Privacy

What we record, and what we do not.

Short version: you can read every filing on this site without an account, without cookies, and without us learning anything about you personally. Nothing about readers is sold or shared with anyone.

No cookies and no accounts

This site sets no cookies. There is no login, no signup, and no email box anywhere on the free tool. You do not have to identify yourself to read a 10-K here, and there is no way for you to do so even if you wanted to.

What the counters hold

We count page views so we know which parts of the site are worth the work, and so a sector sponsor can be quoted an honest number. A count is a number attached to a public thing: a ticker, a section id, a sector. For example, the counter records that item-1a was read a certain number of times today. It does not record who read it, in what order, or from where. There is no profile, no session, no identifier that follows you between pages.

The trending page is built from those totals, and any figure below 50 views is left out entirely, so a page nobody much visits cannot be traced back toward a single reader.

Analytics

We use Vercel Web Analytics, which is cookieless and does not fingerprint visitors or follow them across sites. That is why there is no consent banner to click away: there is nothing to consent to.

Assistant and IDE connector

An assistant sends the arguments for the tool it calls, such as a ticker or filing id. It does not send its conversation through this connector. We use those arguments to answer the request. Usage events contain only the tool name, result category, a broad response-time bucket, an allowlisted assistant label and whether traffic was marked as an internal test. Unmarked traffic stays unclassified. Events contain no arguments, filing text, IP addresses, cookies, credentials or raw user agents. These compact events go to Vercel Analytics and our existing host logs; they are not a per-person history. Their retention follows those services' configured retention, with no separate conversation or filing-query store. Removing the connector stops future calls.

Connector usage measurement is skipped for DNT: 1, Sec-GPC: 1, or a query string on the connector URL. We also pass that choice to the API's own measurement. The daily per-address allowance still applies. A failed analytics delivery never changes the filing answer.

Global Privacy Control

If your browser or extension sends a Sec-GPC header, or the older DNT header, we honour it. The analytics script is not loaded for you at all, and our own server side counters skip your visit. We do this everywhere, not only where the law requires it, and you do not have to ask.

Rate limiting

The free API allows a number of calls a day per address, so one caller cannot exhaust it for everyone. That needs a per address tally, which is kept for the current UTC day and then expires. It is a protection, not a measurement, and it is never used to build a picture of anyone.

Payments and API keys

Plans are paid on Stripe's hosted checkout page, so card details go to Stripe, not to us. We store an API key only as a hash, with its plan, its Stripe customer and subscription identifiers, its status and billing period, and when it was created.

Logs

Our host keeps short lived request logs, as every host does, which include IP addresses. We do not export them, build profiles from them, or join them to anything else.

The filings themselves

Source documents are public domain filings from SEC EDGAR. Reading one here does not tell the SEC anything about you, because we fetch and cache the document rather than sending you to them.

Changes and contact

If this page ever needs to say something less generous than it says today, the change will be obvious rather than quiet. Questions to hello@darkvectorcognition.ai.