you, or that anyone owns the stock at all.
We change these providers from time to time as licensing and quality require. Because they never receive your personal data, a change to them does not change what happens to your information.
Where it's stored and how it's protected
Your bot data is stored on a private, access-controlled machine with encrypted backups. We keep it only while your account is active. Waitlist emails are kept until you ask us to remove yours, or until the beta invitation process is finished. Ticker requests are kept until we've told you the ticker is covered, or until you ask us to remove yours.
Unconfirmed email signups expire after seven days and are removed during the next weekday sync. Signup rate-limit records retain a hashed network address; old request times are discarded when that address makes another request. Confirmed email subscriptions are retained while the account exists, including an inactive subscription after you unsubscribe. Unsubscribing stops email delivery; it does not delete the account. Resend retains its own delivery records under its retention policies.
Your rights
You can ask to access, correct, or delete your data. Under Israel's Privacy Protection Law and comparable rules (e.g. the GDPR), these rights apply to you.
- Bot data: send /delete in Telegram. This erases your local profile and associated briefing data. For email-linked accounts, a one-way identifier hash and deletion time remain to prevent an old signup record recreating the account; they contain no email address, holdings or reasons. External provider records follow the deletion process below.
- Email subscriptions: use the unsubscribe link in an email to stop delivery. To request deletion of your subscription and provider records, email hello@pipthebot.com. Provider delivery history may remain until its retention period ends.
- The waitlist or a ticker request: email hello@pipthebot.com and we'll remove your address. /delete in Telegram does not reach either of them — they are stored separately from the bot, so please say which ones you want removed.
See How to cancel.
International transfer
Pip is operated from Israel and uses US-based providers, so your data may be processed in those countries. OpenRouter may also process it in other countries.
Children
Pip is not for anyone under 18, and we don't knowingly collect their data.
Changes and contact
We may update this notice; we'll post it here with a new effective date. Questions: hello@pipthebot.com.