BOOSTWINRATE/ Security

Security and privacy

FIT analyzes public company information and, for signed-in users, the deals and matrices you create. This page explains what we store, where it lives, who can see it, and how to get rid of it. Written plainly, because you should not need a lawyer to understand it.

What we store

Public research. Company websites, SEC filings, earnings call material and news that FIT pulls to build buyer and vendor profiles. This is public information and we cache it so repeat runs are fast.

Your workspace content. Deals you create, the matrices FIT generates for them, and documents you choose to upload. This belongs to your workspace and is visible only to its members, and a deal marked private is visible only to the person who created it.

Your documents stay in your workspace

Documents you upload are visible only to members of your workspace. They are never used to improve results for anyone else, and they never feed the shared cache of public company research; that cache holds public-source material only. If you turn on cross-deal analysis, FIT looks at other documents in your workspace and nowhere else. The setting is off unless you turn it on, and it is enforced on our servers, not by the checkbox alone. When document-derived evidence appears in a matrix, share-link viewers see that internal evidence exists, never its contents.

Your account. Your email address and sign-in activity. We do not ask for a password, so there is no password to lose.

Usage events. We record operational events (a deal was created, a document was uploaded, when, and by which account) to run and support the service. These events do not include your documents or your matrix contents.

Sign-in

We use sign-in links instead of passwords. You enter your email and we send you a link plus a short code. Use either one. Both expire after 30 minutes and work once. Requesting a new link cancels any older ones.

Sharing

You can create a read-only link to a specific matrix so someone can view it without an account. That link shows the matrix and its underlying evidence, nothing else. You can revoke it at any time, and you can see how many times it has been opened. Shared pages are excluded from search engines.

AI processing

FIT uses Anthropic's Claude API to analyze content. Under Anthropic's commercial terms, content sent through the API is not used to train their models. We do not send your content to any other AI provider. Every score and claim FIT produces is traceable to a source; when the evidence is not there, FIT says so rather than filling the gap.

Deletion

Delete a document and we remove the file, the text we extracted from it, and anything derived from it. Delete a deal and everything attached to it goes with it: matrices, evidence, documents, and share links. Ask us to delete your workspace and we delete all of it. These are real deletions, not hidden flags.

Retention

Public research caches are refreshed periodically and are not tied to you. Workspace content stays until you delete it or close your account.

Where your data lives

Data is stored in the United States with Vercel and Supabase. Everything is encrypted in transit and at rest.

Who we share it with

We do not sell data and we do not share it with advertisers. We use a small number of service providers to run FIT: Vercel for application hosting, Supabase for the database and document storage, Upstash for caching, Anthropic for AI analysis, and Resend for sign-in and notification emails. That is the complete list.

Questions or a problem to report

and we will confirm receipt within one business day.

Last updated: August 5, 2026