1. Scope & definitions
This Privacy Policy explains how LuLu Ventures LLC ("Deep Values," "we," "us," "our") collects, uses, shares, and protects personal information when you use our websites at deepvalues.ai and app.deepvalues.ai, our mobile app, and any related services (the "Service"). It is the master policy for our consumer product; certain features link to layered notices with additional detail.
The terms below are used throughout:
- Account — the credentialed user identity you create to access the Service.
- Inputs — anything you type, speak, paste, or upload into Deep Values: tickers you research, questions you ask Buffett Lens, watchlist edits, guru follow preferences.
- Outputs — the AI-generated content we return to you: research briefings, intrinsic-value estimates, chat responses, alerts.
- Briefing — a multi-analyst AI research run on a single company.
- Sub-processor — a third-party service we use to deliver the Service (named individually in section 6).
2. Information we collect
We collect only what we need to run the Service. Three buckets:
From you
- Account — email, display name, password, optional profile fields.
- Billing — when paid plans launch, name, billing address, and the last 4 digits of your card. Full card numbers will go directly to our payment processor (a PCI-compliant third party); we never receive or store them.
- Your inputs — tickers, watchlists, guru follows, alert rules, feedback.
- Communications — emails, support tickets, survey responses.
Automatically
- Usage — features visited, briefings generated, credits spent, timestamps.
- Device & network — IP, browser, OS, device identifier, city-level location.
- Analytics — Cloudflare Web Analytics (cookieless, no fingerprinting). Cookie details in section 7.
From third parties
- Sign-in providers — email + identifier from Google or Apple if you use SSO.
- Public sources — SEC filings, transcripts, 13F holdings. Not personal data about you.
3. How we use your information
We use your information only for the purposes below. Each maps to a legal basis under GDPR/UK GDPR (contract, legitimate interest, consent, or legal obligation).
- Operate the Service — authenticate you, generate the briefings and chat responses you request, deliver alerts, sync your watchlist across devices.
- Personalize your experience — remember your follows, surface relevant briefings, tailor the in-app feed.
- Process payments — manage your subscription, apply credit packs, send receipts.
- Communicate with you — send transactional emails (receipts, security alerts), product updates you opted into, and answer your support requests.
- Improve the Service — aggregate, de-identified usage analytics so we can fix bugs and prioritize features. We do not use your Inputs or Outputs to train AI models (see section 4).
- Security & fraud prevention — detect abuse, prevent payment fraud, enforce our Terms.
- Legal compliance — comply with tax, accounting, and law-enforcement obligations.
4. AI & automated processing
Deep Values is an AI-native product. This section is the full disclosure of how AI processes your data, including the pre-use notice required under California's Automated Decision-Making Technology (ADMT) regulations and the transparency obligations of EU AI Act Article 50.
You are interacting with AI
When you generate a briefing, ask Buffett Lens a question, or receive an alert summary, you are interacting with an AI system — not a human analyst. AI-generated audio (e.g., Buffett Lens voice replies, Deep Value Shorts narration) is labeled as such in-app and includes a machine-readable marker when delivered.
What the AI does
Briefings are produced by a multi-analyst pipeline that reads SEC filings, prior earnings transcripts, and public market data, then summarizes, scores, and writes a research report. Buffett Lens answers your questions using the same pipeline plus a retrieval layer over the company's public disclosures. The AI cites its sources; you can always click through to the original filing.
We do not train AI models on your inputs
Your Inputs and Outputs are not used to train any foundation model — ours or our vendors'. We send Inputs to OpenAI and Anthropic under their API / enterprise no-training contractual terms, which prohibit them from using customer content for model improvement. We periodically verify these terms remain in force.
Human review
We do not routinely read your prompts or chats. A small engineering and trust-and-safety team may review specific Inputs only when (a) you explicitly send them to us as feedback or a bug report, (b) abuse-detection systems flag potential misuse, or (c) we are compelled by valid legal process. Any human review is logged and access-restricted.
This is research, not investment advice
AI Briefings are factual research and educational analysis. They are not personalized investment recommendations, brokerage advice, or fiduciary guidance. Deep Values is not a registered investment adviser. You are responsible for your own investment decisions. AI can be wrong or out-of-date — always confirm against the original sources we cite.
Your right to opt out of automated processing
Because the Service is an AI research product, the AI is what you're paying for — there isn't a useful non-AI version. But you do have the following granular controls in Settings:
- Disable Buffett Lens entirely (no voice or text chat).
- Turn off personalized recommendations (your feed becomes a flat reverse-chronological list).
- Turn off email alerts (transactional only).
- Request human-readable disclosure of the logic behind any AI Output by emailing team@deepvalues.ai with the briefing ID. California residents have a statutory right to this; we extend it to everyone.
5. Buffett Lens voice data
Buffett Lens is a voice-and-text conversational interface. Because voice data is sensitive — and may be classified as a biometric identifier under laws like Illinois BIPA and Texas CUBI — we apply additional safeguards.
- Capture & consent — your device microphone is only activated when you tap the Lens record button. We do not background-listen.
- Transcription — audio is streamed to Microsoft Azure Speech Services for real-time transcription. We proxy the stream through our servers but never write the audio to our own storage; Azure processes the audio in real time and does not retain it.
- Retention — neither we nor Microsoft Azure store the raw audio after transcription completes. Only the text transcript is kept, and only as part of your conversation history; deleting a conversation removes the transcript.
- No biometric profile — we do not build voice fingerprints, do not perform voice ID, and do not use audio for any purpose other than answering your question.
- No model training — voice data is never used to train speech or language models, ours or our vendors'.
- Opt-out — toggle "Disable Buffett Lens" in Settings to prevent any future audio capture.
6. How we share information / sub-processors
We share information only with vetted vendors that help us run the Service. Each is contractually required to protect your data and use it only for the purposes we authorize. We do not sell personal data.
| Sub-processor | What it handles | Where |
|---|---|---|
| Amazon Web Services (AWS) | Hosting, DynamoDB database, encrypted storage, backups | US |
| AWS Cognito | Account authentication, password hashing, session tokens | US |
| OpenAI | LLM inference for briefings & Buffett Lens text chat (under no-training enterprise terms) | US |
| Anthropic | LLM inference for briefings & Buffett Lens text chat (under no-training API terms); used as an alternative or complement to OpenAI | US |
| Microsoft Azure (Speech Services) | Real-time speech-to-text transcription for Buffett Lens voice; we proxy the audio stream and never write it to our own storage | US |
| Cloudflare | CDN, DDoS protection, cookieless web analytics | Global edge |
| Google Workspace | In-app transactional email delivery (account, billing, alerts) via SMTP | US |
| EmailJS | Newsletter signup processing on the marketing site | US |
We may also disclose information when required to do so by law, valid legal process, or to protect the rights, safety, or property of Deep Values, our users, or the public. If we are ever involved in a merger, acquisition, or asset sale, your information may transfer as part of that transaction — we will notify you in advance.
7. Cookies, analytics & tracking
- Essential cookies — keep you signed in, remember your language preference, and prevent CSRF attacks. Cannot be disabled without breaking the Service.
- Analytics — Cloudflare Web Analytics. Cookieless, no fingerprinting, no cross-site tracking, aggregated by day.
- No advertising trackers — we do not use Google Analytics, Facebook Pixel, TikTok Pixel, or any ad-network tracker. We do not retarget you elsewhere on the web.
8. Your rights & choices
Regardless of where you live, you can:
- Access the personal data we hold about you.
- Correct inaccurate data from Settings → Profile.
- Export your account data as JSON from Settings → Privacy.
- Delete your account from Settings → Delete account. Deletion is permanent and propagates to backups within 90 days.
- Opt out of email via the unsubscribe link in any non-transactional email.
- Withdraw consent at any time where processing is based on consent.
To exercise rights that require a manual step, email team@deepvalues.ai. The team reads every request and replies as soon as possible. You will not be retaliated against for exercising a privacy right.
9. Data retention
- Account data — kept while your account is active; deleted within 30 days of account deletion.
- Briefings & chat history — kept until you delete them, or indefinitely if you keep them.
- Buffett Lens raw audio — not stored on our servers. Streamed to Microsoft Azure for real-time transcription; Azure does not retain the audio after the transcription completes.
- Billing records — retained for 7 years to comply with US tax and accounting law.
- Backups — encrypted snapshots are retained for up to 90 days, then overwritten.
- Aggregated analytics — kept indefinitely in de-identified form.
10. Security
- TLS 1.3 in transit; AES-256 at rest for stored data and backups.
- Passwords stored only as salted hashes (Cognito-managed).
- Principle of least privilege; production access requires hardware MFA and is logged.
- Quarterly access reviews and annual third-party security review.
- Incident response: if a breach affects your data, we will notify you within 72 hours of confirmation, in line with GDPR Article 33 timelines.
No system is perfectly secure. You can help by using a strong, unique password and enabling two-factor authentication from Settings → Security.
11. International data transfers
Deep Values is based in the United States and our primary infrastructure is hosted in the US. If you access the Service from outside the US, your information will be transferred to and processed in the US.
For transfers out of the EEA, UK, and Switzerland, we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum where required. We complete a Transfer Impact Assessment when onboarding new sub-processors.
12. Regional disclosures
California (CCPA / CPRA)
You have the right to know what personal information we collect, the right to request deletion or correction, the right to opt out of "sale" or "sharing" (we do neither), and the right to limit use of sensitive personal information. You also have a pre-use right to know when Automated Decision-Making Technology (ADMT) significantly affects you — sections 4 and 5 above are that disclosure for our AI briefings and Buffett Lens. To submit a request, email team@deepvalues.ai with the subject "California Privacy Request."
Other US states
Residents of Colorado, Connecticut, Virginia, Texas, Utah, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Rhode Island, Indiana, Kentucky, and Tennessee have access, correction, deletion, portability, and opt-out rights similar to California's. The same email address handles those requests.
EEA, UK, and Switzerland (GDPR / UK GDPR / FADP)
Our legal bases are: (a) contract for delivering the Service, (b) legitimate interest for security, fraud prevention, and product analytics, (c) consent for optional features like marketing emails, and (d) legal obligation for tax and accounting. You have the rights of access, rectification, erasure, restriction, portability, objection, and to lodge a complaint with your supervisory authority. Contact us at team@deepvalues.ai; we will appoint an EU Representative under Article 27 once we reach the relevant threshold.
13. Minimum age
Investing literacy starts young, and we want Deep Values to be useful to anyone who can read a 10-K. So we set our age floors at the lowest level the law allows for each feature, rather than blanket-banning anyone under 18.
- Reading and the free Basic plan — open to anyone 13 or older (16 or older in the EEA and UK, per GDPR-K). Build a watchlist, run free briefings, browse Smart Money — all fine.
- Paid plans (Plus, Pro, API) and Buffett Lens voice — limited to users 18 or older. This isn't about content; it's about contract capacity. In nearly every US state, minors can't enter into a binding subscription contract on their own, and most payment processors require account holders to be 18+. Voice data from minors also carries extra-sensitive treatment under several state laws.
- Under 13 — we do not knowingly collect personal information from children under 13 (in compliance with COPPA). If you are under 13, please do not create an account or send us personal information.
If a parent or guardian believes a child under 13 has provided personal information to us, please email team@deepvalues.ai with the subject "Child data deletion" and we will remove it promptly.
We're working on a custodial/family-account flow so a parent can pay on behalf of a teen who wants the full feature set. Until then, parents are welcome to share their own paid account with a teen learner.
14. Changes & contact
We may update this Privacy Policy to reflect changes in the Service, our practices, or the law. When we make material changes, we will notify you by email (to the address on your account) and post a notice in-app at least 14 days before the change takes effect. The "Effective" date at the top tells you when the current version went live; you can subscribe to change notifications at deepvalues.ai/privacy/changes.
For any privacy question, request, or complaint:
- Email: team@deepvalues.ai
The team reads every privacy request and replies as soon as possible.
Last reviewed: May 17, 2026 · Version 1.0