Privacy Policy
Last updated: 2026-09-08
This Privacy Policy explains how personal data is processed when you use the application provided at hentschel.ai (the “Service”). The controller is based in Switzerland and the Swiss Federal Act on Data Protection (revFADP) applies. For users resident in the EU/EEA, the General Data Protection Regulation (GDPR) may additionally apply; the legal bases cited under Art. 6 GDPR apply insofar as the GDPR is applicable.
1. Controller
Controller within the meaning of the revFADP (and, where applicable, Art. 4(7) GDPR):
Hentschel Consulting GmbH
Sandmatte 2a, 5712 Beinwil am See, Switzerland
Email: support@hentschel.ai
Data protection contact: support@hentschel.ai. An EU representative under Art. 27 GDPR is currently not appointed; please direct any requests to the contact address above.
2. Categories of data processed
- Account data: email address, password (stored only as a cryptographic hash), optional name and avatar, language/display preferences, verification, password-reset and sign-in-link tokens (each stored only as a digest). If you register a passkey we additionally store its public key, a credential id, the signature counter, the supported transports and a device label you choose. The private key never leaves your device.
- Contract and payment data: selected plan, subscription/billing status, customer ID at the payment provider. Payment details (e.g. card data) are processed solely by the payment provider.
- Usage and content data: chat history and messages, images uploaded as part of a message, investment profile (e.g. goal, risk capacity, horizon, regions, sectors, ESG preferences, savings goal), portfolio data (securities, transactions, cash balances), watchlist entries (watched securities including target price and your notes), notifications and usage counters.
- Feedback and survey data: ratings of answers (thumbs up/down), bug reports and feature requests submitted through the feedback form, and your replies to our short satisfaction surveys (a 1–5 rating and optional free text).
- Technical data: IP address, timestamps, server logs, device/browser information, and data used for rate limiting.
- Shared content (share links): when you share an analysis result, we create a publicly accessible page under a random address containing only privacy-preserving metrics (e.g. percentage performance, scores, benchmark and security names, as-of date) — no position sizes, amounts, portfolio values, profile data or rationale text.
3. Purposes of processing
As a controller based in Switzerland, our processing follows primarily the data processing principles of the revFADP (lawfulness, good faith, proportionality, purpose limitation, transparency and data security, Art. 6 revFADP). The revFADP does not require a specific “legal basis” for processing by private persons. The GDPR legal bases cited below apply only where the GDPR is applicable to you (users in the EU/EEA).
3.1 Providing the account and the Service
We process account, content and usage data to register and authenticate you and to provide the contractually agreed features. This serves performance of the user agreement; where the GDPR applies, the legal basis is Art. 6(1)(b) GDPR.
3.2 Payment processing
For paid subscriptions we process contract and billing data and transmit the required data to our payment provider. This serves contract performance and compliance with commercial and tax retention obligations; where the GDPR applies, the legal bases are Art. 6(1)(b) and (c) GDPR.
3.3 AI-assisted analysis
To generate the analyses and answers, your inputs and relevant profile and portfolio data are transmitted to and processed by a specialised AI provider (processor). This serves provision of the agreed features; where the GDPR applies, the legal basis is Art. 6(1)(b) GDPR. Please do not enter sensitive personal data (Art. 5(c) revFADP / Art. 9 GDPR) into the chat.
These AI requests are technically configured so that they are routed only to a provider that processes them in an EU region, that inputs and outputs are not retained once the request completes (zero data retention), and that they are not used to train AI models. The only exception is the optional web research (section 4).
3.4 Email communication and feedback
We send transactional emails (e.g. verification, password reset, notices about portfolio reviews or payments). If you use the feedback form or answer one of our short satisfaction surveys, we process what you submit in order to handle your request and to improve the Service. This serves contract performance and our legitimate interest in secure account management and in improving our offering; where the GDPR applies, the legal bases are Art. 6(1)(b) and (f) GDPR respectively.
3.5 Security, stability and abuse prevention
To ensure security and stability we process technical data and use rate limiting. This is based on our legitimate interest in a secure, abuse-free operation; where the GDPR applies, the legal basis is Art. 6(1)(f) GDPR.
3.6 Error and stability monitoring
To detect and fix technical faults we use Sentry (Functional Software, Inc.), which collects error reports and technical diagnostics (error message, stack trace, the affected code location, timestamp) plus a sample of performance measurements. Its use is limited to technical operation: we have switched off the transmission of personal data (no IP addresses, request headers, cookies or request bodies), we do not record sessions (no session replay), and we run no audience or advertising analytics. The data is processed on Sentry’s EU instance (Frankfurt). This processing is required to operate the Service without faults and is therefore not optional; it is based on our legitimate interest in security and stability (where the GDPR applies: Art. 6(1)(f) GDPR), to which you may object under Art. 21 GDPR.
3.7 Quality assurance and product improvement
To measure and improve the quality of the analyses, we evaluate which concrete calls the Service made and how they subsequently played out; in addition we review metrics on how conversations run (such as response time, length and the tools used). This evaluation is strictly internal, serves no advertising profile, and no AI models are trained on your data (section 3.3).
Objection (opt-out): You can object to this use at any time in the settings under “Privacy”, by switching off the “Allow use of my data” toggle. While the objection is active, no new calls are logged for your account and your conversations are excluded from the evaluations described above. Calls already logged remain (section 8). Processing that is strictly required to operate the Service (in particular sections 3.1, 3.5 and 3.6) is unaffected. The processing is based on our legitimate interest in demonstrable quality of our analyses; where the GDPR applies, the legal basis is Art. 6(1)(f) GDPR.
3.8 Sharing analysis results (share links)
At your explicit request, you can share individual analysis results via a link. This creates a page accessible without login — that is, publicly — under a random, unguessable address that contains only the privacy-preserving metrics described above. The pages are excluded from search engine indexing (noindex) and reachable only via the random address. The associated preview image (Open Graph) is generated on our own infrastructure (hosting provider Vercel); we do not actively transmit any data to social media providers. However, if you share a link on a social network or messenger, that provider retrieves the page itself to generate a preview and thereby receives the privacy-preserving values contained in it. The page contains no reference to your person or account. You can revoke a shared link at any time, after which the page is no longer accessible. Where the GDPR applies, the legal basis is your consent (Art. 6(1)(a) GDPR) and contract performance (Art. 6(1)(b) GDPR).
4. Market data and news
To answer your requests, the Service retrieves market data (e.g. quotes, FX rates, metrics) and news from external sources. No account identifiers are transmitted to these sources.
In addition, the Service may run an isolated web search for a market question (live web research). It is on by default and can be switched off at any time in the settings under “Privacy”. Only a sanitised, public market question is transmitted — no chat history, profile, portfolio or account data. This one request does not run via Amazon Bedrock but directly via Anthropic, PBC (USA), because the search capability is only available there; it is likewise processed without retention and without model training, but it is not technically restricted to an EU region and may therefore be processed outside the EU. The search itself is executed by Anthropic through a search engine provider it engages.
5. Cookies and similar technologies
We use strictly necessary cookies, in particular for login and session management and to store preferences such as language and theme. These are required for operation. The processing is based on our legitimate interest in a secure and functional service (where the GDPR applies: Art. 6(1)(f) GDPR).
Audience measurement: We use Vercel Web Analytics to count page views. The service works without cookies and without cross-site recognition; it records the page requested, the referrer, the country of origin as well as browser and device type. A hash that rotates daily is derived from the incoming request and does not allow you to be re-identified; the IP address is not stored and no profiles are created. The processing is based on our legitimate interest in improving the Service (where the GDPR applies: Art. 6(1)(f) GDPR).
6. Recipients and processors
To provide the Service we use carefully selected providers as processors, whose processing takes place on the basis of the respective data processing clauses of the providers (Art. 9 revFADP; where applicable Art. 28 GDPR). Categories of recipients are in particular:
- Vercel Inc. (hosting, CDN, serverless infrastructure, cookieless audience measurement and routing of AI requests via the Vercel AI Gateway);
- Neon Inc. (managed PostgreSQL database storing the application data);
- Anthropic, PBC, provided via Amazon Web Services (AWS Bedrock, region eu-central-1), for processing the AI analysis requests;
- Anthropic, PBC (USA) directly — solely for the optional live web research (section 4), which receives nothing but the sanitised market question;
- Stripe, Inc. (handling of paid subscriptions);
- Resend (Plus Five Five, Inc.) (delivery of transactional emails);
- Sentry (Functional Software, Inc.) (error and stability monitoring, processed on the EU instance in Frankfurt);
- Upstash, Inc. (Redis service for rate limiting, for guarding parallel chat sessions, and for briefly buffering an in-flight answer so an interrupted chat can resume).
A current overview of the processors we use is available on request.
7. International transfers
Some providers may process data outside Switzerland and the EEA (notably the USA). Where data is disclosed to a country without an adequate level of protection, we ensure appropriate safeguards, e.g. Standard Contractual Clauses (recognised by the Swiss Federal Data Protection and Information Commissioner, FDPIC, and/or the EU Commission) or Swiss-US / EU-US Data Privacy Framework certification. Some of the providers named above are based in the USA; transfers take place on the basis of the safeguards described. For the AI analysis the restriction in section 3 applies: those requests are processed in an EU region; only the optional web research (section 4) may be processed outside the EU. Error diagnostics (section 3.6) run on Sentry’s EU instance in Frankfurt.
8. Retention
We retain personal data only as long as necessary for the stated purposes or required by statutory retention obligations. Account data is stored for the duration of account use. You can delete chats yourself at any time, individually or all at once (Settings → Privacy). Certain data (e.g. a portfolio’s transaction history) is kept for functional integrity while the associated portfolio exists. Calls already logged (section 3.7) outlive the deletion of the chat they came from — their link to that chat is severed — and are removed when the account is deleted.
When you delete your account, the associated data — chats, investment profile, portfolios, watchlist, passkeys, shared links, notifications, logged calls and earlier survey feedback — is deleted immediately, and a running paid subscription is cancelled. The closing email contains a short survey; a reply to it is stored without your email address and without any link to the account. Excluded from deletion is data subject to retention obligations (e.g. under commercial or tax law, typically up to 10 years for invoicing data). That data sits with the payment provider; we no longer keep a customer record after deletion.
9. Your rights
Under the revFADP you have in particular the right to information (access, Art. 25 revFADP), to rectification of inaccurate data, to obtain or transfer your data (Art. 28 revFADP), as well as the right to request deletion or blocking of your data or to object to processing. Where the GDPR applies, you additionally have the following rights:
- access to the data processed (Art. 15 GDPR);
- rectification of inaccurate data (Art. 16 GDPR);
- erasure (Art. 17 GDPR);
- restriction of processing (Art. 18 GDPR);
- data portability (Art. 20 GDPR);
- objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR).
You may withdraw consent at any time with effect for the future. To exercise your rights, a message to the contact details above is sufficient.
10. Right to lodge a complaint
You have the right to lodge a complaint with the competent data protection authority. In Switzerland this is the Federal Data Protection and Information Commissioner (FDPIC), edoeb.admin.ch. Where the GDPR applies, you may also contact a supervisory authority in the member state of your residence.
11. Obligation to provide data
Providing certain data (e.g. your email address) is necessary to enter into the contract and to use the Service. Without this data the Service cannot be provided, or can only be provided to a limited extent.
12. Changes to this Privacy Policy
We update this Privacy Policy when our data processing or the legal framework changes. The version published on this page applies.