1. About this policy

This policy covers ShortPut at shortput.app, including option-chain research, sign-in, saved watchlists and the access waitlist. ShortPut is an independently operated research tool. The contact at the end of this page reaches the site operator.

2. Information we process

  • Google sign-in: account identifiers, email address, email-verification status and basic profile information returned by Google, such as your name or avatar. Supabase handles authentication and may retain that profile. The ShortPut application stores your account ID, email, creation time, display preferences and access-related records.
  • Account features: saved ticker symbols, their order, and your language and theme choices. Signing in can create an account record even if you do not join the waitlist.
  • Waitlist: the email you submit, the submission time and, when available, an approximate country/region inferred from your IP address by Cloudflare. Our waitlist record stores the country code, not the full IP address. Location may be inaccurate or unavailable; we do not request precise device location.
  • Technical and support information: your requests, browser/device information, connection metadata and information you send when contacting us. Hosting and authentication providers may process IP addresses and operational or security logs separately from the waitlist database.

3. Google data and permissions

Google sign-in is used to verify your identity, maintain your session and apply account permissions. We request basic identity, email and profile access, not Gmail messages, Drive files, contacts or your Google password. Your Google password is entered with Google, not ShortPut.

We do not sell Google user data or use it for advertising profiles, credit decisions or training general-purpose AI models. Its use is limited to the account and security features described here. ShortPut’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including applicable Limited Use requirements.

Google API Services User Data Policy

4. Why we use information

We use information to provide sign-in and research features, restore your preferences and watchlist, protect the service against abuse, respond to support requests and manage requests for access. If you join the waitlist, we may contact you about access becoming available. Joining does not grant access or subscribe you to unrelated marketing.

Where applicable law requires a legal basis, providing requested account features supports performance of the service; security and administration serve legitimate interests; optional waitlist contact follows your request or consent; and legally required records are handled to meet those obligations. You may withdraw consent for optional contact without losing access to public pages.

5. Providers and sharing

Google provides identity verification. Supabase provides authentication and database storage. Cloudflare hosts and delivers the application and provides network security and approximate country information. These services process the information needed for their roles, including technical metadata. The authorized site operator can access account and waitlist records to administer the service; those records are not public.

Market-data requests contain ticker symbols, search terms or contract identifiers needed to retrieve quotes. We do not send your Google profile or waitlist email to market-data providers as part of those requests. We may disclose information when legally required or when necessary to investigate abuse and protect users, with disclosure limited to that purpose.

Providers may process information in countries other than your own. Applicable protections and provider retention practices can differ. Contact us if you need further information about the service’s data processing or international transfers.

6. Cookies and browser storage

Authentication uses cookies and session tokens. We also use browser storage and cookies to remember language and light/dark preferences; preference cookies can last up to one year. Temporary market-data caches keep the interface responsive. These mechanisms support the service, rather than cross-site advertising profiles.

You can sign out or clear cookies and site data in your browser. This can reset preferences or interrupt sign-in, but does not delete records already stored on the server. Google and our infrastructure providers may operate additional authentication or security mechanisms under their own policies.

7. Retention, deletion and your choices

Account and watchlist information is retained while needed to provide your account. Waitlist entries are retained to manage access requests until no longer needed or removal is requested. The application currently has no automatic fixed-age deletion schedule; account and waitlist deletion requests are handled manually.

Email the contact below to request a copy, correction or deletion of your data, or removal from the waitlist. We may ask you to verify control of the relevant email address. Requests are handled subject to applicable law; limited records may need to remain for legal or security reasons. Backup copies, where present, follow the applicable backup retention cycle rather than disappearing immediately.

You can revoke ShortPut’s Google access in your Google Account’s third-party connections settings. Revoking Google access or signing out is not the same as deleting your ShortPut account, Supabase authentication record or waitlist entry. Request deletion separately. Depending on your location, you may also have rights to restrict or object to processing, receive portable data or complain to a data-protection authority.

8. Security and intended audience

We use encrypted connections and access restrictions to protect information. No internet service can guarantee absolute security. Please do not send passwords, payment-card details, government identification or brokerage credentials in support messages.

ShortPut is intended for adults and is not directed at children. If you believe a child has provided personal information, contact us so we can investigate and arrange appropriate removal.

9. Updates and contact

We will update the date on this page when this policy changes. Material changes will be communicated through the service or available contact channels as appropriate. If a new use of Google data requires consent, we will request it before that use. For privacy questions or data requests, contact the ShortPut operator using the email below.