LEGAL

Privacy Policy

Effective May 22, 2026

Introduction

This Privacy Policy describes our policies and procedures on the collection, use, and disclosure of your information when you use the Service. It also tells you about your privacy rights and how the law protects you.

We use your Personal Data to provide and improve the Service. By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.

Interpretation and Definitions

Interpretation

Words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.

Definitions

For the purposes of this Privacy Policy:

  • Account means a unique account created for you to access our Service or parts of our Service.
  • Affiliate means an entity that controls, is controlled by, or is under common control with a party, where "control" means ownership of 50% or more of the shares, equity interest, or other securities entitled to vote for election of directors or other managing authority.
  • Application refers to CentoFlow, the software service provided by the Company.
  • Company (referred to as either "the Company," "We," "Us," or "Our" in this Agreement) refers to CentoFlow Limited, RM 1205, 12/F Beverly House, 93-107 Lockhart Road, Wan Chai, Hong Kong.
  • Country refers to: Hong Kong SAR China.
  • Device means any device that can access the Service such as a computer, a cellphone, or a digital tablet.
  • Personal Data is any information that relates to an identified or identifiable individual.
  • Service refers to the website at centoflow.com and related applications operated by the Company.
  • Service Provider means any natural or legal person who processes the data on behalf of the Company.
  • Third-Party AI Service means any external artificial intelligence service provider that the Company uses to process, analyze, or generate responses based on data submitted through the Service.
  • Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself.
  • You means the individual accessing or using the Service, or the company or other legal entity on behalf of which such individual is accessing or using the Service.

Collecting and Using Your Personal Data

Types of Data Collected

Personal Data

While using our Service, we may ask you to provide us with certain personally identifiable information that can be used to contact or identify you. Personally identifiable information may include, but is not limited to:

  • Email address
  • Display name
  • Account credentials (passwords are stored hashed; we do not retain plaintext passwords)
  • Subscription tier and billing information (handled by Stripe, our payment processor — we do not store full credit card numbers)
  • Usage Data

Portfolio and Financial Research Data

When you use the Service, you may voluntarily provide:

  • Watchlists and tracked assets
  • Manual portfolio holdings entered into the Service
  • Queries to the AI Analyst and Devil's Advocate features
  • Subscription preferences and notification settings

CentoFlow does NOT connect to brokerage accounts and does NOT access your actual trading account, real holdings, real-time balances, or execute trades on your behalf. All portfolio data within CentoFlow is manually entered by you.

Usage Data

Usage Data is collected automatically when using the Service.

Usage Data may include information such as your device's Internet Protocol address (IP address), browser type, browser version, the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers, and other diagnostic data.

When you access the Service via a mobile device, we may collect certain information automatically, including the type of mobile device, mobile device unique ID, IP address, mobile operating system, type of mobile Internet browser, and other diagnostic data.

Third-Party AI Services and Data Sharing

Our Service uses third-party artificial intelligence (AI) services to provide core functionality, including AI-assisted financial markets research, conviction analysis, Devil's Advocate counter-arguments, and the AI Analyst feature. This section explains what data is shared, who it is shared with, and how your consent is obtained.

What Data Is Sent to Third-Party AI Services

When you use the AI-powered features of our Service, the following data may be sent to third-party AI service providers:

  • Text-based queries, prompts, and messages you submit to the AI Analyst, Devil's Advocate, and similar features
  • Financial research parameters you provide (such as stock tickers, watchlist names, manually-entered portfolio context)
  • Contextual information necessary to generate relevant AI responses (such as conversation history within a session)
  • Public market data and CentoFlow-generated signal context that grounds the AI response

We do NOT send your email address, account credentials, payment information, or device identifiers to third-party AI service providers.

Who the Data Is Sent To

We currently use the following third-party AI service provider to power the AI features of our Service:

  • Anthropic (Anthropic, PBC) — for natural language processing, AI-generated research analysis, conviction reasoning, and AI Analyst responses. Anthropic's privacy policy can be found at https://www.anthropic.com/privacy

We may update this list in the future as we evaluate other AI service providers. We will update this Privacy Policy to reflect any new third-party AI service providers and notify users of material changes before they take effect.

Your Consent and Control

By using the AI-powered features of the Service (including AI Analyst, Devil's Advocate, conviction reasoning, and similar features), you acknowledge and agree that your input data will be transmitted to the third-party AI providers identified above for processing.

You may choose not to use the AI-powered features of the Service. Non-AI features (such as raw signal data, watchlists, and static portfolio analytics) will continue to function without transmission to third-party AI providers.

Data Protection by Third-Party AI Providers

We require that all third-party AI service providers we work with provide an appropriate level of protection for your Personal Data:

  • Data sent to third-party AI providers is transmitted using industry-standard encryption (TLS/SSL)
  • We use API-based integrations under terms where user-submitted data is not used to train the AI provider's general models
  • Third-party AI providers are contractually obligated to handle your data in accordance with their published privacy policies and applicable data protection laws

Payment Processing

Our Service uses Stripe, Inc. as our payment processor. When you subscribe to a paid tier, your payment information (credit card details, billing address) is collected and processed directly by Stripe under their own privacy and security terms.

CentoFlow does NOT store full credit card numbers, CVV codes, or other sensitive payment credentials. We retain only the information necessary to manage your subscription (subscription tier, billing status, last 4 digits of card for reference, billing email).

Stripe's privacy policy can be found at https://stripe.com/privacy. Stripe is PCI-DSS Level 1 certified.

Hosting and Infrastructure Providers

The Service is hosted on the following infrastructure providers, located in the United States:

  • Vercel, Inc. — frontend application hosting and content delivery
  • Railway Corp. — backend application hosting, database, and background processing

Your data, including Personal Data and Usage Data, is processed and stored on servers operated by these providers within the United States. By using the Service, you consent to the transfer and processing of your data in the United States.

Vercel's privacy policy: https://vercel.com/legal/privacy-policy
Railway's privacy policy: https://railway.com/legal/privacy

Email Communications Provider

We use Resend, Inc. to deliver transactional emails (account verification, password reset, billing receipts, subscription notifications). Resend processes your email address and the content of transactional emails on our behalf.

Resend's privacy policy: https://resend.com/legal/privacy-policy

Use of Your Personal Data

The Company may use Personal Data for the following purposes:

  • To provide and maintain our Service, including to monitor the usage of our Service
  • To manage your Account: to manage your registration as a user of the Service, giving you access to features available to registered users
  • For the performance of a contract: the development, compliance, and undertaking of the purchase contract for the subscription tier you have selected or any other contract with us through the Service
  • To contact you: by email or other equivalent forms of electronic communication regarding updates, security alerts, or informative communications related to the functionalities, products, or contracted services, including transactional emails sent via Resend
  • To provide you with news, special offers, and general information about other features, services, and events that we offer that are similar to those you have already purchased or enquired about, unless you have opted not to receive such information
  • To manage your requests: to attend and manage your requests to us
  • For business transfers: we may use your information to evaluate or conduct a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets
  • For other purposes: data analysis, identifying usage trends, determining the effectiveness of our promotional campaigns, and to evaluate and improve our Service, products, services, marketing, and your experience
  • To power AI features: we may send your queries, prompts, and related financial research data to third-party AI service providers as described in the "Third-Party AI Services and Data Sharing" section above, to generate AI-powered research analysis and responses

Sharing Your Personal Information

We may share your personal information in the following situations:

  • With Service Providers: We may share your personal information with Service Providers (Stripe for payments, Vercel and Railway for hosting, Resend for email, Anthropic for AI processing) as described above
  • With Third-Party AI Service Providers: We share your queries, prompts, and related data with Anthropic to power the AI features of our Service, as described in the "Third-Party AI Services and Data Sharing" section above
  • For business transfers: We may share or transfer your personal information in connection with, or during negotiations of, any merger, sale of Company assets, financing, or acquisition of all or a portion of our business to another company
  • With Affiliates: We may share your information with our affiliates, in which case we will require those affiliates to honor this Privacy Policy
  • With other users: when you share personal information or otherwise interact in any public areas of the Service, such information may be viewed by all users
  • With your consent: We may disclose your personal information for any other purpose with your consent
  • For legal reasons: We may disclose your information if required by law, valid government request, or to protect our rights, property, or safety

We do NOT sell your personal information to third parties.

Retention of Your Personal Data

The Company will retain your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use your Personal Data to the extent necessary to comply with our legal obligations, resolve disputes, and enforce our legal agreements and policies.

The Company will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period of time, except when this data is used to strengthen the security or to improve the functionality of our Service, or we are legally obligated to retain this data for longer time periods.

AI conversation history may be retained for the duration of your subscription plus a reasonable period thereafter to support feature improvements and to allow you to access historical conversations. You can request deletion of your conversation history at any time.

Transfer of Your Personal Data

Your information, including Personal Data, is processed at the Company's operating offices in Hong Kong and on servers located in the United States. This means that this information may be transferred to — and maintained on — computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction.

Your consent to this Privacy Policy, followed by your submission of such information, represents your agreement to that transfer.

The Company will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy. No transfer of your Personal Data will take place to an organization or a country unless there are adequate controls in place to protect the security of your data and other personal information.

Your Rights and Choices

Delete Your Personal Data

You have the right to delete or request that we assist in deleting the Personal Data that we have collected about you.

Our Service gives you the ability to delete or update certain information about you from within your account settings. You may also contact us at admin@centoflow.com to request access to, correct, or delete any personal information that you have provided to us.

Please note, however, that we may need to retain certain information when we have a legal obligation or lawful basis to do so (for example, payment records required for tax purposes).

Access and Portability

You have the right to request a copy of the Personal Data we hold about you. Contact admin@centoflow.com with such requests.

Opt Out of Marketing

You can opt out of marketing emails at any time by clicking the "unsubscribe" link in any marketing email, or by adjusting notification settings in your account. Transactional emails (such as billing receipts, security alerts, and account-related notifications) will continue regardless of marketing preferences.

Withdraw Consent

Where we rely on your consent to process Personal Data, you have the right to withdraw that consent at any time. Withdrawing consent will not affect the lawfulness of processing before withdrawal.

Disclosure of Your Personal Data

Business Transactions

If the Company is involved in a merger, acquisition, or asset sale, your Personal Data may be transferred. We will provide notice before your Personal Data is transferred and becomes subject to a different Privacy Policy.

Law Enforcement

Under certain circumstances, the Company may be required to disclose your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g., a court or a government agency).

Other Legal Requirements

The Company may disclose your Personal Data in the good-faith belief that such action is necessary to:

  • Comply with a legal obligation
  • Protect and defend the rights or property of the Company
  • Prevent or investigate possible wrongdoing in connection with the Service
  • Protect the personal safety of users of the Service or the public
  • Protect against legal liability

Security of Your Personal Data

The security of your Personal Data is important to us, but remember that no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.

Security measures we employ include:

  • TLS/SSL encryption for all data in transit
  • Encryption at rest for sensitive data in our databases
  • Hashed password storage (we never store plaintext passwords)
  • Access controls and audit logging on administrative actions
  • Regular security reviews of our infrastructure and code

In the event of a data breach that materially affects your Personal Data, we will notify you and applicable regulatory authorities as required by law.

Children's Privacy

Our Service is not directed to anyone under the age of 18. We do not knowingly collect personally identifiable information from anyone under the age of 18. If you are a parent or guardian and you are aware that your child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from anyone under the age of 18 without verification of parental consent, we take steps to remove that information from our servers.

Links to Other Websites

Our Service may contain links to other websites that are not operated by us. If you click on a third-party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit.

We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date at the top of this Privacy Policy.

We will let you know via email and/or a prominent notice on our Service prior to material changes becoming effective.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

Contact Us

If you have any questions about this Privacy Policy, you can contact us:

CentoFlow Limited
RM 1205, 12/F Beverly House
93-107 Lockhart Road
Wan Chai, Hong Kong

By email: admin@centoflow.com