This policy explains how Filing Shock collects, uses, shares, protects, and deletes account, product, billing, notification, mobile, and API-related information.
Last updated: August 2, 2026
Filing ShockThis Privacy Policy applies to Filing Shock websites, mobile apps, APIs, account pages, billing flows, support interactions, and notification systems.
Public SEC filings, issuer disclosures, market data, company details, and company analytics are not personal information by themselves. Account-specific activity tied to an individual user is handled as described below.
The service shares limited information with the providers used to operate enabled product features, including hosting, sign-in, payment, app-store, email, push-notification, Discord or webhook destinations you configure, security, and support systems. Production provider disclosures must match the providers that are actually enabled.
The service may disclose information when required by law, legal process, security investigation, fraud prevention, provider enforcement, business transfer, or protection of rights, users, and the service.
The service does not sell personal information or use personal information for third-party targeted advertising. Filing Shock will provide any notice, choices, and consent required by applicable law before introducing a materially different practice.
A web payment provider, Apple, Google, or another app-store payment provider may process payment details under their own terms and privacy policies. Filing Shock receives payment and subscription records needed to provide access, support billing, and keep records.
If a mobile app offers account creation, purchases, subscriptions, push notifications, or platform sign-in, the app and store listing may require privacy and data-safety disclosures that match the data practices described in this policy.
The web app uses cookies and similar technologies to keep users signed in, protect mutations, remember account state, and maintain security. Session cookies are HttpOnly and SameSite=Lax, and they are Secure when the service is delivered over production HTTPS.
Mobile apps may store session tokens or similar credentials in secure device storage and may register push tokens if the user enables push notifications. Logging out removes the session from that device. Deleting the app removes locally stored credentials but does not by itself revoke a server-side session. Operator-completed account closure revokes the account's sessions.
Users may opt into operational messages and alert notifications. Billing, security, account, and support notices may be sent when needed to provide or protect the service. Filing Shock does not send optional marketing messages unless a separate compliant opt-in and unsubscribe process is enabled.
SMS, push, Discord, and webhook delivery may be controlled by device settings, provider settings, account settings, or destination configuration. Message and data rates may apply for SMS or mobile data.
Account and product data is kept while the account is active or as needed to provide the service. Some records may be retained after deletion where reasonably necessary for billing, tax, legal compliance, fraud prevention, security, backups, dispute resolution, audit logs, or provider requirements.
After an operator completes account closure, the encrypted address used for the final confirmation email is not used for delivery after 30 days, is removed sooner after successful delivery, and is removed by the next daily cleanup after that cutoff. Filing Shock may retain a keyed email fingerprint and a minimal closure audit record. Raw payment customer and subscription identifiers are removed from that record; keyed, non-plaintext provider-resource fingerprints may remain for up to 90 days solely to prevent late provider events from reattaching closed-account data, after which they are purged. Native purchase-intent records normally expire within seven days. Encrypted app-store subscription references converted for closure safety may remain for up to 400 days. Unresolved provider refund or entitlement cases remain until an operator records a verified outcome, and resolved case records are purged after up to 400 additional days.
Public company filings, issuer details, market data, and company-level analytics may remain in the service after an account is closed because they are not created from a user's personal account data.
Signed-in users can export their account data from Profile. Filing Shock does not provide a self-service account-deletion control. Users may request correction or other privacy help through the signed-in Settings page. Filing Shock verifies account control before acting on account-specific requests.
Depending on your location, you may have rights to know, access, correct, delete, export, opt out of certain sharing or targeted advertising, limit certain sensitive data uses, or appeal a privacy decision. The service does not sell personal information or use personal information for third-party targeted advertising.
The service is designed to use hashed session tokens and one-time email codes, protect mutation routes, limit abuse, validate inputs, and restrict admin functionality. No system can guarantee perfect security.
Users should protect email and OAuth accounts, devices, notification destinations, and API keys, and report suspected unauthorized access promptly.
Filing Shock accounts are intended only for people who are at least 18 years old and at least the legal age required to enter a binding contract where they live. Filing Shock is not directed to children, and the operator does not knowingly create accounts for or collect account information from anyone under 18.
Filing Shock may update this Privacy Policy as the product, providers, mobile apps, payment flows, or law changes. Material updates will be posted with a new effective date and, when required, users will be asked to accept the updated documents before continuing.
Privacy export is available on the signed-in Profile page.