Privacy Policy

Last updated August 28, 2026

DogBone Capital is a university investment-club platform. All trading on the platform is simulated. This policy explains what personal data we collect, why, who processes it on our behalf, how long we keep it, and the choices you have.

Who this applies to

It covers visitors to our public Research Hub (research, team, fund, and subscribe pages) and members who sign in to the platform. “We” refers to the DogBone Capital investment club operating this platform.

What we collect and why

We only collect data needed to run the club platform:

  • Account identity (via Google sign-in). When you sign in we receive and store your email address, name, and profile image from Google, and we store the OAuth tokens needed to maintain your session. This is how we authenticate you and control access.
  • Member profile. Optional fields you choose to add: profile photo, bio, headline, skills, university, graduation year, and a LinkedIn URL, shown on your member page and the public team page.
  • Trading activity (simulated).The orders, fills, positions, ledger entries, realized P&L, and any journal/thesis notes you record. These power your portfolio, performance, and the club leaderboards.
  • Research contributions. Research you upload (files stored in object storage) and contributor attribution (display name, and an email if provided) shown on published research.
  • Newsletter subscription. If you subscribe, your email, optional name, and your frequency/content preferences, plus when you subscribed and the source of that consent.
  • Access requests. If you request access, the email, name, and message you submit, so an administrator can review it.
  • Technical and product telemetry. Standard server logs and in-app event records (e.g. news-pipeline and engagement events) used to operate, secure, and debug the platform. This includes how long a page stays open (time-on-page), tied to your account when signed in or the same cookie-less, browser-local identifier already used for page views when signed out. This is never a third-party analytics service. If error tracking is enabled, diagnostic error reports are sent to our error-tracking processor with PII scrubbing at the boundary.
  • Problem reports you submit.If you use “Report a problem,” we store the page, your description, and, only if you check the technical-context box, the current page, browser identifier, and recent on-screen error text your browser already held. That box is never checked for you, and a report never includes your portfolio holdings or trading activity.

We do not sell personal data, run advertising, or use third-party analytics/marketing trackers.

How we detect duplicate accounts

The club enforces a one-account rule (see our Terms of Use). To identify accounts that may belong to the same person, we compare only these signals:

  • emails you have linked to an account, or that match an email linked to another account;
  • your declared name and university, matched against another account’s;
  • your Google sign-in (SSO) identity; and
  • your LinkedIn URL, if you have provided one, matched against another account’s.

That is the complete list. We do not use device or browser fingerprinting, IP address correlation, or any capture of your prompts, keystrokes, or session activity to detect duplicate accounts, and we do not reserve a general right to use signals beyond the four above. A match creates an internal record for review, not an automatic suspension; both accounts are notified of what was found and how to respond before any account restriction takes effect.

Decision provenance

Where the platform records the history behind a decision, such as a trade idea, an order, a strategy version, a declared data source, or a disclosure flag, we call that a decision artifact. We keep an audit trail of these enumerated artifacts, not a general log of your activity. We do not capture keystrokes, browsing history, session recordings, or the raw prompts and transcripts of your conversations with an AI assistant. If you use an AI assistant, the record discloses that assistance happened and which model was used; the full prompt or transcript is attached to your record only if you choose to attach it. Provenance for an external dataset you declare using is self-attested: it records what you told us you used, not an independent verification of that dataset. This provenance is retained for as long as you hold the associated record, follows the same archived-season presentation as the rest of your history, and is removed on account deletion along with the rest of your personal data.

Product usage analytics (your choice)

Signed-in members can share first-party product-usage analytics that help us understand how the platform is used and where it can improve. It is on by default and you can turn it off with one tap during onboarding or any time under Settings → Privacy & data. When it is off, your account generates no behavioral analytics events on our servers. This is a real off switch, not a hidden collection. It is all first-party; we never send this to a third-party analytics service.

When it is on, we record:

  • Page/route views and how long a page stays open (dwell time).
  • Which features you interact with and for how long (e.g. chart tools, opening the order ticket, opening a research document, invoking the copilot, viewing an unlock step, acknowledging the welcome message, opening or confirming a fund mandate, starting a calibration or unlock test): counts and durations, not the content.
  • Whether you opened a key communication, such as the welcome message, the leadership handbook, a fund mandate document, or an announcement page, and how long it stayed open. We record which communication and the dwell time, never the communication’s own text.
  • A coarse device class (mobile / tablet / desktop and a viewport size bucket), never a device fingerprint.
  • A profile-completeness snapshot (what percentage of fields are filled and which sections are empty).
  • Your progression through the onboarding and unlock funnels.

Even when it is on, we never collect through this:

  • Page content, keystrokes, or anything you type.
  • Your order details, positions, or trading activity.
  • Research document content or copilot prompts and responses.
  • Precise geolocation or your contacts.

Who can see it

Admins and fund advisors can see a summary built from these events for a member in their organization: which communications you have read and for how long, your onboarding progress, your active days, which features you have used, and your quiz and calibration results. They never see the underlying event-by-event log, only this summary. Every time an admin or advisor opens a member’s summary, that view is itself logged. If your usage analytics is off, your summary shows as off, not reconstructed from any other source.

Turning usage analytics off does not affect the operational records we must keep to run the club safely: authentication and security logs, your order and ledger records, scrubbed error diagnostics (if error tracking is enabled), and metering of AI/tool usage for billing. Those are not behavioral analytics and are described elsewhere in this policy.

Service providers (processors)

We share data only with providers that help us run the platform:

  • Google: sign-in / OAuth identity.
  • Neon: managed PostgreSQL database hosting our records.
  • Cloudflare R2: object storage for profile photos and research files.
  • Fly.io: application hosting and server infrastructure.
  • Resend: transactional and newsletter email delivery.
  • Alpaca: market data only (quotes/bars). We send symbols, not your personal data; no real brokerage account or order is created.
  • Finnhub and Tiingo: market news ingestion. We send symbols, not your personal data.
  • The configured LLM provider (e.g. OpenAI, Anthropic, or Groq): used to screen news articles and, if you use the order copilot, to review the order context you submit. We do not send your account identity for these calls.
  • An error-tracking provider (e.g. Sentry): only if enabled, for diagnostics.

Cookies and sessions

We use a single essential cookie: an authentication session cookie set when you sign in (our sessions are stored server-side in our database). We also store your light/dark theme preference in a cookie for convenience. We set no analytics, advertising, or cross-site tracking cookies, so no consent banner is required for non-essential tracking.

How long we keep data

Account, profile, trading, and research records are retained while you are a member and for the club’s historical and audit purposes. Operational data is pruned on a schedule: for example non-portfolio news after 30 days, portfolio-relevant news after 365 days, dismissed alerts after 90 days, and hourly snapshots after 30 days.

When a member departs, we anonymize their personal profile data while preserving the integrity of append-only financial records (which are anonymized rather than deleted). You can ask us to do this sooner (see your rights below).

Your rights and choices

  • Access / export. Signed-in members can export their account data from Settings, or request a copy from us.
  • Correction. Update your profile fields anytime under Settings.
  • Deletion / anonymization.You can ask us to delete or anonymize your account. Financial ledger records are anonymized rather than hard-deleted to keep the club’s books consistent.
  • Newsletter opt-out. Every email includes a one-click unsubscribe link; you can also manage preferences on the Subscribe page.

Contact

Questions or requests about your data? Contact a club administrator, or request access via our access request page. See also our Terms of Use.