Privacy notice
This notice explains what Bilenabi stores about you, why, for how long, and what you can do about it. It is written to match what the software actually does.
Who is responsible
The operator of this Bilenabi instance is the data controller. Contact details are published on the site's footer or the account page of the deployment you are using.
What we store
Account: email address, display name, a scrypt hash of your password (never the password), the language you chose, when the account was created and verified.
Security: session records (a hash of the session token, creation and expiry time, IP address and browser description), a security log of sign-ins, failed attempts, lockouts, password and two-factor changes, and passkey public keys if you add any. Authenticator secrets are stored encrypted when the operator has configured a key.
Your book: the holdings, cash, watchlist, alerts and risk mandate you enter or import, the advice log the advisor writes for you, daily valuations of your book, and the morning briefs written for you.
Usage: the number of model tokens each feature consumed, so plan allowances can be enforced. Prompts and answers are not stored beyond the request.
Billing: if the operator has enabled Stripe, your Stripe customer and subscription identifiers. Card details never touch this service.
Push: if you enable notifications, the browser's push endpoint and keys.
Why
To run the service you asked for (contract); to keep accounts secure and to detect abuse (legitimate interest); to meet legal obligations; and, for optional features such as mail briefs and push notifications, because you turned them on (consent, revocable at any time).
Where your data goes
Google (Gemini API) receives the text of your questions together with the data the advisor needs to answer them — your holdings, alerts and the market data it reads — to generate a reply. Headlines are also scored by Gemini. Google's API terms govern that processing.
Market data providers (Bitstamp, Yahoo Finance, the European Central Bank via Frankfurter, Google News, and any contracted feed the operator configures) receive only the instrument symbols being requested, never your identity.
Stripe, if billing is enabled, receives your email and the plan you chose; it processes payment data under its own privacy policy.
Your mail provider receives the messages the service sends you.
No data is sold, and no advertising or analytics trackers are used.
Cookies
Two first-party cookies only: the session cookie (HttpOnly, needed to keep you signed in) and the language cookie. Both are strictly necessary for the features you use; no consent banner is shown because no tracking cookies exist.
How long
Account and book data: until you delete the account. Sessions: until they expire or you end them. The security log and usage ledger: kept while the account exists, for security and billing reconciliation. Backups are rotated on the operator's schedule (by default fourteen daily snapshots). Market data is not personal data and is kept indefinitely.
Your rights
Access and portability: the account page exports everything the service holds about you as one JSON file. Rectification: change your name, language, book and settings at any time. Erasure: delete the account from the account page; every record listed above is removed immediately and disappears from backups as they rotate. Objection and restriction: turn off mail and push, or contact the operator. You may also complain to your supervisory authority (in Türkiye, the KVKK; in the EU, your national authority).
Not investment advice
Bilenabi produces information generated by software and a language model. It is not personal investment advice, the operator is not your broker or adviser, and no order is ever placed on your behalf. See the terms of use.