Privacy policy
This policy describes what personal data OpenInsider collects, why, and how you can contact us about it.
Last updated October 7, 2026
What we collect
If you create an account, we collect your email address and an optional name. Email and password authentication is handled by Better Auth. We set a session cookie marked HttpOnly, and we verify your email address before your account is fully usable.
What we do not do
We do not sell personal data, and we never collect card details. Payments are handled by a third party, Lemon Squeezy.
Payments
Checkout and payment are handled by Lemon Squeezy. We store provider customer, subscription, variant, and order identifiers — never card details.
Analytics
We use GA4 and Umami for analytics, only after you grant consent. Analytics never receive query strings, fragments, or referrers. See the cookie policy for details.
Your data rights
You may request access, rectification, erasure, objection or restriction of processing and, where applicable, portability at info@pabloreyes.es. Identify the record or data concerned and your request. The general response period is one month; if complexity requires a permitted extension, you will be informed. A public record does not automatically mean your request will be refused.
People mentioned in regulatory filings
We also process data about people without accounts: names, disclosed roles or relationships with issuers, and transactions publicly reported to CNMV or AMF. These come from official filings and documents. The purpose is to enable searching, normalization, verification and context for those filings; the website links to sources and preserves known amendments.
Profiles and derived analyses
Filings may be organized into profiles, relationships and activity patterns. A matching name does not prove identity; a relationship or signal does not establish intent or unlawful insider dealing. This research is not intended for contact prospecting, personalized advertising or sensitive-trait inference. Published fields and historical access are bounded by the product contract.
Retention and corrections
Regulatory history is retained to reproduce and verify research while that purpose continues, subject to retention reviews. A correction creates a new version rather than silently changing earlier evidence. Internal retention does not require keeping all information publicly accessible: restriction and erasure requests are assessed according to the data, purpose and applicable obligations.
Technical logs and external services
Access and security logs support operation, abuse prevention and incident resolution. Our internal policy sets a baseline of 90 days for raw technical logs, except during an active incident or required retention. Hosting, email, consented analytics, payments and external resources have different roles; loading resources such as logos may send connection metadata to their provider. An authentication library is not itself an external recipient of data.
Requests and identity verification
Privacy inquiries and supporting evidence are handled privately, not through public comments or issues. Only information needed to verify a request will be sought. Do not send identity documents unless necessary and requested. Errors in an official source may require correction by the authority; we separately review OpenInsider extraction, classification or identity errors.
Complaints
If you believe processing infringes your rights, you may complain to the competent data protection authority, including the Agencia Española de Protección de Datos (AEPD).