Privacy Policy
Last updated: August 27, 2026
This Policy explains exactly what personal data Lobix.AI Ltd collects when you use Phenomen ETFs US, why we collect it, who receives it, how long we keep it, and the controls you have. It is written to describe our service as it actually works, including every tool the app exposes to your AI assistant.
1. Who we are
Phenomen ETFs US (the “Service”) is operated by Lobix.AI Ltd (Lobix.AI), Tel Aviv, Israel. For the purposes of the EU/UK General Data Protection Regulation, Lobix.AI Ltd is the data controller for the personal data described here; as an Israeli company we are also subject to the Israeli Privacy Protection Law, 5741-1981. Privacy questions and requests: contact@lobix.ai.
2. What this Policy covers
- This website (https://phenomen-etfs-us.site.lobix.ai), which is informational only: it has no accounts, no sign-in, and no payments.
- The Phenomen ETFs US MCP server at
https://etf-us.mcp-apps.lobix.ai/mcp, which your AI assistant (ChatGPT or Claude) connects to, and the interactive widgets it renders inside that assistant.
It does not cover the AI assistant itself. Your conversation with ChatGPT or Claude is governed by OpenAI’s or Anthropic’s own privacy policy; see section 5.
3. Data we collect, why, and how long we keep it
| Category | Exactly what | Why | Legal basis (GDPR) | Retention |
|---|---|---|---|---|
| Account identity | Your email address and the unique user identifier issued by our authentication provider (WorkOS), recorded the first time you connect the Service or first save a position or watchlist item. | To authenticate you, keep your saved positions and watchlist separate from other users’, and answer support requests. | Performance of a contract, Art. 6(1)(b). | For as long as your account exists. Deleted within 30 days of a deletion request. |
| Portfolio positions you save | For each position you choose to save: ticker symbol, start date, number of shares, and — if you supply them — average entry price, percentage allocation, and long/short direction. | To store your holdings so the Service can report and analyse them on request. | Contract, Art. 6(1)(b). | Until you delete the position, or until your account is deleted. |
| Watchlist items you save | Ticker symbol, start date, and an optional free-text note of up to 500 characters, stored exactly as you type it. | To keep your watchlist available across sessions and assistants. | Contract, Art. 6(1)(b). | Until you delete the item, or until your account is deleted. |
| Usage telemetry | One minimal record per tool call: your user identifier, the name of the tool, whether it succeeded or failed, an error code if it failed, how many milliseconds it took, and when it ran. We do not record the arguments you supply, the contents of any response, your IP address, or your device/browser. | To monitor reliability, debug errors, and understand which features are used. | Legitimate interests, Art. 6(1)(f) — keeping the Service working. | Automatically deleted 90 days after it is recorded, by a scheduled daily job. Earlier deletion on request. |
| Website cookies | None. This website sets no cookies at all — no session, analytics, advertising, or tracking cookies. The only thing stored in your browser is your light/dark theme choice, kept in localStorage on your device and never sent to us. Fonts are served from our own domain; no third-party scripts or trackers run on this site. | Not applicable — nothing is collected. | Not applicable. | The theme preference stays on your device until you clear your browser storage. |
| Operational logs | Standard server logs kept by our hosting provider: requested URL, timestamps, and error messages. Request bodies, tool arguments, and tool results are never written to logs. | To run, secure, and troubleshoot the Service. | Legitimate interests, Art. 6(1)(f) — security and availability. | Short-lived; retained by our hosting provider on a rolling basis and not archived by us. |
| Support correspondence | Your email address and whatever you write to us. | To answer your question and keep a record of the issue. | Contract / legitimate interests, Art. 6(1)(b) and (f). | Up to 24 months after the request is closed. |
4. What the app’s tools take in, and what they return
Phenomen ETFs US exposes a set of tools to your AI assistant over the Model Context Protocol. This is what each group does with data.
Market-data tools (the majority)
Screening, recommendations, universe listings, fundamentals, suitability and technical scores, end-of-day price history, candlestick charts, and single-ETF analysis, plus the widgets that display them.
- Input: a US ETF ticker symbol, or filter criteria such as asset class, region, assets under management, average dollar volume, expense ratio, and which universe to search.
- Output: ETF market and reference data from our own database.
- What we store: nothing. These inputs are not saved and are not attached to your account. Only the fact that the tool ran is recorded, in the minimal telemetry form described above.
Portfolio and watchlist tools (read)
Four tools return your saved data — your positions, your watchlist, and the two interactive managers that display them. They take no search input and return only rows belonging to your own authenticated account. Using them creates or updates your account record (identifier and email) if it does not exist yet.
Portfolio and watchlist tools (write and delete)
Four tools change stored data, and they can only be triggered by you clicking inside the app’s widgets — the AI model cannot call them on its own:
- Save a position — stores ticker symbol, start date, number of shares, and optional average entry price, allocation percentage, and long/short direction.
- Delete a position — removes that position permanently.
- Save a watchlist item — stores ticker symbol, start date, and your optional free-text note, verbatim.
- Delete a watchlist item — removes that item permanently.
Your conversation with the assistant
What you type in ChatGPT or Claude, and the results our tools return, pass through that assistant’s systems and are handled under OpenAI’s or Anthropic’s privacy policy. We receive only the specific tool inputs listed above — not your wider conversation.
Preferences stored in your browser
The widgets remember display preferences — theme, sort order, visible columns, row density, page size, chart timeframe — in your browser’s local storage under keys beginning etf-us:. These stay on your device and are never transmitted to us. Clearing your browser storage resets them.
5. What we never collect
- Brokerage credentials, account numbers, or trading authority. The Service is read-only, has no link to any broker, and cannot place a trade or move money.
- Payment card or bank details. The Service is free; we take no payments and operate no checkout.
- The arguments or results of your tool calls, and no record that could reconstruct what you were looking at.
- Your IP address or device fingerprint in usage telemetry.
- Special categories of data (health, biometrics, political or religious views, and similar). Please do not put such information in a watchlist note.
We do not sell or share your personal data, we do not run advertising or ad-tech, we do not build behavioural profiles, and we do not use your data to train AI models.
6. Who receives your data
We use a small number of service providers, each bound by contract to process data only on our instructions and only to deliver their service to us.
| Recipient | Role | What it receives |
|---|---|---|
| WorkOS, Inc. | Authentication and login | Your email address, user identifier, and login events. |
| Neon, Inc. | Managed PostgreSQL database | Hosts all stored data described in section 3: account identity, positions, watchlist items, and telemetry. |
| Railway Corp. | Application hosting | Processes requests in memory and keeps standard operational logs. |
| EODHD | Market-data vendor | No personal data, ever. Our nightly pipeline requests prices and fundamentals for a fixed list of ETF symbols. Your positions, watchlist, queries, and identity are never sent. |
| OpenAI, Anthropic | The AI assistants you connect from | Your prompts and our tool results transit the assistant you chose, under that provider’s privacy policy. |
We may also disclose data to professional advisers, or to authorities where we are legally required to, and to a successor entity in the event of a merger, acquisition, or sale of assets — in which case this Policy continues to apply until you are told otherwise.
7. International transfers
We are established in Israel, and our service providers process data on servers in the United States and the European Union. Israel is recognised by the European Commission as providing an adequate level of protection for personal data, so transfers from the European Economic Area and the United Kingdom to us do not require additional safeguards. Where data is transferred to a provider outside the EEA or the UK, the transfer relies on an adequacy decision or on the European Commission’s Standard Contractual Clauses, together with the safeguards that provider applies. You can ask us for details at contact@lobix.ai.
8. How long we keep things — summary
- Usage telemetry: deleted automatically 90 days after it is recorded.
- Positions and watchlist items: until you delete them, or until your account is deleted.
- Account identity: for the life of your account; erased within 30 days of a deletion request.
- Support email: up to 24 months after the request is closed.
9. Your rights and controls
Things you can do yourself, right now
- Edit or delete any saved position or watchlist item at any time from the positions manager or watchlist manager widget inside your assistant. Deletion is immediate and permanent.
- Cut off the app’s access to your account by disconnecting Phenomen ETFs US in your assistant’s settings (ChatGPT: Settings → Connectors/Apps; Claude: Settings → Connectors). This revokes the authorisation instantly. Data you already saved stays until you delete it or ask us to.
Rights under the GDPR and UK GDPR
If you are in the EEA or UK you have the right to access your data, to have it corrected, to have it erased, to restrict or object to processing based on our legitimate interests, to receive your data in a portable machine-readable form, and to withdraw consent where processing relies on it. To exercise any of these, email contact@lobix.ai from the address on your account. We verify requests against that address and respond within 30 days, free of charge. You also have the right to lodge a complaint with your local data protection supervisory authority.
Rights under the CCPA/CPRA (California)
In the past 12 months we have collected the following categories of personal information: identifiers (email address, account identifier), internet or other electronic network activity (the minimal usage telemetry described above), and user-provided content (positions and watchlist notes). Each is collected for the business purposes stated in section 3 and disclosed only to the service providers named in section 6.
We do not sell personal information and we do not share it for cross-context behavioural advertising, and we have not done so in the preceding 12 months. We do not knowingly sell or share the personal information of anyone under 16. You have the right to know, delete, and correct your personal information, to opt out of sale or sharing (nothing to opt out of here), and not to be discriminated against for exercising these rights. Requests, including by an authorised agent, go to contact@lobix.ai.
10. Security
- All traffic to this website and to the MCP server is encrypted with HTTPS/TLS.
- Authentication uses OAuth 2.0 / OpenID Connect via WorkOS; access tokens are scoped to this app and expire.
- Database access is restricted to our application services over encrypted connections; each tool reads and writes only the calling user’s own rows.
- There are no brokerage credentials, no payment details, and no card data in our systems to lose.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authority as required by law.
11. Children
The Service is intended for adults and is not directed to anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us data, email contact@lobix.ai and we will delete it.
12. Automated decision-making
Our suitability and technical scores are computed from published market data about ETFs, not from your personal data, and they are informational only. We do not carry out automated decision-making that produces legal or similarly significant effects for you, and nothing the Service produces is investment advice — see our Investment Disclaimer.
13. Changes to this Policy
If we change how we handle personal data, we will update this page and move the “Last updated” date above. For material changes we will also notify you by email or in the Service before the change takes effect.
14. Contact
Privacy questions, access requests, and deletion requests: contact@lobix.ai, or write to Lobix.AI Ltd, Tel Aviv, Israel.