Privacy Policy
Bolsix sells market data, not data about people. We keep the minimum needed for you to have an account, use API keys and stay within usage limits. This policy follows Brazil's General Data Protection Law (Law 13,709/2018, LGPD).
This is a translation. The Portuguese version prevails if the two differ.
Effective 2026-09-24.
The data controller is Bolsix. For any privacy matter, including exercising your rights, write to support@bolsix.io.
| Data | When | Why |
|---|---|---|
| Email and Google account identifier | When you sign in with Google | Create and identify your account |
| API keys, the name you give each key, and plan | When you create a key | Authenticate requests |
| Daily request counts per key and endpoint, and time of the last request | On every API or MCP request | Enforce limits and show your usage in the console |
| Tickers on your watchlist | If you use the watchlist | Build your portfolio briefing |
| Email and sign-up source | If you join the Pro waitlist | Tell you when Pro opens |
| Request counter for the keyless demo, kept under a hash of the IP address | On every request without a key | Cap the demo at 100 requests a day; deleted when the UTC day ends |
| Technical logs: IP address, date and time, endpoint and URL parameters, response code | On every request | Security, abuse prevention and fault diagnosis |
We do not ask for your name, tax ID, phone number or payment details. The MCP server does not store your conversations with the assistant: it receives only the parameters of each tool call (for example, a ticker) and passes them to the API as an ordinary request.
Send your key in the Authorization header. If it is sent in the URL, it can end up in the technical logs.
The site uses only two cookies, both needed for sign-in:
| Cookie | Duration | Purpose |
|---|---|---|
| bolsix_session | 30 days | Keep you signed in to the console |
| bolsix_oauth_state | 10 minutes | Protect sign-in against request forgery |
We use no advertising or traffic-analytics cookies.
We do not sell personal data or use it for advertising. It is handled by the providers that run the service, only for that purpose:
These providers may process data outside Brazil, mainly in the United States. We may also share data when the law or a competent authority requires it.
You may ask for confirmation of processing, access, correction, anonymisation, blocking or deletion of your data, portability, information about sharing, and withdrawal of consent (LGPD art. 18).
Write to support@bolsix.io from your account's email address. We answer within 15 days. You may also complain to Brazil's data protection authority (ANPD).
All traffic is encrypted (TLS), database access is restricted, and the session cookie is signed and unreadable by page scripts. No system is fully secure: if an incident could put you at risk, we will notify you and the ANPD as the law requires.
Bolsix is not intended for anyone under 18.
We may update this policy. Material changes will be announced by email or on the site before they take effect, and the date at the top of the page will change.