YOUR PRIVACY MATTERS. This Privacy Policy explains what information Medea collects, how we use and share it, your rights, and how we protect it. By using Medea, you agree to this Policy.
This Privacy Policy ("Policy") describes how Medea, LLC, a Delaware limited liability company ("Medea," "we," "us," or "our"), collects, uses, shares, retains, and protects personal information when you use our websites, mobile applications, and other services (collectively, the "Services").
This Policy applies to all Users of the Services. Capitalized terms not defined in this Policy have the meanings given in our Terms of Service, available at https://getmedea.com/terms.
If you are a California resident, please see Section 11 for additional rights under the California Consumer Privacy Act and California Privacy Rights Act (collectively, "CCPA").
If you are a resident of the European Economic Area, the United Kingdom, or Switzerland, please see Section 12 for additional rights under the General Data Protection Regulation ("GDPR") and UK GDPR.
1. Scope of This Policy
In plain English: This Policy covers everything about how Medea handles your personal information.
This Policy covers personal information that Medea collects:
- When you visit our websites, mobile applications, or other online properties;
- When you create or use an Account, including as an Advisor or Explorer;
- When you connect a Brokerage Account through SnapTrade or another Integration Partner;
- When you subscribe to an Advisor or process payments through Stripe;
- When you communicate with us by email, support channels, or social media;
- When you participate in surveys, promotions, or events that we host.
This Policy does not cover information collected by third parties that you interact with separately, including Brokerage Account providers (e.g., Charles Schwab, Fidelity, Robinhood), SnapTrade (Passiv Financial Technologies Inc.), Stripe, Inc., or other service providers operating their own platforms. Their privacy practices are governed by their own privacy policies.
2. Information We Collect
In plain English: We collect what you give us (name, email, etc.), what we observe (how you use Medea), and what we get from connected services (your broker, Stripe).
2.1 Information You Provide to Us
When you create an Account or use the Services, we collect:
- Identification information: full legal name, email address, country of residence, date of birth, username, profile photo (optional);
- Authentication information: password (stored as a salted hash), two-factor authentication settings, security questions;
- Advisor-specific information: biography, strategy description, sector focus, geographic focus, language(s), tax forms (e.g., IRS Form W-9 or Form W-8BEN), tax identification number (collected by Stripe for tax reporting, not stored by Medea);
- User-generated content: posts, comments, responses to questions, biographies, descriptions, and any other content you post on the Services;
- Communications: messages you send to us through support, contact forms, or in-Platform messaging;
- Survey, promotional, or event participation information.
2.2 Information from Connected Services
When you connect a Brokerage Account through SnapTrade or another Integration Partner, we receive (on a read-only basis) the following financial information about that Brokerage Account:
- Account-level data: account type (e.g., individual, IRA, joint), base currency, broker name, account creation date;
- Holdings: security identifiers (ticker, ISIN, CUSIP), position quantities, position values;
- Transactions: purchase and sale records (security, quantity, price, date), dividends, interest, fees, transfers, corporate actions;
- Performance metrics: cumulative return, periodic returns, time-weighted return, allocation percentages, sector breakdowns.
Medea does not receive, request, or store: your brokerage account number, brokerage login credentials (when OAuth is used), social security number or other government identification, contact information stored at the brokerage, or any data outside the connected Brokerage Account.
When you process a Subscription through Stripe, Medea receives (from Stripe) limited payment information: transaction identifier, status, amount, currency, and the last four digits of the payment card (where applicable). Medea does not receive or store full payment card numbers, CVV codes, or banking credentials.
2.3 Information We Collect Automatically
When you use the Services, we and our service providers automatically collect:
- Device information: device type (desktop, mobile, tablet), operating system, browser type and version, device identifiers, screen resolution, and language preferences;
- Connection information: IP address, internet service provider, approximate geographic location (city or region), and time zone;
- Usage information: pages viewed, features used, clicks, scrolls, time spent on pages, referring URLs, search queries within the Services, and crash reports;
- Cookies and similar technologies: information collected via cookies, web beacons, pixels, SDKs, and similar technologies, as described in Section 8.
2.4 Information from Other Sources
We may receive information about you from publicly available sources, business partners, identity verification services (where required for compliance), and analytics providers. We use this information to verify identities, prevent fraud, improve Services, and comply with law.
3. How We Use Information
In plain English: We use your information to run Medea, process payments, keep things secure, comply with the law, and improve the Platform.
We use the information we collect for the following purposes:
3.1 Providing the Services
- Creating and maintaining your Account;
- Displaying broker-verified performance and holdings on Advisor profiles;
- Enabling you to follow, subscribe to, and view Advisors;
- Processing Subscriptions and payments (in conjunction with Stripe);
- Calculating platform fees and Advisor payouts;
- Sending transactional communications (e.g., subscription confirmations, billing notices).
3.2 Security and Fraud Prevention
- Authenticating you and protecting your Account from unauthorized access;
- Monitoring for fraudulent activity, market manipulation, money laundering, and other unlawful activity;
- Investigating violations of our Terms of Service or applicable law;
- Responding to security incidents and reporting them where required by law.
3.3 Communication
- Responding to your inquiries and providing customer support;
- Sending administrative messages about the Services (e.g., updates to these policies, security alerts);
- Sending marketing communications about Medea features, content, or related products, where permitted by law and subject to your communication preferences.
3.4 Analytics and Improvement
- Understanding how Users interact with the Services and identifying areas for improvement;
- Conducting research, testing, and development of new features;
- Producing aggregated or anonymized statistics about Platform usage.
3.5 Legal and Regulatory Compliance
- Complying with applicable laws, regulations, court orders, subpoenas, and law enforcement requests;
- Responding to claims, defending Medea's legal rights, and enforcing our Terms;
- Cooperating with regulators (including the SEC, FINRA, FinCEN, state securities regulators, and consumer protection agencies).
3.6 Aggregated and Anonymized Information
We may aggregate or anonymize personal information so that it no longer identifies you, and we may use and share such aggregated or anonymized information for any lawful purpose, including for analytics, research, marketing, and public reporting about Platform activity. Aggregated or anonymized information is not subject to this Policy.
4. How We Share Information
In plain English: We share your info only when we need to run the Platform (with Stripe, SnapTrade, hosting), to comply with the law, or with your consent. We do not sell your information.
MEDEA DOES NOT SELL YOUR PERSONAL INFORMATION TO THIRD PARTIES. MEDEA DOES NOT "SHARE" YOUR PERSONAL INFORMATION FOR CROSS-CONTEXT BEHAVIORAL ADVERTISING AS THOSE TERMS ARE DEFINED UNDER CCPA/CPRA.
4.1 Service Providers (Processors)
We share personal information with service providers who process information on our behalf to operate the Services. These include:
- Stripe, Inc. — payment processing for Subscriptions; tax form generation for Advisors; KYC and identity verification for Advisors receiving payouts.
- SnapTrade / Passiv Financial Technologies Inc. — brokerage data integration for Advisor profiles.
- Cloud hosting provider(s) — infrastructure to operate the Services (e.g., Amazon Web Services, Google Cloud, or similar).
- Email and communication providers — transactional emails, support communications, and notifications.
- Analytics providers — understanding usage and improving the Services (e.g., Google Analytics, or similar).
- Security and fraud-prevention providers — detecting and preventing fraudulent activity.
- Identity verification providers — where required to verify Users (typically for Advisors).
Service providers are bound by contract to process personal information only on Medea's instructions and only for the purposes set out in the relevant agreement, and to implement reasonable security measures.
4.2 Other Users
Certain information is shared with other Users as a fundamental aspect of the Services:
- Public profile information (username, profile photo, biography, performance metrics, sector focus, strategy description) is visible to other Users browsing your Advisor profile;
- Content you post (posts, comments, responses to questions, public messages) is visible to other Users who can access it;
- For Advisors with paid Subscriptions, certain detailed information (e.g., position sizes, allocations, transaction history) is visible to your Subscribers.
Medea does not display brokerage account numbers, payment card information, government identification, or other sensitive identifiers.
4.3 Business Transfers
If Medea is involved in a merger, acquisition, asset sale, reorganization, financing, dissolution, bankruptcy, or similar transaction, personal information may be transferred to the acquiring or surviving entity, subject to standard confidentiality protections and applicable law.
4.4 Legal Obligations
We may disclose personal information when we believe in good faith that disclosure is necessary to:
- Comply with applicable law, regulation, court order, subpoena, or other legal process;
- Cooperate with a law enforcement, regulatory, governmental, or judicial authority;
- Enforce our Terms of Service or other agreements;
- Protect the rights, property, safety, or security of Medea, our Users, or any third party;
- Detect, prevent, or address fraud, security, or technical issues.
4.5 With Your Consent
We may share personal information with other third parties when you direct or expressly consent to such sharing.
5. Data Retention
In plain English: We keep your information only as long as we need to, generally while your account is active and a reasonable period after.
We retain personal information for as long as needed to provide the Services, comply with legal obligations, resolve disputes, enforce our agreements, and pursue legitimate business interests. Specifically:
- Account information: for the duration of your Account plus a reasonable period (typically up to seven (7) years) after account deletion to comply with legal, tax, accounting, and regulatory requirements.
- Brokerage data: for the duration of the brokerage connection plus historical data displayed on the Advisor profile; on disconnection, data may remain displayed on the profile subject to deletion requests.
- Payment and tax records: for at least seven (7) years following the relevant transaction or filing year, as required by U.S. tax and financial recordkeeping laws.
- User Content: for as long as it remains visible on the Services or as needed for legitimate business purposes; after deletion, backup copies may persist for a limited period.
- Communications: typically for up to three (3) years from the date of communication.
- Security and fraud-prevention records: as long as needed to detect, investigate, or prevent malicious activity.
- Aggregated or anonymized data: may be retained indefinitely as it no longer identifies you.
On termination of your Account, we will delete or anonymize your personal information within a reasonable period, except where retention is required by law, necessary to resolve disputes, or appropriate to enforce our Terms.
6. Security
In plain English: We take security seriously. We use encryption, access controls, and other measures. But no system is 100% secure, so use a strong password and stay vigilant.
Medea implements administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit using industry-standard TLS;
- Encryption of sensitive data at rest;
- Access controls limiting personal information access to authorized personnel on a need-to-know basis;
- Multi-factor authentication for administrative access;
- Regular security reviews and vulnerability assessments;
- Logging and monitoring of access to systems containing personal information;
- Incident response procedures for suspected security events;
- Vendor due diligence for service providers handling personal information.
However, no method of internet transmission, electronic storage, or security measure is 100% secure. We cannot guarantee absolute security. You are responsible for maintaining the security of your Account credentials and for taking reasonable precautions to protect your information.
If we become aware of a security incident affecting personal information, we will notify affected Users and applicable regulators where required by law and within the timeframes required by law (including, where applicable, within 72 hours under GDPR).
7. Your Choices and Rights
In plain English: You can access, correct, delete, or download your information. You can opt out of marketing. Specific legal rights depend on where you live.
7.1 Account Information
You may access, update, or correct your Account information at any time through your Account settings. You may also request access, correction, deletion, or portability of your personal information by contacting us at privacy@getmedea.com.
7.2 Marketing Communications
You may opt out of marketing communications at any time by clicking the "unsubscribe" link in any marketing email or by adjusting your communication preferences in your Account settings. We will continue to send you transactional and administrative communications (e.g., billing notices, security alerts), which are not subject to opt-out.
7.3 Cookies and Tracking
You can manage cookies through your browser settings. Most browsers allow you to block or delete cookies, or to be notified when cookies are set. Note that blocking essential cookies may prevent parts of the Services from functioning. See Section 8 for more information on cookies.
7.4 "Do Not Track" Signals
Some browsers transmit "Do Not Track" signals. Because there is no industry standard for how websites should respond to such signals, Medea currently does not respond to Do Not Track signals.
7.5 Account Deletion
You may delete your Account at any time through Account settings or by contacting us at privacy@getmedea.com. Deletion of your Account does not delete information that we are required to retain by law (see Section 5).
8. Cookies and Similar Technologies
In plain English: We use cookies to make Medea work and to understand how you use it. You can control cookies in your browser.
Medea and our service providers use cookies, web beacons, pixels, SDKs, local storage, and similar technologies (collectively, "Cookies") to operate the Services, remember your preferences, analyze usage, and improve the Services.
8.1 Categories of Cookies
- Strictly necessary cookies: essential for the Services to function (e.g., authentication, security). Cannot be disabled without breaking the Services.
- Functional cookies: remember preferences and improve experience (e.g., language, display settings).
- Analytics cookies: help us understand how Users interact with the Services to improve them.
- Marketing cookies (if applicable): used to deliver relevant communications. Medea does not currently use marketing cookies for cross-context behavioral advertising.
8.2 Managing Cookies
You can control cookies through your browser settings (e.g., block all cookies, accept only first-party cookies, delete cookies). Visit https://www.allaboutcookies.org or your browser's help documentation for instructions. Note that disabling strictly necessary cookies may prevent the Services from functioning correctly.
For EEA, UK, and Swiss residents, we obtain consent for non-essential cookies as required by applicable law (e.g., the ePrivacy Directive). You may withdraw consent at any time through our cookie management tool, accessible at the bottom of our website.
9. International Data Transfers
In plain English: Medea is based in the U.S. If you're outside the U.S., your information may be transferred to and processed in the U.S. We protect it as required by law.
Medea is established in the United States. Personal information we collect is processed and stored in the United States and may also be processed by service providers in other countries. Data protection laws in the United States may differ from those in your country and may provide less protection.
9.1 Safeguards for Transfers from the EEA, UK, and Switzerland
Where we transfer personal information from the European Economic Area, the United Kingdom, or Switzerland to a country that has not received an adequacy decision from the European Commission, UK government, or Swiss Federal Data Protection and Information Commissioner, we rely on one or more of the following legal mechanisms:
- Standard Contractual Clauses approved by the European Commission and, where applicable, the UK International Data Transfer Addendum or Swiss equivalents;
- Your explicit consent to the transfer, where appropriate;
- Necessary for the performance of a contract between you and Medea;
- Other lawful transfer mechanisms permitted under applicable law.
You may request a copy of the safeguards we use for international transfers by contacting privacy@getmedea.com.
10. Children's Privacy
In plain English: Medea is for adults 18 and older. We do not knowingly collect information from children.
The Services are not directed to, and may not be used by, any person under the age of 18. Medea does not knowingly collect personal information from any person under the age of 13, in compliance with the Children's Online Privacy Protection Act ("COPPA"). If we learn we have collected personal information from a child under 13, we will promptly delete that information.
If you are a parent or guardian and believe a child under 13 has provided us with personal information, please contact us at privacy@getmedea.com so we may take appropriate action.
11. California Privacy Rights (CCPA / CPRA)
In plain English: If you live in California, you have extra rights: see what we collect, ask us to delete it, correct it, or limit how we use sensitive info. We do not sell your data.
This section applies to California residents and supplements other sections of this Policy. Capitalized terms not defined in this Policy have the meanings given in the CCPA/CPRA.
11.1 Categories of Personal Information Collected
In the past 12 months, Medea has collected the following categories of personal information about California residents:
- Identifiers: name, email address, username, IP address, online identifiers.
- Customer records (Cal. Civ. Code § 1798.80(e)): name, signature, financial information, account information.
- Commercial information: transaction records, subscription history, payment information (limited; full payment data held by Stripe).
- Internet/network activity: browsing history within the Services, interactions with content, search queries within the Services, device and connection data.
- Geolocation data: approximate location derived from IP address (city/region only).
- Professional/employment-related information: for Advisors, employer or affiliation information, where provided.
- Inferences: inferences drawn from the above to characterize User preferences.
- Sensitive personal information: Account log-in credentials (for authentication only), tax identification numbers (collected and held by Stripe for Advisor tax reporting).
11.2 Sources, Purposes, and Disclosures
Sources of personal information are described in Section 2. Business and commercial purposes for which we use personal information are described in Section 3. Categories of third parties to whom we disclose personal information are described in Section 4.
11.3 No "Sale" or "Sharing"
Medea does not sell personal information. Medea does not share personal information for cross-context behavioral advertising as those terms are defined under CCPA/CPRA.
11.4 California Resident Rights
If you are a California resident, you have the following rights:
- Right to know: request information about the categories and specific pieces of personal information we collect, use, and disclose.
- Right to delete: request deletion of personal information we hold about you, subject to certain exceptions.
- Right to correct: request correction of inaccurate personal information.
- Right to opt out of sale or sharing: as noted, Medea does not engage in sale or sharing as defined under CCPA/CPRA.
- Right to limit use of sensitive personal information: we use sensitive personal information only as permitted by Section 1798.121(a) (e.g., for authentication, fraud prevention, and as necessary to provide the Services).
- Right to non-discrimination: we will not discriminate against you for exercising your rights.
11.5 Exercising Your Rights
To exercise any of these rights, contact us at privacy@getmedea.com with the subject line "California Privacy Request." We will verify your identity before responding, typically by confirming information you have provided to us. You may also designate an authorized agent to make a request on your behalf, with appropriate proof of authorization.
We will respond to verifiable requests within 45 days, with a possible 45-day extension if reasonably necessary.
11.6 "Shine the Light" (California Civil Code § 1798.83)
California residents may request information about Medea's disclosure of personal information to third parties for those parties' direct marketing purposes. To make such a request, contact privacy@getmedea.com. Medea does not currently share personal information with third parties for their direct marketing.
12. European Privacy Rights (GDPR / UK GDPR)
In plain English: If you live in Europe, the UK, or Switzerland, you have rights under GDPR: access, correct, delete, port, restrict, or object. Contact us to exercise them.
This section applies to residents of the European Economic Area ("EEA"), the United Kingdom, and Switzerland (collectively, "European Users") and supplements other sections.
12.1 Data Controller
For purposes of GDPR and UK GDPR, the data controller is Medea, LLC, [REGISTERED ADDRESS, DELAWARE, USA]. You may contact us at privacy@getmedea.com or by mail at the registered address.
12.2 Legal Bases for Processing
We process personal information of European Users based on one or more of the following legal bases:
- Performance of a contract (Art. 6(1)(b)): to provide the Services pursuant to our Terms of Service, including processing Subscriptions and displaying Advisor performance.
- Legitimate interests (Art. 6(1)(f)): for security, fraud prevention, Service improvement, and analytics, balanced against your interests and rights.
- Compliance with legal obligations (Art. 6(1)(c)): for tax, accounting, anti-money-laundering, and other legal requirements.
- Consent (Art. 6(1)(a)): for non-essential cookies, marketing communications, and certain other processing where required by law. You may withdraw consent at any time.
12.3 European User Rights
European Users have the following rights under GDPR / UK GDPR:
- Right of access: obtain confirmation of whether we process your personal data and request a copy.
- Right to rectification: request correction of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): request deletion of your personal data in certain circumstances.
- Right to restriction of processing: request that we limit processing in certain circumstances.
- Right to data portability: receive your data in a structured, commonly used, machine-readable format and to transmit it to another controller, where technically feasible.
- Right to object: object to processing based on legitimate interests, including for direct marketing.
- Right to withdraw consent: withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
- Right to lodge a complaint: file a complaint with your local supervisory authority. A list of EEA supervisory authorities is available at https://edpb.europa.eu/about-edpb/board/members_en. UK residents may contact the Information Commissioner's Office at https://ico.org.uk.
12.4 Automated Decision-Making
Medea does not make decisions about you based solely on automated processing, including profiling, that produce legal effects on you or similarly significantly affect you.
12.5 Exercising Your Rights
To exercise these rights, contact us at privacy@getmedea.com. We will respond within one month, subject to extensions permitted by law. We may need to verify your identity before responding.
13. Financial Information; Gramm-Leach-Bliley Act
In plain English: To the extent we are considered a financial institution under U.S. financial privacy law, this section explains our practices.
To the extent the Gramm-Leach-Bliley Act ("GLBA") applies to Medea's collection and use of nonpublic personal information about individuals who obtain or use financial products or services from us, this section serves as our GLBA privacy notice. (Medea is not currently a regulated financial institution, but we adopt these practices voluntarily to protect User information.)
13.1 Information We Collect
Information we may collect that could be considered nonpublic personal information under GLBA includes:
- Information you provide on applications and forms (e.g., name, email, date of birth);
- Information about your transactions with us (e.g., subscription history);
- Information received from third parties (e.g., performance and holdings data received from Brokerage Accounts via SnapTrade).
13.2 Disclosure Practices
Medea does not disclose nonpublic personal information about Users to nonaffiliated third parties except as described in Section 4 (Service Providers, Other Users, Business Transfers, Legal Obligations, or With Your Consent).
We restrict access to nonpublic personal information to those employees and service providers who need to know the information to provide the Services. We maintain physical, electronic, and procedural safeguards designed to protect such information.
14. Other U.S. State Privacy Laws
In plain English: Residents of Virginia, Colorado, Connecticut, Utah, and other states with privacy laws have similar rights to California residents.
In addition to California, several U.S. states have enacted comprehensive consumer privacy laws, including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and others. Residents of these states may have rights similar to those described in Section 11, including the right to access, delete, correct, and obtain copies of personal information, and the right to opt out of targeted advertising or the sale of personal information (Medea does not engage in either).
To exercise rights under any U.S. state privacy law, contact us at privacy@getmedea.com with the subject line "State Privacy Request" and your state of residence.
15. Changes to This Policy
In plain English: We may update this Policy. We'll tell you about material changes.
Medea may update this Policy from time to time. The current version is always available at https://getmedea.com/privacy with the effective date noted at the top. If we make material changes, we will provide notice by email, in-Platform notification, or other reasonable means, at least 30 days before the changes take effect (or shorter notice where required by law or emergency circumstances).
By continuing to use the Services after the effective date of any changes, you accept the updated Policy. If you do not agree, please stop using the Services and delete your Account.
16. Contact Us
In plain English: Have questions or want to exercise your privacy rights? Email us.
If you have questions, concerns, or complaints about this Policy or our privacy practices, or wish to exercise your privacy rights, please contact us:
Email: privacy@getmedea.com
Mail: Medea, LLC, Attn: Privacy Officer, [REGISTERED AGENT ADDRESS, DELAWARE, USA]
For European Users, we have not designated an EU representative under GDPR Article 27, but you may contact us directly using the information above.
If you are not satisfied with our response, you may have the right to lodge a complaint with your local data protection or consumer protection authority.
Acknowledgment
By using the Services, you acknowledge that you have read and understood this Privacy Policy.
Medea, LLC
A Delaware Limited Liability Company
Contact: privacy@getmedea.com
Effective Date: [TO BE SET ON LAUNCH]
Version: 1.0