Privacy Policy
Last updated: September 20, 2026
1. Data Controller
The data controller responsible for data processing on this website is:
AI Momentum LLC
30 N Gould St Ste R
Sheridan, WY 82801, USA
Email: terminal@cashflowengine.io
Represented by: Thomas Mehlitz
2. General Information
We take the protection of your personal data seriously. We process personal data collected during your visit to our website in compliance with the General Data Protection Regulation (GDPR) and applicable national data protection laws.
3. Legal Basis for Processing
We process personal data based on the following legal grounds:
a) Your consent (Art. 6(1)(a) GDPR)
b) Performance of a contract (Art. 6(1)(b) GDPR)
c) Legal obligations (Art. 6(1)(c) GDPR)
d) Legitimate interests (Art. 6(1)(f) GDPR)
4. SSL/TLS Encryption
This website uses SSL/TLS encryption for security purposes and to protect the transmission of confidential content.
5. Hosting
This website is hosted by Vercel Inc.; the Cashflow Engine App is hosted by Railway Corp. with Supabase Inc. as database provider. Since 20 September 2026, the database and the application API are operated in the United States (Northern Virginia); this website is served from both US and EU locations. All three providers are US companies certified under the EU-US Data Privacy Framework, which is the transfer mechanism for the processing of personal data in the United States described here.
The Cashflow Engine Workbench (wb.cashflowengine.io) and its API (api.cashflowengine.io) use the same infrastructure (Vercel frontend, Railway API, Supabase) plus the additional services listed in section 9 (“Workbench”).
6. Cookies & Consent
Our website uses cookies. Analytics cookies (specifically PostHog) are only set after your explicit consent via our cookie consent banner (opt-in). Without your consent, no tracking takes place.
You can revoke your consent at any time by clearing your browser cookies. The consent banner will reappear on your next visit.
7. Analytics
PostHog (EU Cloud). We use PostHog to understand how the site is used. Data is processed on PostHog’s EU infrastructure (Frankfurt, Germany).
If you are in the EEA, PostHog is only activated after your consent via our cookie banner — without your opt-in, no analytics data is collected. Legal basis: Art. 6(1)(a) GDPR (consent).
Outside the EEA, analytics is active by default and you can switch it off at any time via the cookie banner or the privacy settings. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in understanding and improving how the site is used).
Session recording. PostHog also records anonymised session replays (page navigation and clicks) to help us find usability problems. Replays are masked: all text and form input is obscured before it leaves your browser, so no figures, names or entries are legible — we see layout and interaction, not content. Recording follows the same consent rule as the rest of PostHog.
Vercel Web Analytics. We also use Vercel Web Analytics for aggregate visitor counts. It is cookieless, sets no identifier on your device and does not track you across websites; it records only the page requested, the referring page and coarse technical data, which cannot be used to identify you.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in measuring reach and operating the website reliably).
8. Email
We send email to customers — both service messages and occasional updates about the product — to people who hold an account with us.
Newsletter. You can subscribe to our newsletter with the form on our homepage. We collect your first name, your email address, and the time you gave consent.
Double opt-in. After you submit the form, we email you a confirmation link. You’re only subscribed once you open that link and press “Confirm my subscription”. The link expires after 48 hours. Signups that are never confirmed are deleted after 30 days.
Spam protection. To block automated signups, the form uses Cloudflare Turnstile (Cloudflare, Inc., USA), which checks your browser and IP address. We also count signup attempts per IP address and per email address to limit abuse. These counters are stored in our own database (Supabase), contain only a scrambled (hashed) form of your IP and email address, and expire automatically within 24 hours.
Processors. Supabase Inc. stores your signup record. Resend (Plus Five Five, Inc.) sends the confirmation email and the newsletter. Cloudflare provides the spam protection described above. All are based in the USA; section 10 explains how these transfers are safeguarded.
Legal basis. Your consent (Art. 6(1)(a) GDPR) for the newsletter itself. Our legitimate interest in keeping the form free of abuse (Art. 6(1)(f) GDPR) for the spam protection.
Unsubscribe and deletion. Every newsletter contains an unsubscribe link, and you can withdraw your consent at any time. Withdrawing doesn’t affect the lawfulness of anything we did before. To have your signup record deleted completely, contact us at the address in section 1.
Delivery of customer email (account and service messages, and the newsletter once confirmed) is handled by Resend (Plus Five Five, Inc.), USA.
Open and click measurement. Our emails contain a small invisible image that tells us an email was opened, and the links in them are routed through Resend so that we can see which links were followed. We use this to understand which content is useful — for example whether a video or a tool link gets read. We do not store the IP address or device details that this measurement would otherwise produce; they are discarded on receipt.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in measuring whether our own emails are read and useful).
You can unsubscribe at any time via the unsubscribe link in each email, which also ends this measurement. If you would like us to stop measuring but keep sending, write to us and we will do that.
9. Cashflow Engine Workbench (wb.cashflowengine.io)
The Cashflow Engine Workbench is our paid analysis and portfolio tool. In addition to the hosting providers above, we use the following processors to operate it. For users in the EEA, non-essential services (analytics, marketing, session replay) are activated only after consent.
Subscription & payments (Stripe)
We sell the Workbench subscription directly and use Stripe, LLC (USA) as our payment processor. Stripe processes name, email, and payment/invoice data on our behalf to take payment and to prevent payment fraud. The invoice is issued by Cashflow Engine. Stripe, LLC is self-certified under the EU-US Data Privacy Framework (see section 10). Legal basis: Art. 6(1)(b) GDPR (contract).
Product & funnel analytics (PostHog)
We use PostHog (EU Cloud, Frankfurt) to analyse product usage via pseudonymous usage events. For EEA users, PostHog is initialised only after consent. Legal basis: Art. 6(1)(a) GDPR (consent).
Error & performance monitoring (Sentry)
We capture technical error and performance data with Sentry (EU region). Personal identifiers (tokens, emails, trade and portfolio details) are stripped before transmission. Any session replay is enabled only after consent. Legal basis: Art. 6(1)(f) GDPR (legitimate interest) or (a) for session replay.
Conversion tracking (Google Ads, Meta)
For ad campaigns we measure conversions server-side via Google Ads and the Meta Conversions API. Only pseudonymous event data required for attribution is transmitted; for EEA users only with marketing consent (Google Consent Mode). Legal basis: Art. 6(1)(a) GDPR (consent).
Broker account connection
Direct broker connections and trading execution are currently used only by the operator for his own accounts and are not enabled for customers. Authorization takes place directly with the broker. AI Momentum LLC stores encrypted OAuth tokens under its own broker application registration, together with connection metadata and the account, position and order data processed for that connection.
OAuth tokens authorize access to the brokerage account; they are distinct from the password used to sign in with the broker. We request no withdrawal, transfer or other money-movement permissions. The former account-aggregation integration is retired.
Affiliate links (Option Omega, OptionsApp)
The Workbench links to Option Omega (validation) and OptionsApp (execution) and may earn a commission. Data is transferred to these providers only once you actively open a link or trigger an export; their own privacy notices then apply.
10. Third-Country Transfers & Third-Party Data Processors
Some of the providers we use are established outside the EU. The legal framework applicable to each provider — for example the EU-US Data Privacy Framework (DPF) — is stated in the “Framework” column below. Our payment processor Stripe, LLC (USA) is self-certified under the DPF and receives personal data originating from the EEA, the UK, or Switzerland on that basis; where the certification does not apply, Stripe’s EU Standard Contractual Clauses (or the UK IDTA) apply instead.
| Service | Purpose | Location | Framework |
|---|---|---|---|
| Resend (Plus Five Five, Inc.) | Email delivery (broadcasts and transactional) including open and click measurement | USA | EU-US Data Privacy Framework |
| Vercel Inc. | Website Hosting & CDN, cookieless traffic measurement (Web Analytics) and performance monitoring (Speed Insights) | EU-Region (USA) | EU-US Data Privacy Framework |
| Railway Corp. | API Hosting (api.cashflowengine.io) | EU-Region (USA) | EU-US Data Privacy Framework |
| Cloudflare, Inc. (Turnstile) | Spam protection for the newsletter signup | USA | EU-US Data Privacy Framework |
| Supabase Inc. | Database & Authentication | USA | EU-US Data Privacy Framework |
| Stripe, LLC | Payment Processing (Workbench subscription) | USA | EU-US Data Privacy Framework |
| PostHog (EU Cloud) | Product & Funnel Analytics (consent only) | EU (Frankfurt) | No third-country transfer |
| Sentry (Functional Software Inc.) | Error & Performance Monitoring | EU-Region (USA) | EU-US Data Privacy Framework |
| Google Ads | Conversion Tracking, Advertising (consent only) | USA | EU-US Data Privacy Framework |
| Meta Platforms Ireland Ltd. | Conversion Tracking / CAPI, Advertising (consent only) | Irland / USA | EU-US Data Privacy Framework |
11. Your Rights
Under the GDPR, you have the following rights:
Right of access (Art. 15 GDPR)
Right to rectification (Art. 16 GDPR)
Right to erasure (Art. 17 GDPR)
Right to restriction (Art. 18 GDPR)
Right to data portability (Art. 20 GDPR)
Right to object (Art. 21 GDPR)
Right to withdraw consent (Art. 7(3) GDPR)
To exercise your rights, contact us at: terminal@cashflowengine.io
12. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates the GDPR. The competent authority depends on your place of residence.
13. Data Retention
We delete personal data as soon as the purpose for its storage no longer applies, unless statutory retention periods require otherwise. As a guide:
a) Account / master data: for the duration of the user relationship, then until statutory retention periods expire.
b) Invoice & payment data: per commercial and tax retention obligations (typically up to 10 years, § 147 AO); subscription billing is handled by us via our payment processor (Stripe).
c) Newsletter data: until you unsubscribe or withdraw consent. Confirmation links expire after 48 hours; unconfirmed signups are deleted after 30 days; spam-protection counters expire within 24 hours.
d) Analytics / tracking data (GA4, PostHog): until you withdraw consent, or per the retention settings of the respective service.
e) Server log files: typically short-term (a few days to weeks) for security purposes.
f) Contact requests: until your inquiry has been fully handled.
g) Broker connection data: access credentials and historical trade or audit records are handled separately. Disconnecting a connection does not automatically delete historical trade or audit records.
14. Minors
Our services are intended exclusively for adults (18 years and older). We do not knowingly collect personal data from minors. If we become aware that data from a minor has been provided to us without parental consent, we will delete it without undue delay.
15. Changes to This Policy
We reserve the right to update this privacy policy to reflect changes in our services or legal requirements. The current version always applies.
Engineered by Thomas Mehlitz · Cashflow Engine