Collect less. Say exactly what happens.
EquityLayer does not require an account to run a diagnostic, use the public research tools, or export a Portable Research Profile. Google sign-in is optional and appears only when you choose cloud sync, cloud restore, or cloud deletion after a session expires.
Anonymous product events
The site can record a small event name and timestamp, such as a diagnostic-prompt copy or the completion of a consented report. EquityLayer does not intentionally attach an email address, holdings, portfolio, IP address, user agent, or advertising identifier to these events.
These counts are read as totals per stage. Because no session, visitor, or device identifier is stored, EquityLayer cannot link one event to another or follow a person between them.
The paste page at /diagnostic runs entirely in your browser until you take an explicit network action. A diagnostic result you paste there is validated and rendered locally. It is not sent to EquityLayer unless you explicitly choose cloud sync or separately tick the de-identified sharing box, which is unchecked by default. A profile you download is written to your own device. Choosing “Save on this device” writes the Portable Research Profile to that browser's local storage; it stays there until you delete it or clear browser data. The page can record the same kind of bare event name described above — that a gap map was rendered, or that a profile was downloaded — with no copy of what you pasted.
Shared only after explicit consent
If you approve report sharing, the diagnostic may send profile categories, a Ready/Partial/Missing gap map, and capability names matched by EquityLayer's deterministic rules. The server maps profile fields to fixed vocabularies and rejects free text. Do not send holdings, identity, private files, credentials, or conversation history.
This aggregate signal guides curator sweeps and future recommendation priorities. It is not used to personalize trades or create a public investor profile.
Identifiable, explicit, and separate
“Save & sync” first saves the profile on your device. If cloud sync is configured, it then checks for an authenticated profile. “Restore saved profile” can also open Google sign-in, then reads your existing cloud profile into the current browser. Only these actions — plus “Delete cloud copy” when an earlier session has expired — can open Google sign-in; the diagnostic, public MCP, and local export remain available without an account.
A cloud Portable Research Profile is identifiable because it is tied to your account. It contains only the closed-vocabulary profile categories, nine Ready/Partial/Missing states, deterministic capability matches, dates, and run/version metadata. It must not contain holdings, free text, credentials, files, or conversation history. Each cloud version has a 365-day access expiry: expired versions are excluded from profile reads and are physically purged the next time profile storage is accessed. You can export the current profile as JSON and delete the cloud copy from the diagnostic page; deletion removes all saved versions immediately.
Google may return an email during authentication, but EquityLayer does not copy that email, the raw Google account identifier, or Google access and refresh tokens into the profile store. A deployment-scoped one-way owner key links the saved versions. Signing in does not subscribe you to a newsletter, and cloud profiles are not joined to optional de-identified diagnostic reports or basic product events.
Optional research backups
Workspace settings provide a separate, manual research backup. It contains the theme question, review trigger, selected companies, evidence version, and decision journal that you choose to upload. These fields can contain private text. Reading the cloud copy does not upload local research. The backup belongs to your signed-in account and is not available through the public MCP tools.
The service keeps one current research backup until you replace or delete it. Deletion removes the research content from the active application database. A revision number and account key remain to reject stale writes. Provider backups can retain older database copies under the hosting provider’s retention policy. No research text is used as a log fallback. Export a local JSON copy from Tracking & updates. Delete the cloud copy from Workspace settings.
工作區設定提供手動研究備份,包含你選擇上傳的問題、重查條件、公司、證據版本與判斷紀錄。 查看雲端副本不會上傳本機資料,公開 MCP 也無法讀取。備份保留到你取代或刪除為止。 刪除會移除應用資料庫中的研究內容;帳戶識別與版本號保留,用來阻擋舊版本寫入。 主機供應商的資料庫備份可能依其保存政策保留舊副本。
No silent email capture
Public newsletter signup is disabled until durable subscriber storage, delivery, unsubscribe handling, deletion handling, and a retention policy are configured. Valid email addresses are not written to deployment logs as a fallback.
During beta, de-identified diagnostic reports and basic events may be written to restricted deployment logs when a database is not attached. This page will be updated before any broader data collection begins.
Research infrastructure, not a brokerage
EquityLayer does not connect a wallet, place trades, custody assets, or provide personalized investment advice. The product is independent and is not affiliated with Robinhood, Solana, Circle, or listed capability providers unless explicitly stated otherwise.