Privacy Notice
This notice explains what personal data FFP One collects — across the marketing site and the product — and why.
Controller
FFP One, Inhaber (sole proprietor): Randall Helms
Beckerstr. 6A, 12157 Berlin, Germany
Contact: randall.helms@ffp.one
What we collect and why
Account & identity
Email, organization membership, and session data via Supabase authentication. Purpose: authenticating you and keeping your account secure.
Product usage
Chat messages, research queries, and notes are stored to provide the service and let you return to your own history. Chat conversations are additionally logged in full to Google Cloud Storage for quality and debugging during the beta.
Portfolio uploads — not live in this cohort
If/when portfolio uploads become available, the holdings and values in a brokerage statement you upload would be processed to power your Portfolios view. This feature is not available today, so nothing is collected here yet.
Usage analytics
We use PostHog to record pageviews and product-usage events, tied to your account. This is different from the marketing site's cookieless, anonymous PostHog use.
Error diagnostics
We use Sentry to capture crash reports and request metadata when something breaks. Sensitive query parameters are stripped before a report is sent.
Who processes your data (sub-processors)
- Supabase — authentication and database hosting.
- Railway — hosts the backend API.
- Vercel — hosts the frontend.
- MotherDuck — hosts the analytics warehouse (company/fund financial data; your account isn't stored here).
- Research Mode lets you choose which AI provider processes your question — Anthropic (default), OpenAI, GLM (Zhipu), or DeepSeek. Whichever you select receives your typed question and research request for that run, to generate the response.
- OpenAI is also used server-side for a narrower purpose: generating embeddings over filing text (not your personal data).
- Tavily — web search, used by Research Mode when a query needs current information.
- PostHog — product analytics.
- Sentry — error monitoring.
- Buttondown — used for beta announcement and product emails.
International transfers
Most of the above — Supabase, Railway, Vercel, MotherDuck, Anthropic, OpenAI, Tavily, PostHog, Sentry, Buttondown — are US-based; standard contractual clauses and their own GDPR compliance posture apply.
Separately: GLM (Zhipu) and DeepSeek are China-based — China has no EU adequacy decision. If you select one of these two providers for a research request, your typed question is processed there. This applies only when you actively choose GLM or DeepSeek; Anthropic and OpenAI stay in the standard US-transfer bucket above.
Retention
We retain your account and product-usage data for as long as your account is active, plus a reasonable period afterward for security and legal purposes.
Your rights
Under GDPR you have the right to access, correct, delete, or port the personal data we hold about you, and to object to certain processing. You also have the right to lodge a complaint with a supervisory authority. To exercise any of these rights, contact us at randall.helms@ffp.one.
Cookies & tracking
Unlike the marketing site's cookieless, anonymous PostHog setup, the product's analytics are tied to your logged-in account so we can understand how the product is used and fix problems.
Last updated: July 2026