Privacy policy
WhaleCreep collects as little as it can. Reading the site needs no account and sets no tracking cookies. If you create an account, this page explains what is kept, why, where, and for how long.
Effective September 22, 2026.
Who is responsible
WhaleCreep (whalecreep.com) is run by Konstantinos Papadopoulos, an individual based in the United Kingdom, who is the data controller for the personal data described here. Contact: [email protected].
What is collected
If you only read the site
- Server logs. Like any website, the hosting (Google Firebase Hosting and Cloud Run) records each request: IP address, time, page requested, browser user agent and referrer. These logs are used only to keep the service running and secure.
- Settings in your browser. The site stores a few preferences in your browser's local storage: light or dark theme, and in the interactive board the timeframe, view, colour palette and section you last used. It also keeps a list of the funds you have opened (up to five) so the free guest limit works. None of this is sent to WhaleCreep or anyone else; it stays on your device and you can clear it at any time in your browser settings.
There are no analytics, advertising or social-media trackers on the site, and no cookies are set by WhaleCreep.
If you create an account
- Account details. Your email address and password, handled by Google Firebase Authentication. WhaleCreep never sees or stores your password; Firebase keeps only a salted hash. Firebase also records when the account was created and last signed in, and whether your email is verified. It keeps you signed in using browser storage.
- Your watchlist. The funds you choose to watch, when you added each one, whether filing emails are switched on, and the email address to send them to. Stored in Google Cloud Firestore.
- Email delivery records. Which filing alerts have been sent to you, so no email is ever sent twice.
- API keys (paid plans). For each key you create: the name you gave it, its first few characters, when it was created and last used, and a one-way hash of the key. The key itself is shown to you once and never stored. Calls made with a key are recorded in the server logs like any other request, and counted in memory for rate limits. The agent you connect (for example Muse or Claude) sends WhaleCreep only the tool calls it makes; what it does with the answers is governed by that provider's own privacy policy.
If you buy the Lifetime plan
- Payment. Payment is taken by Stripe on its own checkout page. WhaleCreep never sees or stores your card details. Stripe tells WhaleCreep that a payment succeeded, was refunded or was disputed, together with your account identifier, and the plan is recorded on your account. Stripe keeps its own records of the transaction (name, email, billing country, payment method details) as required by law. See Stripe's privacy policy.
Why it is used, and the legal basis
- To provide the service you asked for (performance of a contract): creating and signing in to your account, keeping your watchlist, sending the filing emails you switched on, taking payment and granting the plan.
- To keep the service secure and working (legitimate interests): server logs, preventing abuse and fraud, handling refunds and payment disputes.
- To meet legal obligations (legal obligation): keeping payment and tax records.
WhaleCreep sends account emails (verification, password reset) and, if you have the Lifetime plan and switch them on, filing alerts. There is no marketing email and no newsletter. Every filing alert has a one-click unsubscribe link. Your data is never sold, rented or used for advertising, and no automated decisions with legal or similar effects are made about you.
Who processes it
| Provider | What for | Where |
|---|---|---|
| Google (Firebase Authentication, Firebase Hosting, Cloud Run, Cloud Firestore, Cloud Logging) | Accounts, hosting, watchlists, server logs | Firestore and the API run in the EU (Belgium); Firebase Authentication and Hosting run on Google's global infrastructure, including the United States |
| Stripe | Payments | Ireland and the United States |
| Resend | Sending filing-alert emails | United States |
Each acts as a processor under a data processing agreement, or, for Stripe's own payment records, as an independent controller. Where data leaves the UK, it is protected by the UK's adequacy regulations (including the UK Extension to the EU-US Data Privacy Framework) or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.
How long it is kept
- Account, watchlist, API key and delivery records: until you revoke the key or ask for your account to be deleted.
- Payment records: six years after the purchase, as UK tax law requires.
- Server logs: about 30 days.
- Browser storage: until you clear it.
Your rights
Under UK data protection law you can ask to access the personal data held about you, correct it, delete it, restrict or object to its use, or receive a copy in a portable format. To delete your account, or to use any of these rights, email [email protected] from the address on the account. You will get a reply within one month. Deleting your account removes your login, watchlist, API keys and delivery records; payment records are kept for the period above.
If you are unhappy with how your data is handled, please get in touch first. You also have the right to complain to the Information Commissioner's Office (ico.org.uk).
Security
All traffic is encrypted in transit (HTTPS). Account data is only reachable through the authenticated API; the database is closed to direct access. Secrets are held in Google Secret Manager. No system is perfectly secure, and if a breach affecting your data happens you will be told as the law requires.
Children
WhaleCreep is meant for adults. Accounts are not for anyone under 18.
Changes
If this policy changes, the new version is published here with a new effective date. Material changes are emailed to account holders before they take effect.
See also the terms of service.