Privacy Policy
Last updated: July 29, 2026
Market Dip is operated by AGR Holdings LLC, a Wyoming limited liability company.
This Privacy Policy explains how AGR Holdings LLC, a Wyoming limited liability company (“AGR Holdings,” “we,” “us,” or “our”), collects, uses, discloses, and safeguards personal information in connection with the Market Dip website, mobile applications, and related services (collectively, the “Service”). It applies to anyone who visits our website, creates an account, or otherwise interacts with the Service. By using the Service, you acknowledge the practices described in this Policy. If you do not agree with these practices, please do not use the Service.
1. Information We Collect
We collect the following categories of information:
- Account information (through Clerk). When you create an account we collect identifiers such as your email address, username, an optional display name, and — if you enable them — phone number, profile photo, or connected social identifiers. Clerk, our authentication provider, processes this information on our behalf and issues session tokens used to keep you signed in.
- Subscription and payment information (through Stripe). If you subscribe to a paid plan, our payment processor, Stripe, collects and processes your payment credentials directly. We never receive or store your full card number, CVV, or bank credentials. We receive from Stripe only the information needed to manage your subscription — such as your customer identifier, plan, billing status, the last four digits of your card, the card’s brand and expiration month/year, and country.
- Usage and preferences. We collect information about how you interact with the Service, including symbols you scan or add to watchlists, the alerts you subscribe to, the preferences you set (for example, timeframes, overlays, notification channels, and the explicit- labels toggle), device push tokens you provide so we can deliver push notifications, and interface settings stored in your browser or app.
- DipBot conversation logs. When you interact with DipBot, we log your prompts, the AI responses, and associated metadata (timestamp, model version, account identifier, truncation and safety events) for the purposes described in Section 2. These logs are retained under our compliance retention schedule described in Section 5.
- Device, log, and diagnostic data. Our servers automatically receive information such as your Internet Protocol (IP) address, approximate geographic location derived from that address, browser or app version, operating system, device type, referring URL, and timestamps of your requests. We use this to operate the Service, diagnose errors, and protect against abuse.
We do not collect information about your portfolio holdings, account balances, income, net worth, or risk tolerance. The Service does not offer or accept any input fields for such data. If you volunteer such information into DipBot, please do not — Market Dip is not designed to receive or act on it, and DipBot output does not take personal financial circumstances into account.
2. How We Use Information
We use the information we collect to:
- provide, maintain, secure, and improve the Service;
- authenticate your account and manage your subscription;
- deliver the alerts, emails, push notifications, and in-app messages you request;
- respond to your support inquiries and communicate with you about the Service;
- monitor the quality and safety of DipBot output and comply with our AI-provider’s policies;
- detect, investigate, and prevent fraud, abuse, and violations of our Terms of Service;
- comply with legal obligations, respond to lawful requests, and enforce our rights; and
- conduct internal research and analytics to improve the Service, in aggregated or de-identified form where practical.
We do not sell your personal information. We do not share your personal information with third parties for their independent advertising or marketing purposes, and we do not participate in cross-context behavioral advertising.
3. Service Providers & Sub-processors
We rely on a small number of service providers who process personal information on our behalf, under written contracts that require them to handle it in accordance with this Policy and applicable law. As of the date at the top of this Policy, our principal sub-processors are:
- Clerk — user authentication and account management.
- Stripe — subscription billing and payment processing.
- Vercel — web application hosting and edge delivery.
- Railway — API and background-worker hosting.
- Anthropic — large-language-model inference for DipBot and related AI features.
- Market-data providers — including Yahoo Finance, Binance, and other providers that supply prices, fundamentals, calendars, and news.
Personal information may be processed in the United States and in other countries where our sub-processors operate. Where required by applicable law, we rely on lawful transfer mechanisms such as standard contractual clauses to protect information that leaves your country of residence.
4. Cookies & Local Storage
We use cookies and local storage only for functionality that is essential to the Service. In particular, our authentication provider sets session cookies to keep you signed in, and we store interface preferences (for example, the explicit-labels toggle, chart overlay states, and tab order) in your browser’s localStorage so the Service remembers them across visits.
We do not use third-party advertising cookies, third-party marketing pixels, or cross-site tracking tags. You can clear cookies and local-storage entries at any time from your browser settings; doing so may sign you out and reset your preferences.
5. Retention
We retain personal information for as long as your account is active, and for a reasonable period thereafter to comply with our legal, tax, and accounting obligations, to resolve disputes, and to enforce our agreements. Specific retention periods vary by data type. DipBot conversation logs are retained for a rolling period consistent with our safety-and-abuse monitoring and any applicable legal retention requirements.
When you request deletion of your account, we will delete or de-identify your personal information within a reasonable period, except where we are required or permitted by law to retain it (for example, to comply with tax, audit, or fraud-prevention obligations, or to satisfy a legal hold).
6. Your Privacy Rights
Depending on where you live, you may have rights with respect to your personal information, including:
- the right to access the personal information we hold about you;
- the right to correct inaccurate or incomplete information;
- the right to delete your personal information (subject to legal retention requirements);
- the right to portability of the information you provided to us;
- the right to object to or restrict certain processing;
- the right to opt out of the sale or sharing of personal information (we do not engage in either); and
- the right to withdraw consent where processing is based on consent.
We honor rights requests under the California Consumer Privacy Act (as amended by the CPRA), the European Union General Data Protection Regulation, the United Kingdom Data Protection Act, and analogous laws in other jurisdictions. You may exercise any of these rights by writing to us at legal@marketdip.app. We may need to verify your identity before responding. You will not be discriminated against for exercising your rights.
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you also have the right to lodge a complaint with your local supervisory authority if you believe our processing of your personal information violates applicable law.
7. Children
The Service is not directed to children under thirteen (13) years of age, and we do not knowingly collect personal information from children under thirteen. If you believe a child under thirteen has provided us with personal information, please contact us at legal@marketdip.app and we will take steps to delete the information.
Certain features of the Service — including the explicit-labels grading option — are additionally gated to users seventeen (17) and older by an in-app agreement.
8. Security & Data-Breach Notice
We employ administrative, technical, and physical safeguards designed to protect personal information against loss, misuse, unauthorized access, disclosure, alteration, and destruction. Examples include TLS-encrypted transport, least-privilege access controls, secrets management, third-party security review of our authentication and payment sub-processors, and regular monitoring for unusual account activity.
No online service is perfectly secure. If we become aware of a security incident that materially affects the confidentiality, integrity, or availability of your personal information, we will notify you and any applicable regulator without undue delay, and in any event within the time frames required by applicable law.
9. Changes to This Policy
We may update this Privacy Policy from time to time. If we make a material change, we will update the “Last updated” date at the top and provide notice through the Service or by email to the address associated with your account before the change takes effect. We encourage you to review this Policy periodically.
10. Contact
If you have questions or concerns about this Policy, or wish to exercise a privacy right, please contact us at legal@marketdip.app. AGR Holdings LLC is the entity responsible for the processing of your personal information described in this Policy.