Legal Notice · Terms of Service · Privacy Policy · Last updated: August 2026
E-mail: api@stocklake.dev
Stocklake API is provided "as is", without warranty of any kind. The service may be modified, interrupted, or discontinued at any time without notice. The operator does not guarantee accuracy, availability, or continuity of data or service.
All data, ratings, signals, and AI-generated analysis provided through this service are for informational purposes only. Nothing here constitutes financial, investment, or trading advice. The operator is not a licensed financial advisor. Users are solely responsible for their own investment decisions. Always consult a qualified financial professional before making investment decisions.
Market data is sourced from public third-party feeds and may be delayed, incomplete, or inaccurate. The operator accepts no liability for any loss or damage arising from reliance on this data.
Much of what this service shows — research summaries, verdicts, trade signals, sentiment readouts, and similar synthesized text — is generated by AI models, not written by a human. Wherever it appears on the dashboard, a stock page, or in example output, it carries an "AI" label so it's never mistaken for human-authored analysis or editorial content.
These outputs are automated interpretations of public market data. They are not fact-checked or edited by the operator before being shown, and they can be incomplete, outdated, or wrong. Treat them the same as any other unverified, informational signal — see "Not Financial Advice" above.
This service does not use AI to interact with you directly — there is no AI chatbot or AI customer support. Any correspondence with the operator (e-mail, contact form) is handled by a human.
By using this service you agree not to:
The operator reserves the right to suspend or terminate API keys at any time, with or without cause, including for suspected abuse or policy violations.
Pro subscriptions are billed monthly via Stripe. By subscribing you authorise recurring monthly charges to your payment method until you cancel.
Free trial: Pro subscriptions include a 7-day free trial. Your card is not charged during the trial period. If you do not cancel before the trial ends, your card will be charged the monthly Pro rate on day 8 and each month thereafter.
Cancellation: You may cancel at any time via the billing portal on your account page. Access continues until the end of the current billing period. No partial-period refunds are issued for unused days after cancellation.
Refunds: Refunds are available for the most recent payment only, if requested within the same billing period. To request a refund, contact api@stocklake.dev. Refunds are granted at the operator's discretion and are not guaranteed.
The operator reserves the right to change subscription pricing with reasonable notice. Continued use after a price change constitutes acceptance of the new pricing.
To the maximum extent permitted by applicable law, the operator is not liable for any direct, indirect, incidental, or consequential damages arising from use of, or inability to use, this service — including but not limited to data loss, financial loss, or service interruption.
© 2026 Stocklake. All rights reserved. Site content and design are owned by the operator. Underlying market data remains the property of its respective third-party providers.
Account data: your e-mail address, used for API key issuance and login. No passwords are stored — sign-in is by one-time magic link. If you subscribe to Pro, we also store your Stripe customer ID, subscription ID, subscription status, and trial end date.
Usage data: a log of each API call — which tool, which symbol, response time, and any error — recorded per key and per day for rate limiting, billing, and abuse monitoring.
Site analytics: every page request — not just API calls — is logged server-side: IP address, browser/OS/device type, referrer, and country. This is processed on our own servers, used solely for our own internal analytics and abuse monitoring, and never shared with, sold to, or processed by any third party.
Member activity: while you are signed in, we record which stock pages and blog posts you open, linked to your account, so we can see which coverage is actually being used. Kept for 180 days.
Watchlist: the symbols you add to your watchlist, stored against your account so the API and dashboard can return them.
Contact messages: whatever you send us through the contact form or by e-mail, so we can reply.
Solely to operate the service — key issuance, rate limiting, subscription management, abuse prevention, and answering your messages. We do not sell your data, and we do not share it with anyone for advertising or profiling. The only third parties that ever receive any of it are the two processors named below, each for a single job.
Payments — Stripe. Payments are processed by Stripe — for customers in Europe, Stripe Payments Europe, Limited (Dublin, Ireland) — acting as our processor under Stripe's Data Processing Agreement. We never see, receive, or store your card number: card details go directly from you to Stripe's PCI-DSS Level 1 certified infrastructure. The only thing we hand Stripe is your e-mail address, so it can identify your subscription and send you receipts. From Stripe we keep your customer ID, subscription ID, subscription status, and trial end date — enough to set your account tier and open the billing portal, nothing more.
What Stripe does on its own account: Stripe also uses transaction and device data as an independent controller — for fraud detection, loss prevention, authentication, and analytics on its own services. That processing is Stripe's own, governed by Stripe's Privacy Policy, not ours. We embed no Stripe scripts and set no Stripe cookies on this site; checkout and the billing portal are pages hosted on Stripe's own domain, and any cookies there are Stripe's. Stripe's Data Processing Agreement includes the EU Standard Contractual Clauses for transfers outside the EEA.
E-mail delivery — Amazon SES. Transactional e-mails (login links, welcome messages, contact form replies) and product update e-mails are sent through Amazon Simple Email Service (Amazon SES), operated by Amazon Web Services (AWS Europe — Amazon Web Services EMEA SARL, Luxembourg) as our processor under the AWS Data Processing Addendum. We hand AWS exactly two things: your e-mail address and the message itself. Nothing else about your account, API usage, or watchlist is shared.
No open tracking: we use SES as a delivery pipe and nothing more. Our sends carry no SES configuration set and no event publishing, so SES inserts no open-tracking pixel and does not rewrite our links. Engagement metrics in AWS Virtual Deliverability Manager are switched off. There is no tracking pixel in any e-mail we send — we do not know whether you opened one, and we could not find out retroactively. The only delivery data we read back from AWS is aggregate counts (delivered, bounced, spam complaints), with no recipient addresses attached.
Link clicks in marketing e-mails: the one thing we do measure. Links in our newsletters point at a redirect on our own server, which counts the click and then sends you on to the real page. That record holds the campaign, which link was clicked, your e-mail address, and your IP; it is kept for 90 days and never leaves our own infrastructure — no e-mail marketing platform is involved. Transactional e-mails — login links, API key delivery, billing and account notices — carry no click tracking at all. You can avoid click measurement entirely by opting out of marketing e-mails (see below).
What AWS keeps: AWS does not retain the message once it has been delivered. The single exception is an address that hard-bounces or is reported as spam: it is kept on the SES suppression list so that we do not mail it again. You can have that entry removed — together with our own copy — by emailing api@stocklake.dev. E-mails are processed in the AWS US-West (Oregon) region, meaning your e-mail address is transferred to the USA for delivery. AWS is covered by Amazon.com, Inc.'s certification under the EU–U.S. Data Privacy Framework (European Commission adequacy decision of 10 July 2023), and the AWS Data Processing Addendum additionally includes the EU Standard Contractual Clauses as a fallback safeguard.
Nobody else. No advertising networks, no third-party analytics, no data brokers, no e-mail marketing platform. Site analytics and newsletter click counting both run on our own servers.
We set a single session cookie on login (HttpOnly, Secure — used only to keep you signed in to your account). No tracking cookies. No advertising cookies.
We send product updates and feature announcements to users by default (the consent checkbox at sign-in is pre-checked — uncheck it to opt out before signing in, or withdraw consent at any time from your Account Settings). Every marketing e-mail also carries a one-click unsubscribe link. Links in these e-mails are click-counted as described under Who we share it with. We never share your e-mail with third parties for marketing purposes.
Your account and API key are retained for as long as the account is active. API usage logs, site analytics, security/event logs, and newsletter click records are deleted automatically after 90 days; signed-in member activity after 180 days. Contact messages are retained for up to 12 months. You may request deletion at any time by emailing api@stocklake.dev.
Under GDPR, you have the right to access, rectify, or erase your data, restrict or object to its processing, and request data portability. To exercise any of these, email api@stocklake.dev. You also have the right to lodge a complaint with your local data protection supervisory authority at any time.
You can deactivate your account at any time via your account page. This revokes all API keys and marks your account as inactive. Your data is retained for audit purposes. To request permanent deletion of your data, email api@stocklake.dev.