← All policies
Legal

Privacy Policy

Effective: September 2026

The Operator doing business as 141 software ("141," "we," "us") values being clear about personal information. This Privacy Policy describes how we collect, use, and disclose personal information when you use our websites, applications, waitlist, accounts, paid plans, and other Services. It also describes rights you may have. Questions: privacy@141.software.

If you are in the EEA, the United Kingdom, or Switzerland, also read the Europe Privacy Addendum.

This policy covers personal information we process as a controller for the Services. Warehouse market data, filings, and similar research content are generally not your personal information, except insofar as logs record that your account requested or viewed them. For certain organization accounts, 141 may process Customer Data as a processor or service provider on behalf of the organization, in which case the applicable data-processing agreement or enterprise agreement governs that processing. Employment recruiting, if we later run a careers process, would be described separately. If you access 141 only through a third party's product, that party's policy may also apply.

1. Personal information we collect

We may collect personal information from you and about you. Examples of what we may collect, how we may collect it, how we may use it, and how we may disclose it are below. We do not need every category for every person. What we actually hold depends on whether you join a waitlist, create an account, pay us, contact us, or simply browse.

Account and waitlist data

Email address, display name, hashed credentials handled by our authentication provider, invitation or waitlist status, user id, organization or seat association if any, and similar account records. If you sign in through a third-party identity provider, that provider may send us identifiers and profile fields you authorize.

How we may collect it. Directly from you, from an administrator who invites you, or from an identity or authentication provider you choose.

How we may use it. To provide, operate, analyze, and maintain the Services; to create and administer accounts, waitlists, seats, and paid plans; to provide support; to communicate with you; to secure the Services and prevent abuse; to develop and improve the Services using aggregated or de-identified information; and for legal, accounting, and compliance purposes.

How we may disclose it. To processors who host, authenticate, email, bill, monitor, or otherwise support the Services under contract; if required by law or to protect 141, users, or the public; in connection with a merger, financing, acquisition, or other business transfer; and with your direction.

Payment and billing data

If you purchase a plan, subscription, seat, or other paid feature, we and our payment processor may process payment-method type, last four digits or similar tokenized identifiers, billing name and address, email, transaction amounts, tax, invoices, and subscription status. Full card numbers are collected by the processor, not stored in full on our servers. Until checkout is enabled we typically hold no payment card data.

How we may collect it. From you and from the payment processor or invoicing provider.

How we may use it. To take payment, renew subscriptions, issue invoices and tax records, prevent fraud, provide paid features, and handle cancellations, failed charges, and support.

How we may disclose it. To the payment processor, tax or accounting providers, and otherwise as in the standard disclosure list.

Customer Data and other user content

Notes, highlights, uploaded files, saved views, watchlists, and other material you store or submit in the Services. If a feature lets you send a query to a model or similar tool to generate a response for you, the input and output of that feature are processed to provide it.

How we may collect it. Directly from you (and, for organization accounts, from users on that account).

How we may use it. To provide the feature you asked for, to host and back up your workspace, to secure the Services, and to support you. We do not use Customer Data to train foundation models.

How we may disclose it. To processors who host, authenticate, email, bill, monitor, or otherwise support the Services under contract; if required by law or to protect 141, users, or the public; in connection with a merger, financing, acquisition, or other business transfer; and with your direction.

Communications

Messages you send us (access requests, support, legal, billing), and our replies, including names and contact details you include.

How we may collect it. Directly from you, including email, forms, and in-product contact.

How we may use it. To provide, operate, analyze, and maintain the Services; to create and administer accounts, waitlists, seats, and paid plans; to provide support; to communicate with you; to secure the Services and prevent abuse; to develop and improve the Services using aggregated or de-identified information; and for legal, accounting, and compliance purposes.

How we may disclose it. To processors who host, authenticate, email, bill, monitor, or otherwise support the Services under contract; if required by law or to protect 141, users, or the public; in connection with a merger, financing, acquisition, or other business transfer; and with your direction.

Preferences and product settings

Theme, notification and sound settings, default landing page, alert preferences, and similar workbench settings.

How we may collect it. Directly from you as you use Settings and related controls.

How we may use it. To remember your configuration and provide the Services.

How we may disclose it. To processors who host, authenticate, email, bill, monitor, or otherwise support the Services under contract; if required by law or to protect 141, users, or the public; in connection with a merger, financing, acquisition, or other business transfer; and with your direction.

Technical, device, and usage data

IP address, user agent, browser and OS, device type, approximate location derived from IP, pages and features used, timestamps, referrer, diagnostic and crash logs, performance metrics, and security events (sign-in, session, password, account deletion).

How we may collect it. Automatically when you use the Services, including through logs and infrastructure tools.

How we may use it. To provide, operate, analyze, and maintain the Services; to create and administer accounts, waitlists, seats, and paid plans; to provide support; to communicate with you; to secure the Services and prevent abuse; to develop and improve the Services using aggregated or de-identified information; and for legal, accounting, and compliance purposes.

How we may disclose it. To processors who host, authenticate, email, bill, monitor, or otherwise support the Services under contract; if required by law or to protect 141, users, or the public; in connection with a merger, financing, acquisition, or other business transfer; and with your direction.

Research activity logs

Pages, tickers, issuers, documents, and features your account views or queries. That history can be commercially sensitive. Warehouse content you view is licensed or public research material; the fact that your account viewed it is usage data about you.

How we may collect it. Automatically from use of the workbench.

How we may use it. We may log which pages, features, tickers, issuers, documents, or datasets your account accesses for security, diagnostics, capacity planning, and product operation. We do not sell that information or use it for targeted advertising, and we do not use it to train foundation models.

How we may disclose it. Access to research activity logs is limited to personnel and service providers with a legitimate operational, security, support, or legal need, and as otherwise required by law.

Feedback

Bug reports, ratings, and feature ideas you choose to send.

How we may collect it. Directly from you.

How we may use it. To operate, maintain, analyze, and improve 141, as described in the Terms of Service.

How we may disclose it. To processors who host, authenticate, email, bill, monitor, or otherwise support the Services under contract; if required by law or to protect 141, users, or the public; in connection with a merger, financing, acquisition, or other business transfer; and with your direction.

Cookies and similar technologies

Essential session cookies on the workbench; essential cookies on the public marketing site; and optional measurement cookies on the public site only if you allow them, as described in the Cookie Policy.

How we may collect it. Through your browser or device when you visit.

How we may use it. To keep you signed in, remember settings, measure site performance, and secure the Services.

How we may disclose it. To infrastructure and measurement providers as described in the Cookie Policy and Processors page.

Approximate location

A general area derived from IP address (for example country or region). We do not currently collect precise GPS location. If we later offer a feature that needs precise location, we will ask where required.

How we may collect it. Automatically from your connection.

How we may use it. To operate, secure, and localize the Services, and to comply with law (including sanctions and geo-restrictions).

How we may disclose it. To processors who host, authenticate, email, bill, monitor, or otherwise support the Services under contract; if required by law or to protect 141, users, or the public; in connection with a merger, financing, acquisition, or other business transfer; and with your direction.

We do not intentionally collect special-category or sensitive demographic data (race, health, religion, precise geolocation, biometrics). Account login credentials are treated as sensitive personal information under some U.S. state laws and are used only to provide and secure the account. Do not upload information that would impose HIPAA or similar regimes unless we have agreed in writing.

2. How we may use personal information

  • To provide, analyze, and maintain the Services — including waitlist, accounts, seats, the workbench, alerts, and paid plans.
  • To provide support and assistance.
  • To develop and improve the Services using aggregated or de-identified usage, not by training models on Customer Data or ticker-level research history.
  • To communicate with you about access, security, billing, product changes, and (where permitted) updates you have not opted out of.
  • To ensure security and integrity — fraud, abuse, unauthorized use, and debugging.
  • For legal purposes — including tax, accounting, enforcement of Terms, and requests we are required to meet.

AI and model training

We may use automated systems, including models, to summarize, classify, extract, or organize third-party and public materials for display in the Services, as described in the Legal Notice and Terms. That processing is not training on Customer Data or on your research-activity logs. We do not currently use Customer Data, user queries, uploaded files, generated work product, or research-activity logs to train foundation models or other machine-learning models, whether our own or a third party's. If we introduce a feature that sends your content to a model provider to generate a response for you, that processing is to provide the feature. We do not knowingly send Customer Data to a model provider whose applicable terms permit that provider to use the Customer Data for model training, unless you have separately consented to that use. We will identify the relevant processing in this policy before enabling the feature where required by applicable law.

3. How we may disclose personal information

We do not sell personal information. We share it only as described above and:

  • With processors in the categories described on the Processors page (hosting, waitlist storage, email, authentication, optional measurement, payments when you pay, and security logging).
  • If required by law, legal process, or to protect 141, users, or the public.
  • In connection with a merger, financing, acquisition, restructuring, or sale of assets, subject to appropriate safeguards.
  • With your direction (for example if you ask us to send something to a colleague, or an organization admin manages seats).

Categories of recipients: Processors.

If 141 or substantially all of its assets are acquired, transferred, or reorganized, personal information may be transferred as part of that transaction subject to applicable law and this Policy.

4. Legal bases (EEA, UK, Switzerland)

Where GDPR or UK GDPR applies, we process personal information because it is necessary to perform a contract with you (account, paid plans, and Services), because we have a legitimate interest in operating, securing, and improving a research platform that does not override your rights, because we have a legal obligation, or because you consented (for example non-essential cookies on the marketing site, or marketing mail). You may withdraw consent without affecting prior lawful processing. We do not treat merely continuing to browse as GDPR consent. Purpose-by-purpose detail is in the Europe Privacy Addendum.

5. Retention

We retain personal information for as long as reasonably necessary for the purposes described in this Policy, including providing the Services, security, fraud prevention, legal obligations, dispute resolution, tax and accounting, and other legitimate business needs. Customer Data is removed from active systems when you delete it or the account. Backups may persist until they expire on their normal rotation. De-identified analytics may be kept longer.

6. Security

We use commercially reasonable technical and organizational measures appropriate to the nature of the information we process, including encrypted transport (TLS), session controls, and restricting operator access. We do not currently claim SOC 2, ISO 27001, or similar certifications. Encryption at rest, key management, audit logging, incident response, and subprocessors will be described in more detail in a security exhibit if we enter an enterprise agreement. No method of transmission or storage is 100% secure. If we become aware of a breach affecting your personal information, we will notify you and regulators as applicable law requires.

7. Minors

The Services are not directed to children under 18, and we do not knowingly collect personal information from them. If we learn that we have, we will delete it and close the account. Contact privacy@141.software if you believe a minor has used 141.

8. Your rights

Depending on where you live you may have rights to access, correct, delete, restrict, or port personal information, to object to certain processing, and not to be subject to solely automated decisions with legal or similarly significant effects (we do not make such automated decisions about you). Settings lets you change display name and preferences and delete the account. Exercise other rights via privacy@141.software. EEA/UK users may complain to their supervisory authority; Swiss users to the FDPIC; Australian users to the OAIC; New Zealand users to the Privacy Commissioner. U.S. state rights are described in California & US State Privacy Rights.

9. International transfers

We are based in the United States. If you access the Services from the EEA, UK, Switzerland, or elsewhere, personal information is processed in the United States and other places our processors operate. Where a restricted transfer requires a safeguard, we rely on mechanisms such as Standard Contractual Clauses with processors, applicable adequacy decisions, or other lawful transfer mechanisms. Where processing is necessary to perform the contract for providing the Services, we may rely on that legal basis where applicable. We do not treat generic continued use of the Services as consent to an international transfer. If a transfer lawfully depends on consent, we will ask for that consent specifically.

10. Do Not Track

There is no uniform standard for browser Do Not Track signals. We do not respond to DNT at this time. California requires that we say so. Global Privacy Control (GPC) is treated as an opt-out of "sale" or "share" of personal information should we ever sell or share; we do not currently sell or share as those terms are defined under the CPRA.

11. Updates

We may update this Privacy Policy by posting a new version with a revised date. Material changes will be highlighted or emailed where required. Continued use after the effective date is acceptance except where the law requires consent.