Privacy Policy
Last updated June 29, 2026
DogBone Capital is a university investment-club platform. All trading on the platform is simulated. This policy explains what personal data we collect, why, who processes it on our behalf, how long we keep it, and the choices you have.
Who this applies to
It covers visitors to our public Research Hub (research, team, fund, and subscribe pages) and members who sign in to the platform. “We” refers to the DogBone Capital investment club operating this platform.
What we collect and why
We only collect data needed to run the club platform:
- Account identity (via Google sign-in). When you sign in we receive and store your email address, name, and profile image from Google, and we store the OAuth tokens needed to maintain your session. This is how we authenticate you and control access.
- Member profile. Optional fields you choose to add — profile photo, bio, headline, skills, university, graduation year, and a LinkedIn URL — shown on your member page and the public team page.
- Trading activity (simulated).The orders, fills, positions, ledger entries, realized P&L, and any journal/thesis notes you record. These power your portfolio, performance, and the club leaderboards.
- Research contributions. Research you upload (files stored in object storage) and contributor attribution (display name, and an email if provided) shown on published research.
- Newsletter subscription. If you subscribe, your email, optional name, and your frequency/content preferences, plus when you subscribed and the source of that consent.
- Access requests. If you request access, the email, name, and message you submit, so an administrator can review it.
- Technical and product telemetry. Standard server logs and in-app event records (e.g. news-pipeline and engagement events) used to operate, secure, and debug the platform. If error tracking is enabled, diagnostic error reports are sent to our error-tracking processor with PII scrubbing at the boundary.
We do not sell personal data, run advertising, or use third-party analytics/marketing trackers.
Service providers (processors)
We share data only with providers that help us run the platform:
- Google — sign-in / OAuth identity.
- Neon — managed PostgreSQL database hosting our records.
- Cloudflare R2 — object storage for profile photos and research files.
- Fly.io — application hosting and server infrastructure.
- Resend — transactional and newsletter email delivery.
- Alpaca — market data only (quotes/bars). We send symbols, not your personal data; no real brokerage account or order is created.
- Finnhub and Tiingo — market news ingestion. We send symbols, not your personal data.
- The configured LLM provider (e.g. OpenAI, Anthropic, or Groq) — used to screen news articles and, if you use the order copilot, to review the order context you submit. We do not send your account identity for these calls.
- An error-tracking provider (e.g. Sentry) — only if enabled, for diagnostics.
Cookies and sessions
We use a single essential cookie: an authentication session cookie set when you sign in (our sessions are stored server-side in our database). We also store your light/dark theme preference in a cookie for convenience. We set no analytics, advertising, or cross-site tracking cookies, so no consent banner is required for non-essential tracking.
How long we keep data
Account, profile, trading, and research records are retained while you are a member and for the club’s historical and audit purposes. Operational data is pruned on a schedule — for example non-portfolio news after 30 days, portfolio-relevant news after 365 days, dismissed alerts after 90 days, and hourly snapshots after 30 days.
When a member departs, we anonymize their personal profile data while preserving the integrity of append-only financial records (which are anonymized rather than deleted). You can ask us to do this sooner (see your rights below).
Your rights and choices
- Access / export. Signed-in members can export their account data from Settings, or request a copy from us.
- Correction. Update your profile fields anytime under Settings.
- Deletion / anonymization.You can ask us to delete or anonymize your account. Financial ledger records are anonymized rather than hard-deleted to keep the club’s books consistent.
- Newsletter opt-out. Every email includes a one-click unsubscribe link; you can also manage preferences on the Subscribe page.
Contact
Questions or requests about your data? Contact a club administrator, or request access via our access request page. See also our Terms of Use.