Turnstone
Home Terms Launch App

Privacy Policy

Effective date: February 26, 2026

This Privacy Policy describes how Turnstone ("we," "us," or "our") collects, uses, and protects your information when you use the Turnstone Deal Screener platform ("Service"). By using the Service, you consent to the practices described in this policy.

1. Information We Collect

Account Information: When you create an account, we collect your name and email address through our authentication provider (Auth0). If you sign in with Google, we receive your Google profile name and email address. We do not collect or store your password — authentication is handled entirely by Auth0.

Uploaded Documents: You may upload PDF documents (such as CIMs, teasers, and financial summaries) or submit listing URLs for screening. These documents are processed to generate deal analysis and are stored in our database associated with your account.

Usage Data: We collect information about how you use the Service, including the number of deals screened, features accessed, and general usage patterns. This data helps us improve the Service and manage billing.

Billing Information: If you subscribe to the Pro tier, payment information (credit card details) is collected and processed directly by Stripe. We do not store your credit card number or full payment details on our servers. We store your Stripe customer ID and subscription status for account management.

2. How We Use Your Information

We use your information to:

  • Provide, maintain, and improve the Service
  • Process uploaded documents through our AI screening pipeline
  • Manage your account and subscription
  • Track usage for billing purposes (per-screen charges for Pro users)
  • Send transactional communications (account confirmations, billing receipts, screening completion notifications)
  • Respond to support requests
  • Monitor for abuse, fraud, and violations of our Terms of Service

3. Third-Party Services and Data Processing

We use the following third-party services to operate the platform. Your data may be transmitted to these providers as described below:

Provider Purpose Data Shared
Anthropic (Claude API) AI analysis of uploaded documents Document content (PDF text, listing page content)
Auth0 Authentication and identity management Email address, name, login events
Stripe Payment processing and subscription management Email, name, payment method details
Supabase Database hosting (PostgreSQL) All account and deal data (encrypted at rest)
Railway Backend application hosting Application data in transit
Vercel Frontend application hosting Static assets only (no user data)
Cloudflare DNS and CDN Network routing data

4. AI Processing and the Anthropic API

This section is particularly important if you upload confidential documents.

When you submit a document or URL for screening, the content is sent to Anthropic's Claude API for analysis. Regarding Anthropic's data handling:

  • No model training: Per Anthropic's API terms, content submitted through their commercial API is not used to train their AI models.
  • Processing only: Document content is sent to Anthropic solely for the purpose of generating your screening analysis. Anthropic processes the data to produce a response and does not retain it for other purposes beyond their standard API data handling practices.
  • No human review by default: Anthropic's API data is not reviewed by humans unless flagged for trust and safety concerns or required by law.

We encourage you to review Anthropic's Privacy Policy for full details on their data handling practices.

5. Data Storage and Security

Your data is stored in a PostgreSQL database hosted by Supabase in the US West (Oregon) region. We implement the following security measures:

  • Encryption in transit: All data transmitted between your browser, our servers, and third-party services uses TLS/SSL encryption (HTTPS).
  • Encryption at rest: Database storage is encrypted at rest by our hosting provider.
  • Row-level security: Database access controls ensure that each user can only access their own data. Queries are scoped to the authenticated user at the database level.
  • No plaintext credentials: Passwords for shared deal links are hashed using bcrypt before storage.
  • Minimal data collection: We only collect information necessary to provide the Service.

6. Data Retention

  • Account data: Retained for as long as your account is active. You may request deletion at any time.
  • Deal data: Deals you delete are soft-deleted (marked as deleted but retained in the database). You may request permanent deletion by contacting us.
  • Usage logs: Retained for billing reconciliation and service improvement purposes.
  • Uploaded documents: Document content processed during screening is stored as extracted structured data in your deal records. Original PDF files are not retained after processing.

7. Data Sharing

We do not sell, rent, or trade your personal information or uploaded documents to any third party. We only share data with the third-party service providers listed in Section 3, and only as necessary to operate the Service.

We may disclose your information if required by law, legal process, or government request, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

8. Shared Deal Links

If you create a shareable link to a deal screening result (Pro feature), the recipient of that link can view the deal analysis. Shared links may be optionally protected with a password. You control who receives shared links and are responsible for any resulting disclosure of deal information. Shared link access logs are maintained for your reference.

9. Cookies and Local Storage

The Service uses:

  • Authentication cookies/tokens: Managed by Auth0 to maintain your login session.
  • Local storage: Used for non-sensitive UI preferences only (such as sort order and filter settings). No deal data or authentication tokens are stored in local storage.

We do not use third-party tracking cookies or advertising cookies.

10. Your Rights

You have the right to:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate personal data.
  • Deletion: Request deletion of your account and associated data. Upon request, we will delete your account and all associated deal data. Some data may be retained as required by law or for legitimate business purposes (such as billing records).
  • Data portability: Export your deal data using the CSV export feature available in the application.
  • Withdraw consent: You may stop using the Service at any time. Pro subscribers can cancel their subscription through the billing portal.

11. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • The right to know what personal information we collect and how it is used.
  • The right to request deletion of your personal information.
  • The right to opt out of the sale of personal information. We do not sell your personal information.
  • The right to non-discrimination for exercising your privacy rights.

12. International Users

The Service is hosted in the United States. If you access the Service from outside the United States, your data will be transferred to and processed in the United States. By using the Service, you consent to this transfer. We process data in accordance with applicable data protection laws.

13. Children's Privacy

The Service is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a minor, please contact us and we will promptly delete it.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification at least 14 days before taking effect. The "Effective date" at the top of this page indicates when the policy was last revised. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.

15. Contact

For questions about this Privacy Policy or to exercise your data rights, contact us at support@turnstone.app.

Home Insights Public Markets Analyst Terms of Service Privacy Policy Contact

© 2026 Turnstone