Legal and trust
Privacy Policy
Effective and last updated: August 5, 2026
1. Who operates takehold
takehold is operated by Anthony Vecchione, an individual based in New Hampshire, United States. In this Privacy Policy, “takehold,” “we,” “us,” and “our” refer to Anthony Vecchione as the operator of the takehold service.
This Privacy Policy explains how we collect, use, disclose, and retain information when you use https://takehold.app and its related features (the “Service”).
2. The Service and its privacy spaces
takehold has two distinct privacy spaces:
- Take is collaborative. Its watchlists, Takes, Group Notes, shared chart workspaces and annotations, and related activity are available only to current members of the relevant watchlist, subject to the historical-content rules described below.
- Hold is owner-private. Imported holdings, Portfolio, Portfolio Analysis, holding detail, source management, and owner-specific Portfolio News selections are available only to the account owner.
takehold is not a public social network. It does not provide public profiles or public posts.
3. Information we collect
Account and profile information
We collect or process:
- your email address;
- an optional display name;
- internal user, membership, invitation, and account identifiers;
- authentication, password-reset, confirmation, and session information; and
- account and security events needed to operate and protect the Service.
Authentication is provided through Supabase. takehold does not store plaintext passwords.
Collaborative Take information
When you use Take, we collect the content and activity you choose to create, which may include:
- watchlist names, membership, invitations, and ticker selections;
- Idea Takes, Position updates, reasons, conditions, stances, targets, dates, and price anchors;
- optional share quantities and action-price information entered in a Position update;
- Group Notes;
- collaborative chart workspaces, annotations, levels, trendlines, and related author attribution; and
- activity necessary to display Take Receipts and recorded Position activity.
If you enter shares in a Position update, those shares are visible to current members of that watchlist. You can leave the shares field blank.
Private Hold and portfolio information
When you use Hold, we collect or derive private information such as:
- normalized holding symbols and descriptions;
- quantities, currencies, cost information, imported values, and source metadata;
- current-value, allocation, concentration, gain/loss, daily-movement, and risk-model calculations;
- import freshness and removal status; and
- owner-private Portfolio News refresh and feed information.
Hold information is not shared with watchlist members. Imported holdings do not become Takes, Take Receipts, or collaborative portfolio history.
CSV import information
When you upload a holdings CSV, the file is processed to identify and normalize current positions. We do not retain the raw CSV file, its filename, brokerage account identifiers, raw rows, brokerage credentials, or the raw AI prompt or response.
We retain only the normalized holdings you choose to save and limited safe mapping/source metadata needed to operate the import. If optional AI-assisted mapping is enabled, only redacted structural information, such as column-header context, may be sent to OpenAI. Raw holding rows, quantities, values, cost basis, account identifiers, and brokerage credentials are not sent to OpenAI for mapping.
Market-data and Portfolio News information
We process public instrument identifiers, such as ticker symbols and listing information, to obtain quotes, chart data, fundamentals, and public price history from Twelve Data and public sources.
Portfolio News uses detached, public-only instrument requests. OpenAI and public-source systems receive one public instrument at a time and do not receive your identity, complete portfolio, quantities, values, weights, cost basis, gain/loss information, brokerage/import context, Takes, Notes, collaborators, or private rankings. Private ranking occurs inside takehold.
Portfolio News stores verified public metadata, such as a direct source URL, headline, source label, publication date, source type, and article format. It does not store article bodies, excerpts, AI-written summaries, sentiment, or investment advice.
Technical information
Our hosting, authentication, security, and email providers may process technical information such as:
- IP address;
- browser, device, and operating-system information;
- requested pages, timestamps, referrers, and diagnostic or error information;
- authentication and session identifiers; and
- security and operational logs.
takehold does not currently use advertising pixels, behavioral advertising, third-party session replay, Google Analytics, or similar product-analytics services.
Communications
If you contact us, we collect the information in your message and the contact information needed to respond. This includes support, privacy, security, abuse, and copyright-related correspondence.
We do not currently operate a marketing-email or SMS program. We may send service-related messages such as account confirmation, password reset, invitations, security notices, support responses, and material policy or service notices.
4. Cookies and browser storage
takehold uses necessary authentication and security cookies so that users can sign in and remain signed in. It also uses limited functional storage for preferences such as the Take/Hold orientation, theme, chart indicators, and chart-layer visibility.
Depending on the feature, these may include:
- session cookies that end with the browser session;
- persistent authentication or preference cookies that may last for up to 400 days; and
- local or session storage for interface preferences. Session-storage preferences end when the browser session ends.
takehold does not currently use cookies for advertising, cross-site tracking, or behavioral analytics. Because only necessary and limited functional technologies are currently used, takehold does not currently provide a separate advertising-cookie consent banner. If we add nonessential tracking technologies, we will update this Policy and implement any consent mechanism required by law.
5. How we use information
We use information to:
- create, authenticate, secure, and support accounts;
- provide private watchlists and authorized collaboration;
- process and display Takes, Notes, chart work, invitations, and Take Receipts;
- process private holdings imports and provide owner-private portfolio views and calculations;
- obtain and display public market data and direct-source Portfolio News metadata;
- maintain, troubleshoot, secure, and improve the Service;
- respond to support, privacy, security, abuse, and legal requests;
- detect fraud, misuse, unauthorized access, or violations of our Terms; and
- comply with law, enforce agreements, and protect users, the public, and the Service.
We do not use personal information for targeted advertising, sell personal information, or share personal information for cross-context behavioral advertising.
6. When information is disclosed
Authorized collaborators
Content you place in Take is disclosed to current members of the relevant watchlist. This can include optional shares if you enter them in a Position update. Historical live content may remain visible to current members after an author leaves or is removed. Hold data is not disclosed to collaborators.
Service providers
We use service providers to operate the Service:
- Supabase provides authentication, sessions, database infrastructure, and storage of account, collaborative, private holdings, and Portfolio News records. Its privacy notice is available at https://supabase.com/privacy.
- Vercel provides hosting, server execution, delivery, and operational request logging. Its privacy notice is available at https://vercel.com/legal/privacy-notice.
- OpenAI provides optional redacted CSV-structure mapping and public single-instrument Portfolio News discovery. Our current API requests use
store: false, but that is not a promise of Zero Data Retention. OpenAI may retain API abuse-monitoring logs for up to 30 days unless a longer period is required by law or needed to protect its services or others. Its privacy policy is available at https://openai.com/policies/privacy-policy/. - Twelve Data provides public market search, quotes, candles, fundamentals, and public instrument information. It receives public instrument parameters, not private portfolio facts. Its privacy policy is available at https://twelvedata.com/privacy.
- Google Workspace provides support, privacy, security, and business email. Its privacy policy is available at https://policies.google.com/privacy.
We use these providers for the purposes described above. Each provider may also process information under its applicable agreements and privacy materials, including for security, abuse prevention, legal compliance, and operation of its services.
Third-party sources and links
The Service can link to the SEC, public publishers, and other external sources. If you click an external link, the destination can receive normal browser-request information such as your IP address, browser details, and the referring page. Those sites are governed by their own policies. takehold does not control them.
Legal, safety, and business transfers
We may disclose information when reasonably necessary to comply with law or valid legal process; protect rights, safety, and security; investigate misuse; or establish, exercise, or defend legal claims.
If the Service or its assets are involved in a merger, financing, acquisition, reorganization, or sale, information may be transferred subject to appropriate notice and the protections required by law.
With your direction or consent
We may disclose information when you direct us to do so or provide valid consent.
7. Data retention and deletion
We retain information for as long as reasonably necessary to provide and secure the Service, maintain authorized collaborative records, fulfill the purposes described in this Policy, resolve disputes, enforce agreements, comply with law, and respond to verified privacy requests.
Important current retention details include:
- Raw uploaded CSV files, filenames, account identifiers, raw rows, and raw AI payloads are not retained.
- Normalized holdings and safe source/mapping metadata remain until they are replaced, removed, the account relationship ends, or a verified request is completed, subject to the limitations below.
- Historical collaborative content can remain after a person leaves or is removed from a watchlist.
- Deleting an individual Take, Group Note, annotation, workspace, or holding may hide or deactivate it without immediately and permanently purging the underlying record. takehold does not currently promise a fixed purge period for every inactive or soft-deleted record.
- When Portfolio News is enabled, its current retention schedule is up to 30 days for owner refresh and feed records, up to 100 days for public jobs and accepted public candidates, and up to 400 days for provider-accounting records. Operational, security, legal, and backup exceptions described in this section may apply.
- Authentication, orientation, and other persistent preference cookies may remain for up to 400 days unless cleared sooner.
- Operational, security, and support records may be retained as reasonably necessary and under the retention practices of the applicable service provider.
- Residual copies can remain temporarily in provider backups or disaster-recovery systems and are not ordinarily restored except for security, continuity, legal, or recovery purposes.
The Service does not currently offer self-service account deletion. To request access, correction, account deletion, or deletion of personal information, email privacy@takehold.app. We may need to verify your identity. We will evaluate and complete requests as required by applicable law and may retain information where permitted or required for security, legal obligations, disputes, fraud prevention, or the rights of other users.
8. Your choices and rights
You may:
- update your available profile information;
- choose not to enter optional profile, Take, Note, chart, share, or holdings information;
- edit or delete certain content through available in-product controls;
- leave a watchlist, subject to the historical-content rules above;
- clear cookies or browser storage through your browser, recognizing that this may sign you out or disable preferences; and
- contact privacy@takehold.app to request access, correction, deletion, or other rights available under applicable law.
We may ask for information reasonably necessary to verify identity and protect the privacy of other users. Authorized agents must provide valid authority where applicable.
9. California disclosures and Do Not Track
takehold does not sell personal information or share it for cross-context behavioral advertising. It does not currently use third-party advertising, behavioral analytics, or session-replay tools.
The Service does not currently respond to browser “Do Not Track” signals. Because takehold does not currently engage in cross-site behavioral tracking, changing a DNT signal does not alter the Service's present practices. We do not knowingly permit third parties to collect personally identifiable information over time across unrelated websites or online services through takehold for targeted advertising.
California users may contact privacy@takehold.app to review or request changes to personal information as described in this Policy. If our practices or applicable legal obligations change, we will update these disclosures.
10. Children and minors
The Service is not directed to children under 13, and users under 13 may not create an account or use the Service. We do not knowingly collect personal information from children under 13.
If you are at least 13 but below the age of legal majority where you live, your parent or legal guardian must review and agree to the Terms and authorize your use of the Service. If you believe a child under 13 has provided personal information, contact privacy@takehold.app so we can investigate and take appropriate action.
11. Security
We use administrative, technical, and organizational measures designed to protect information. No Internet transmission or storage system is completely secure, and we cannot guarantee absolute security.
Report suspected security issues to security@takehold.app. Do not publicly disclose a suspected vulnerability before giving us a reasonable opportunity to investigate it.
12. International use
takehold is currently offered as a free, publicly accessible beta. Initial outreach may be limited, but eligible users who reach the website may create an account normally. Public account creation does not change the Take, Hold, holdings, or Portfolio News privacy boundaries described in this Policy. The beta is intended for users in the United States. Information may be processed in the United States and other locations where our service providers operate. If you access the Service from another jurisdiction, you are responsible for ensuring that your use is lawful there.
13. Changes to this Policy
We may update this Policy as the Service or legal requirements change. We will post the updated Policy and revise the “Last updated” date. Where required by law or appropriate for a material change, we will provide additional notice through the Service or by email.
14. Contact
Privacy questions and requests: privacy@takehold.app
General support: support@takehold.app
Security reports: security@takehold.app
Contact page: https://takehold.app/contact
