Privacy Policy

How Bolsix handles your data

Bolsix sells market data, not data about people. We keep the minimum needed for you to have an account, use API keys and stay within usage limits. This policy follows Brazil's General Data Protection Law (Law 13,709/2018, LGPD).

This is a translation. The Portuguese version prevails if the two differ.

Effective 2026-09-24.

1. Who the controller is

The data controller is Bolsix. For any privacy matter, including exercising your rights, write to support@bolsix.io.

2. What data we handle

DataWhenWhy
Email and Google account identifierWhen you sign in with GoogleCreate and identify your account
API keys, the name you give each key, and planWhen you create a keyAuthenticate requests
Daily request counts per key and endpoint, and time of the last requestOn every API or MCP requestEnforce limits and show your usage in the console
Tickers on your watchlistIf you use the watchlistBuild your portfolio briefing
Email and sign-up sourceIf you join the Pro waitlistTell you when Pro opens
Request counter for the keyless demo, kept under a hash of the IP addressOn every request without a keyCap the demo at 100 requests a day; deleted when the UTC day ends
Technical logs: IP address, date and time, endpoint and URL parameters, response codeOn every requestSecurity, abuse prevention and fault diagnosis

We do not ask for your name, tax ID, phone number or payment details. The MCP server does not store your conversations with the assistant: it receives only the parameters of each tool call (for example, a ticker) and passes them to the API as an ordinary request.

Send your key in the Authorization header. If it is sent in the URL, it can end up in the technical logs.

3. Legal bases

  • Performance of a contract (art. 7, V): account, keys, usage counting and limits, watchlist.
  • Legitimate interest (art. 7, IX): technical logs for security and abuse prevention, and aggregate usage statistics to improve the service.
  • Consent (art. 7, I): the waitlist. You can withdraw it at any time.

4. Cookies

The site uses only two cookies, both needed for sign-in:

CookieDurationPurpose
bolsix_session30 daysKeep you signed in to the console
bolsix_oauth_state10 minutesProtect sign-in against request forgery

We use no advertising or traffic-analytics cookies.

5. Who we share it with

We do not sell personal data or use it for advertising. It is handled by the providers that run the service, only for that purpose:

  • Railway: hosting for the API, the MCP server and the database.
  • Cloudflare: website hosting, network and attack protection.
  • Scalekit: authentication (sign-in to the console and the MCP server).
  • Google: sign-in with your Google account.

These providers may process data outside Brazil, mainly in the United States. We may also share data when the law or a competent authority requires it.

6. How long we keep it

  • Account, keys, usage counts and watchlist: while the account exists. A key deleted in the console stops working immediately but stays on record, with its usage history, until the account is deleted.
  • Waitlist: until you ask to leave it.
  • Technical logs: for our hosting providers' retention period, generally a few weeks.
  • When you ask us to delete your account, we erase this data within 15 days. Backups are overwritten on their normal cycle.

7. Your rights

You may ask for confirmation of processing, access, correction, anonymisation, blocking or deletion of your data, portability, information about sharing, and withdrawal of consent (LGPD art. 18).

Write to support@bolsix.io from your account's email address. We answer within 15 days. You may also complain to Brazil's data protection authority (ANPD).

8. Security

All traffic is encrypted (TLS), database access is restricted, and the session cookie is signed and unreadable by page scripts. No system is fully secure: if an incident could put you at risk, we will notify you and the ANPD as the law requires.

9. Minors

Bolsix is not intended for anyone under 18.

10. Changes to this policy

We may update this policy. Material changes will be announced by email or on the site before they take effect, and the date at the top of the page will change.