Privacy Policy
Effective October 4, 2026
This Privacy Policy explains how Cold Start Ventures Limited (“Cold Start”, “we”, “us” or “our”) collects, uses, shares and protects personal data when you use Gloom and Gloomberb, including our websites, apps, Gloom Cloud, the News API, our MCP server and related services (the “Services”). Capitalized terms not defined here have the meaning given in our Terms of Service.
1. Who we are
Cold Start Ventures Limited, a company incorporated in Hong Kong, is responsible for your personal data as the data controller (or “data user” under the Hong Kong Personal Data (Privacy) Ordinance). You can reach us about privacy at hello@gloom.sh.
2. Using the app without an account
The Gloomberb app runs on your device. If you use it without signing in, your portfolios, watchlists, settings and any broker credentials you configure stay on your device and are not sent to us.
The app still connects to outside services to work: it checks GitHub for updates, loads the plugin registry from plugins.gloom.sh, and requests market data directly from public data sources. These services receive your IP address and the requests your app makes. Unless you turn them off, the app also sends us crash reports and anonymous counts of the functions you open, signed in or not, as described under “Usage and marketing data” below. The desktop app sends basic onboarding events only if you opened it from our website with an anonymous identifier attached to the link.
3. Personal data we collect
Account data. When you create an account: your email address, username, name and password (stored only as a hash), and whether your email is verified. If you sign in with GitHub or Google, we keep only your name, email address, profile picture and account ID from that service. If you fill in your profile, we also store your company, title, bio, public email, X handle and any portfolio you choose to share.
Workspace content. When you use Gloom Cloud, sync is on by default and stores your workspace on our servers, including portfolios, positions, watchlists, layouts, theme, recent tickers, plugin settings and the names of your broker connections (not their credentials). We also store notes, collections, views, theses, alerts, shared layouts, share links and team membership you create.
AI conversations. When you use Ask Gloom and other AI features: your questions, the answers, the tools the assistant used, the workspace data it read to answer (which may include your portfolios and watchlists), and usage counts used to enforce limits.
Chat. Messages you post in public channels, direct messages, and the blocks and reports you make.
Broker data. If you connect Interactive Brokers: the access tokens your broker issues to us, your account identifiers and granted permissions, account balances, positions, daily net asset value and returns, and the order instructions you prepare. We never receive your broker password.
Payment data. Through Stripe: your customer and subscription identifiers, plan, billing status, trial and renewal dates, and any cancellation reason you give. Stripe processes your card details; we do not receive or store full card numbers.
Feedback and support. When you send feedback or contact us: your message, email address, any screenshot you attach, app logs (with secrets removed), diagnostics such as platform and app version, and the emails you exchange with us. If you send feedback while signed out, we store a keyed hash of your IP address to limit abuse.
Device and security data. IP addresses and browser or device details of your sessions and device sign-ins, session identifiers, when you were last active and on which days, push notification tokens with the device name and app version, API and MCP keys (stored as hashes) and the MCP clients you authorize.
Command bar searches. When you are signed in: the text of searches you finish in the Gloomberb command bar (once you pause typing or run them, never each keystroke), the AI suggestions we showed for them and which result you picked. We use them to improve search. In current versions of the app, you can turn this off with the Usage Counts setting or with “config set telemetry.usage false”. We keep them until you delete your account.
Optional research attention. Attention Counts is a separate setting, off unless you explicitly turn it on. If you opt in while signed in with a verified email, the app sends the ticker symbols you deliberately open in company descriptions, charts, quotes and option chains, or add to a watchlist. We use your signed-in account to prevent duplicate contributions and abuse. We do not collect your search text, holdings, position sizes, device identifier or session identifier in these reports, and do not send them to our analytics or advertising providers. Turning on Usage Counts does not turn on Attention Counts.
Usage and marketing data. Product milestones such as loading a research view, saving a ticker, opening a Pro feature or showing upgrade intent. These product events do not include ticker symbols, search text, holdings or transcript content. Unless you turn them off, the app also sends usage counts: how often you open each function and which functions are on screen when it starts, with the app version, operating system, whether you are signed out or on Free or Pro, and a random install identifier. Usage counts are not linked to your account, and a function from a plugin other than our own is recorded only as “plugin”. It also sends crash reports: the error, its stack trace with your home folder removed, the app version and operating system, linked to your account only when you are signed in. On our websites, we also collect pages visited, referrer, campaign parameters, advertising click identifiers and an anonymous identifier stored in your browser, and we receive your IP address and user agent when we forward these events.
4. How we use personal data and why
We use personal data for the following purposes. Where the EU or UK GDPR applies, the legal basis for each purpose is shown in brackets.
- To create and run your account, sync your workspace, provide market data, news, AI features, chat, alerts, broker connections and the other features you use (performance of our contract with you).
- To process payments, trials, renewals and cancellations, and to keep financial records (contract and legal obligation).
- To send service emails and notifications, such as verification, password resets, alerts, portfolio roundups and replies to your messages (contract). You can turn off non-essential emails with the unsubscribe link in each email.
- To secure the Services, prevent fraud, spam and abuse, enforce our Terms and debug problems (legitimate interests).
- To understand how the Services are used and improve them (legitimate interests).
- If you choose Attention Counts, to produce aggregated research-attention statistics visible in Gloom and through our APIs (consent). Each ticker contributes at most one count per account per hour; we publish an hourly ticker count only when at least 20 distinct verified accounts contributed, round counts down in groups of five, and wait at least one hour after the bucket closes. Published tables contain no account, device or session identifiers. These statistics describe participating Gloom users, not the whole market.
- To measure which of our advertising campaigns lead to visits, downloads, sign-ups, trials and purchases (legitimate interests, or consent where the law requires it).
- To comply with law and respond to lawful requests from authorities (legal obligation).
We do not sell your personal data for money, and we do not use your workspace, conversations or other content to train AI models.
5. AI processing
When you use an AI feature, the text of your request, the relevant conversation history and any workspace data the assistant reads to answer are sent to one of our AI model providers to generate the response. Depending on the feature and availability, these are OpenAI, Google (Gemini), OpenRouter (which passes requests to the underlying model provider) and xAI. Gloombot, the AI participant in Gloom chat, runs on xAI models and reads the messages in public channels and the direct messages you send to it.
These providers process the data to return a response under their own terms. Do not include information in prompts or chat messages that you do not want processed this way.
6. How we share personal data
We share personal data with service providers that help us operate the Services, only as needed for the purposes above:
- Hetzner Online (Finland): hosting for our servers and databases.
- Cloudflare: website and web app hosting, network security, and delivery of our emails, including the content of alerts, roundups and notifications.
- Stripe: payment processing and subscription management.
- PostHog (United States): product analytics, error tracking and our support inbox. PostHog receives your account identifiers, email, name, plan, Stripe customer ID, product events, usage counts, crash reports and campaign attribution, and the text of feedback you send, but not your screenshots or app logs.
- OpenAI, Google, OpenRouter and xAI: AI features, as described in Section 5.
- Expo, Apple and Google: delivery of push notifications to your phone, including the notification text, such as alerts and chat messages.
- Telegram: internal notifications to our team about new subscriptions, cancellations and feedback, containing the email address involved and the feedback title.
- X (Twitter): advertising measurement. X may receive an ad click identifier, a cryptographic hash of your email, or your IP address and user agent. We do not send X your raw email address or phone number.
- GitHub: hosting of app updates and downloads, and our public source code.
We also share personal data in these cases:
- With services you choose to connect. If you connect Interactive Brokers, we exchange tokens and request your account data from them. If you subscribe to a third-party add-on such as TheBuildout, we give that provider your email, name and username so it can recognize you.
- With other users, for content you make visible to them, such as your public profile, public chat messages, content you share with your team and share links.
- When required by law, or when we believe in good faith that disclosure is necessary to protect the rights, property or safety of our users, the public or us.
- With a buyer or successor as part of a merger, acquisition, financing or sale of assets, subject to this Privacy Policy.
- With your consent or at your direction.
Under some US state privacy laws, using X’s advertising tools to measure campaigns may count as “sharing” personal data for targeted advertising. You can opt out as described in Section 11.
7. Cookies and similar technologies
We use a secure session cookie to keep you signed in. It is necessary for the Services to work.
Our websites store an anonymous identifier and the campaign that first and last brought you to us in your browser’s local storage, so we can measure our marketing. gloom.sh also sets one first-party cookie with a random identifier, kept for up to 400 days, so that when we test two versions of a page you keep seeing the same one and we can compare them. The web terminal uses its anonymous identifier the same way when we test two versions of something in the terminal. Neither the web terminal’s analytics identifier nor that cookie is created if your browser sends a Do Not Track or Global Privacy Control signal.
Our websites load X’s advertising pixel, which may set cookies controlled by X to measure ad performance. You can block it with browser privacy settings or content blockers, and manage interest-based advertising in your X settings.
8. International transfers
We are based in Hong Kong. Our servers are located in Finland, and our service providers process data in the United States and other countries. These countries may have data protection laws different from those where you live. When we transfer personal data from the European Economic Area, the United Kingdom or Switzerland, we rely on adequacy decisions or on safeguards such as the Standard Contractual Clauses.
9. How long we keep personal data
We keep personal data for as long as your account is active and as needed to provide the Services. When you delete your account, we delete your account data and your stored workspace, conversations, command bar searches, chat messages, feedback and broker connections from our production systems, with these exceptions:
- Content you shared with a team stays available to that team, with your name removed as the author.
- We keep records we must retain for tax, accounting or legal reasons, and Stripe keeps its own payment records.
- Copies held by our service providers, such as analytics and support records, are deleted under their retention schedules, or sooner if you ask us.
Before research-attention counts are aggregated, a restricted temporary table holds ticker counts and a keyed account hash that changes every hour. This is pseudonymous data, not anonymous data. We delete it when the hour is finalized or when its configured lifetime expires, normally six hours and never more than 24 hours while the retention worker is operating. The published aggregates contain no contributor identifiers. Published hourly counts are retained for 35 days while the cleanup worker is operating; the small record that an hour was finalized is retained to prevent republication. Published counts cannot be traced back to remove one person's contribution. You can withdraw consent at any time by turning off Attention Counts; the app clears unsent counts and stops new submissions. Counts already transmitted may remain until aggregation or expiry.
While your account is active, we keep only your latest synced workspace and a limited recent history. Device sign-in requests are deleted a day after they expire, and share links expire automatically. When you delete an Ask Gloom conversation, we permanently delete it and its messages from our production systems right away.
10. Security
We protect personal data with measures including encryption in transit, hashed passwords and API keys, broker tokens encrypted at rest with AES-256-GCM, and access to production systems limited to the people who need it. No system is perfectly secure, and we cannot guarantee the security of data sent over the internet. If you believe your account has been compromised, contact us right away.
11. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal data, to object to or restrict certain processing, to withdraw consent, and to opt out of the sale or sharing of personal data for targeted advertising. We will not discriminate against you for exercising these rights.
You can delete your account at any time from the account settings in the Gloom apps. You can make your profile private, disconnect a broker, delete conversations, and unsubscribe from non-essential emails at any time. To exercise any other right, email hello@gloom.sh. We may need to verify your identity, and we will respond within the time required by applicable law.
If you are in the EU, UK or Switzerland, you may also complain to your local data protection authority. In Hong Kong, you may contact the Office of the Privacy Commissioner for Personal Data.
12. Children
The Services are not directed to children, and you must be 18 or older to create an account. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and change the effective date above. If a change is material, we will notify you by email or in the Services before it takes effect.
14. Contact
Cold Start Ventures Limited, Hong Kong. Email: hello@gloom.sh.