Legal

Privacy Policy

Effective September 27, 2026

This policy explains what Annula ("we") collects when you use useannula.com, the Annula web app, the Mac app and the iPhone app (together, the "Service"), why we collect it, and the choices you have. The short version: we collect what we need to run the Service, we don't sell your data, and your research belongs to you.

What we collect

When you join the waitlist: your email address, your optional answer to "where do you keep research today?", the page you signed up from and the site that referred you. We also store a one-way hash of your IP address for a limited time to stop spam; we can't turn it back into your address.

When you use the website: privacy-friendly product analytics through PostHog, configured to run without cookies. It records pages viewed, clicks on key buttons, your browser and device type, and an approximate country. We don't use advertising trackers.

When you have an account (from the private beta onward): your email, your plan and billing status, and the content you create, such as theses, notes, assumptions, watchlists, portfolio holdings, models, boards and journal entries. We also keep an activity log of what the delegate did on your behalf, so you can review and undo it.

Payments: handled by our payment processor. We receive your billing status and the last four digits of your card, never your full card number.

How we use it

We don't sell your personal information, and we don't use your research content to train AI models.

AI engines

You choose the engine the delegate uses. If you bring your own (an API key, Codex, Claude Code or a local model), the relevant parts of your research are sent to that provider under your agreement with them, or nowhere at all with a local model. If you use Annula's hosted delegate, we send only the parts of your research needed for each task to our AI providers, under terms that prohibit them from training on it.

Who we share it with

Service providers that process data for us, only as needed to run the Service:

We may also disclose information if the law requires it, or to protect the rights and safety of our users or the public. If Annula is acquired or merged, your information would transfer under this policy, and we would tell you first.

How long we keep it

Waitlist entries are kept until you get access or ask us to remove you. Account data is kept while your account is open and deleted within 30 days of closing it, except where the law requires us to keep records such as invoices. IP hashes used against spam are deleted after 30 days.

Your choices and rights

You can export all of your research at any time, and you can ask us to access, correct or delete your personal information by writing to privacy@useannula.com. Depending on where you live, including the EU, the UK and California, you may have further rights, such as objecting to processing or asking us to restrict it. We will not treat you differently for using them. We answer requests within 30 days.

Security

Data is encrypted in transit and at rest, each account's data is isolated from every other account, and access inside Annula is limited to the people who need it to run the Service. No system is perfectly secure; if a breach affects you, we will tell you promptly.

Children

The Service is for people 18 and older. We don't knowingly collect information from children.

International transfers

Annula is operated from the United States, and our providers may process data in other countries. Where the law requires it, we rely on standard contractual clauses or similar safeguards.

Changes

If we change this policy in a way that matters, we'll email you or show a notice in the app before the change takes effect.

Contact

Questions or requests: privacy@useannula.com. General contact: team@useannula.com.