Privacy Policy
WMW - Wavi Market Watch (formerly called Market Sentiment)
Effective date: 2026-10-09
Last updated: 2026-10-09
Operator: Wa-Vi ("we", "us") · Contact: privacy@wa-vi.com
1. What this policy covers
This policy explains what information WMW - Wavi Market Watch (the "App") collects, how it is used, how long it is kept, and the choices you have. It applies to the App's website at mw.wa-vi.com (its earlier address, sentiment.baalzebubba.cloud, now sends you there). The App is private: you can only have an account through an invitation the operator e-mails you or an invite link the operator makes.
2. Information we collect
Your account. Your e-mail address; the display name you choose, if any; when the account was created and when you first set a password; how and when you were invited (an invitation an administrator e-mailed you, an invite link, with when it was made and used, or, for the operator's own account, the server's setting) and who invited you; who last changed your account's standing (for example, a revocation or a reinstatement) and when; your account's status (for example, active or revoked) and whether you are an administrator; your password, stored only as a scrypt hash (never the password itself); for each passkey you register, its public key and its details (a name you can change, when it was added and last used, the App address it was made on, and technical details your device reports about it, such as its signature counter and its credential identifier), and a random identifier the App gives your passkeys (never your e-mail address or account number); for 7 days after you reset your password by e-mail, a hold on setting up a first passkey by e-mail; your signed-in sessions (for each, the IP address it was started from and the description of itself your browser sent then, its "user agent"; when it was started, last used and expires; when its passkey check was made and last used; a fingerprint of its cookie; and, while Plaid Link is open, a fingerprint of the Link token, never the token, and when that token expires); when you last signed in and when you last used the App; if the account goes unused for 11 months, when we e-mailed you about it and the date that e-mail named; whether your e-mail address is confirmed; the one-time links the App e-mails you (an invitation, a password reset, an address confirmation or a passkey approval), kept only as fingerprints that can't be turned back into the link, with when each was made, expires and was used; when you agree before connecting a brokerage, the date and the version of this policy you agreed to; and, for an account that asked for access before 2026-10-04, when the App still had a request form, the note and the IP address that request recorded.
What you add. Your watchlists, their tickers, their order and your notes; the portfolios you create (their names) and the holdings you enter by hand (tickers, shares, costs and the currency they are in, dates, the exchange rate for a purchase, account labels and cash balances); your target allocation; the classifications you set for a holding; and your preferences, such as the currency values are shown in.
Brokerage data from Plaid. If you choose to connect a brokerage, you do so through Plaid Inc. ("Plaid"): you sign in through Plaid (in Plaid's window or on your brokerage's own site), and we never see or store the password for your brokerage. The App uses Plaid's Investments product only, and gets:
- The brokerage's name.
- Each investment account's name, type and last 4 digits.
- Your holdings: each security's name, ticker, type and the exchange it trades on, the quantity, its cost basis, its value and its currency.
- Cash balances.
Nothing else: no transactions, no identity details (such as your name, address or phone number), and nothing from any other account at the same login. Plaid's answer also lists such an account, a checking account for example, with its balance; the App imports none of it and keeps only how many accounts it skipped. Plaid's answers carry more than the App keeps: it reads past, and never stores, such details as each account's overall balances and official name and the securities' identification numbers. An account's name is the one your brokerage gives it, which can include your name. With each connection the App also keeps Plaid's identifiers for the login, the brokerage and each account, the report of the last sync (which names any holding it skipped, and why), and what Plaid reports about the connection: when it last updated the data, an error such as a sign-in that needs renewing, the date your consent to the connection expires, and that new accounts are available to add. To tell its users apart, the App gives Plaid an internal account number, never your name or e-mail address. What the App keeps from a brokerage is a snapshot: each sync replaces the previous one (an account Plaid leaves out of an answer keeps its last snapshot).
Feature-usage counts. We count which features each person uses each day, with the hour of their last use (for example, that you opened the Portfolio tab or ran an analysis), never what you look at or own; the counts are kept 180 days and only the operator can see them, apart from you: your own are in "Download my data".
Account activity log. A record of account events, such as each sign-in (with how you signed in, the kind of browser and device, for example "Safari on iOS", and the network part of the IP address; a passkey sign-in is also recorded with the IP address itself), each passkey check, failed sign-ins, invitations, changes to your display name, password, passkeys and brokerage connections, devices you signed out, and your consent before connecting a brokerage, each with the time and its details. Most records name your account by its e-mail address, and records about brokerage connections by its number. The IP address itself is recorded for a passkey sign-in, a sign-up through an invite link, a password reset asked for or completed, an e-mail confirmation and your consent; a failed sign-in records no IP address, and one for an address with no account records only the time.
Brokerage billing records. For each brokerage connection: when it was connected, last synced and removed, its Plaid ID and the brokerage's name (once a connection has been removed for 24 hours, the next nightly run replaces its ID with a one-way fingerprint and drops the name, so within about two days of the removal), and your account number; and each paid refresh you ask for (with your e-mail address until your account is deleted), so the operator can check what Plaid bills.
Privacy requests. When you download your data, disconnect a brokerage, delete your account or e-mail us a request about your data, when the App itself deletes an inactive account or removes a connection that stopped syncing, and when Plaid tells the App you revoked its access (to a connection at my.plaid.com, or to one account at your brokerage), a record of what was asked or done and when, naming your account by its number, never by your e-mail address.
Server logs. For each request: the IP address, the time, the page or address requested (which can include a ticker symbol, the text of a search, or a figure you typed that the page sends in its address, such as new money to invest; the App never puts a password or an access token in an address, and the secret part of a one-time link is removed), the browser, and the request's outcome, size and duration. They also hold the App's own lines about its work, which name an account or a brokerage connection by its number and an e-mail address only by its first letter and domain, and they record each request the App makes to Plaid: the time, which Plaid service, the outcome, Plaid's reference numbers for the request and for your connection session, and the connection's number in the App; never your credentials, account numbers or holdings. They are kept no longer than 90 days.
Cookies and your browser's storage. Two cookies, both strictly necessary: a session cookie that keeps you signed in, and a form-protection (CSRF) cookie. Your browser's local storage holds display preferences (such as the watchlist and portfolio you last picked); while Plaid Link is open, its link token, which the App stops using after 30 minutes and removes the next time it runs or when you sign out; and, for a few minutes after you come back from your brokerage, the message that says how the connection went. No advertising cookies and no third-party trackers. Plaid Link, which runs from Plaid's site only while you connect, may keep its own storage there under Plaid's policy.
3. How we use your information
We use your information to:
- run your account and sign you in (your password, passkeys and sessions);
- show and value your watchlists, your portfolios and the brokerage accounts you connect, and compare them with your targets;
- keep the App secure (rate limits, passkey checks, the activity log, abuse detection and incident response);
- see which features are used, to improve the App;
- respond to your requests and provide support; and
- comply with legal obligations.
We do not sell your personal information, share it with advertisers or data brokers, or use it for purposes this policy does not describe. We do not use your data to train machine-learning models.
4. Your consent and Plaid's role
Before your first brokerage connection, and again before the next one whenever this policy's "Last updated" date changes, you are shown a consent screen that says what the App gets and why, how long it is kept, and Plaid's role. The App opens Plaid Link, to connect a brokerage, reconnect one or add new accounts to it, only after you have agreed to the current version of this policy; a Plaid Link already open when the policy changes is finished under your earlier agreement. You connect through Plaid Inc., which retrieves data from your brokerage and shares it with us under Plaid's own End User Privacy Policy. You can review and revoke the App's access at any time at my.plaid.com, and you can disconnect any brokerage from within the App.
Plaid also notifies the App about your connections, and the App acts on a notice only once Plaid's signature on it checks out: that new data is ready (the App then syncs the connection); that a connection needs you to sign in again or will stop working on a date (Settings then offers Reconnect); that new accounts are available (Settings then offers to add them, through Plaid Link, after the same consent); and that you revoked the App's access. When you revoke it at my.plaid.com, the App removes the connection and deletes its synced portfolios; if Plaid can't confirm the removal right away, the connection never syncs again, its data is deleted, and the removal is retried every hour. When you revoke one account at your brokerage, the App deletes that account's synced portfolio.
5. How we protect your information
Your data travels encrypted (TLS 1.2 or higher) between your browser and the App, and between the App and Plaid. Seeing or connecting brokerage data needs a recent passkey check (phishing-resistant multi-factor authentication), however you signed in. A new connection is kept only if the browser that finishes it has a recent passkey check, or had one when it opened Plaid Link; otherwise it is removed at Plaid and kept only as a billing record. Plaid access credentials are additionally encrypted in the database with a key kept outside it. Passwords are stored only as scrypt hashes. Only the operator administers the production server. It also hosts the operator's other projects, and the automated deployment jobs of the App and of those projects can reach it, as can a few older keys the operator is still confirming or removing. Every key with access is reviewed each quarter and removed when it is no longer needed. Backups are of two kinds: copies of the account database that the App makes on the server before each upgrade that changes it, deleted 35 days after they are made, and the hosting provider's weekly backups of the whole server, kept about two weeks. Our security practices are documented in an Information Security Policy that is reviewed at least annually; where this server does not yet meet it, the gap and how it is handled are recorded beside it.
6. How long we keep your information
| Data | Kept for |
|---|---|
| Plaid access credentials | Until you disconnect the brokerage, you revoke the App's access at my.plaid.com, your access is revoked, you delete your account, or the connection goes 24 months without a successful sync; then revoked at Plaid and deleted, normally within 24 hours (a removal Plaid has not confirmed yet is retried every hour). If Plaid can't be reached when you disconnect, or when your account is deleted or revoked, nothing changes and the App says so, so it can be tried again. If the App can no longer read a connection's credentials, it can't ask Plaid to revoke them: the operator removes that connection in Plaid's dashboard, and the App deletes its unreadable copy when the operator records that removal, or with your account if that comes first; the connection's synced data is deleted when the App sets it aside (unless you chose to keep a copy as your own portfolios) |
| Brokerage data (accounts, holdings, cash) | A snapshot replaced at every sync, kept until you disconnect (deleted then, unless you choose to keep a copy as your own portfolios), you revoke the App's access at my.plaid.com, your access is revoked or you delete your account (deleted then); if you revoke one account at your brokerage, that account's synced portfolio is deleted then, and its name, type and last 4 digits are kept until the connection is removed; deleted, and the connection removed at Plaid, if it goes 24 months without a successful sync (you are told by e-mail, at an address you have confirmed) |
| Your account and everything you added | Until you delete your account, which removes it all at once. An account other than the operator's that goes 12 months without using the App is deleted after a 30-day e-mail notice, sent only to an e-mail address you have confirmed; nothing is deleted without that notice, so nothing while the App can't send e-mail, and an account whose address was never confirmed is not deleted for inactivity: the operator reviews it. If a brokerage connection can't be released at Plaid right then, an inactivity deletion waits until it can, and a deletion you ask for is refused with the reason, so you can try again; a connection whose credentials the App can no longer read doesn't hold a deletion up (see the first row) |
| Account activity log | Sign-in events 90 days; other records up to 3 years, longer only while the account a record describes exists, or a bill still depends on it; your e-mail address and IP addresses are removed from them when your account is deleted, and so are your sign-ins' network and device |
| Brokerage billing records (dates, the connection's Plaid ID, replaced by a fingerprint within about two days of its removal, and your account number) | A connection's record: as long as your account exists. Each paid refresh, and each record of a connection being linked or removed: 400 days. When your account is deleted, the records of connections Plaid billed in that month or the month before are kept 400 days, and the rest are deleted with the account; the record of a connection the App could not release is kept until the operator records its removal in Plaid's dashboard, then 400 days |
| Records of your privacy requests (what you asked and when, never your e-mail address) | 3 years, also after your account is deleted |
| Feature-usage counts | 180 days |
| Server logs and the mail server's log | No longer than 90 days |
| Backups | The App's pre-upgrade copies of the account database (made before an upgrade that changes it) are deleted 35 days after they are made, and the hosting provider's weekly whole-server backups are kept about two weeks, so deleted data leaves every backup within 35 days of its deletion. One exception: after a rollback to an older release of the App, what that release deletes can stay in the database file, and so in the hosting provider's backups, until the App next rebuilds the file, which it does on any night it finds unused space in it |
7. Your rights and choices
Regardless of where you live, you can:
- Access and export the data we hold about you in a machine-readable format, with "Download my data" in Settings (it includes the IP addresses recorded in your own activity log and your sessions, each passkey's details and public key, and how and when you were invited and who last changed your account's standing, naming an administrator or an invite link only as such, never by address; it leaves out your password's hash, the secrets of your sessions and one-time links and their fingerprints, the fingerprint of an open Plaid Link, Plaid's access credentials, each passkey's credential identifier, your passkeys' random identifier, when a session's passkey check was last used, and some of the App's working records for a brokerage connection: Plaid's identifiers for the brokerage and accounts, the last sync's report and Plaid's status dates), or by e-mailing us, which can also cover what the download leaves out and the server logs;
- Correct your account information: change your display name and password in Settings, and e-mail us to change anything else;
- Delete your account and its data using "Delete my account" in Settings (it asks for your password, and the App then tells you the date by which every backup still holding it is deleted), or by e-mailing us; the records Section 6 says outlive an account are kept for the periods it lists;
- Disconnect any brokerage at any time, in Settings, after a passkey check (if Plaid can't be reached, try again later, or revoke at my.plaid.com);
- Withdraw consent by disconnecting or deleting your account, or at my.plaid.com (the record that you agreed stays with your account, so connecting again under the same version of this policy doesn't ask again).
We acknowledge requests within 10 days and complete them within 30 days (up to 45 days where the law allows, with notice). If you contact us outside the App we will verify the request by confirming control of your account e-mail before acting on it. We will never discriminate against you for exercising these rights.
California residents have the rights described above under the CCPA/CPRA, including the right to know, delete, correct, and the right to opt out of sale or sharing — we do not sell or share personal information as those terms are defined in the CPRA. Residents of other U.S. states, the EEA, or the UK with privacy laws have equivalent rights and may contact us the same way.
8. Sharing with service providers
We share information only with the providers needed to run the App:
- Plaid Inc. — brokerage account connectivity; Plaid handles what it retrieves under its own End User Privacy Policy (see Section 4).
- Hostinger International Ltd. — the server and its weekly backups, bound to use them solely on our behalf; the server is in Boston, Massachusetts, USA.
- Cloudflare, Inc. — receives e-mail sent to the contact address below and forwards it to the operator's mailbox.
- Google — hosts the operator's mailbox: e-mails you send us, and the App's alerts to the operator (which name a person's account by its number, apart from an administrator's own address), are kept in that mailbox.
E-mail the App sends goes out through a mail server we run ourselves on that same server, which logs each message's sender, recipient, time and delivery status and keeps that log no longer than 90 days; we use no third-party provider to send it.
Market data. To price and describe securities, including ones you hold, the App sends ticker symbols and company names (and the text you type into a search box) to Yahoo Finance, the U.S. Securities and Exchange Commission (EDGAR), GDELT and Wikipedia/Wikidata; never your name, e-mail address or account details. The dashboard's chart library loads from the jsDelivr network and, when you connect a brokerage, Plaid Link loads from Plaid's own site; like any website, they receive your browser's request (its IP address and browser).
We may also disclose information if required by law, to protect our rights or users' safety, or in connection with a merger or acquisition (in which case this policy continues to apply to your data).
9. Children
The App is not directed to anyone under 18 and we do not knowingly collect information from minors. If you believe a minor has provided us data, e-mail us and we will delete it.
10. Data location and transfers
Data the App holds is stored in the United States. If you access the App from outside the U.S., your data will be processed in the U.S. E-mail you send us is stored by Google (Section 8), which may keep it elsewhere.
11. Changes to this policy
If we make material changes we will post the new policy here, update the "Last updated" date, and notify you by e-mail before the change takes effect. Each such change asks you to agree to the new version before the App next opens Plaid Link for you (to connect, reconnect or add accounts); connections you already have keep syncing.
12. Contact
Wa-Vi · privacy@wa-vi.com