Privacy Policy

InvestJournal MCP Server

Effective Date: May 7, 2026 · Last Updated: September 8, 2026


1. Introduction

InvestJournal ("we", "our", "us") operates an MCP (Model Context Protocol) server that allows AI assistants like Claude to access your stock research data. This privacy policy explains what data is accessed, how it is used, and your rights.

2. Data We Access

When you connect to the InvestJournal MCP server, the following data from your InvestJournal account may be accessed by the AI assistant on your behalf:

Data TypeReadWriteDestructiveTools
Stocks✓ (admin only)✓ (admin only)GetStockSummary, ListStocks, SearchStocks, ScreenStocks, AddStock, AddStockListing, EditStock, DeleteStock
Market prices (shared market data, not user data)GetPriceHistory, GetLatestPrice
DCF ValuationsGetDcfValuations, GetLatestDcf, CalculateDcf (stateless), SaveDcfValuation, DeleteDcfValuation, SetDcfVerdict, ScreenStocks (reads your valuations to derive upside), ListStocks, SearchStocks, GetStockSummary (count only, and only YOUR valuations — these never reveal how many other users have valued a stock)
Financial Ratios✓ (admin only)✓ (admin only)GetStockRatios, ScreenStocks, AddFinancialRatio
My Data (your own custom metrics, e.g. backlog or store count — private to your account)AddMyMetrics, GetMyMetrics, DeleteMyMetric, and the yourMetrics section of GetStockRatios
Your list (your own Morning Desk checklist — private to your account; checking a stock-attached task off can also write a private note on that stock, per your journal-line preference)ListMyTasks, AddMyTask, CompleteMyTask, EditMyTask, ReorderMyTasks, DeleteMyTask
News (press releases)✓ (admin only)✓ (admin only)ListNews, AddNewsItem, EditNewsItem, DeleteNewsItem, ReportNewsDigest
Earnings calendar (per-stock reporting dates, every one taken from a company's own press release — no estimated or predicted dates are stored or served; the calendar read may include the first sentence of your own thesis, and the per-company reads are scoped to the companies you hold or watch)✓ (admin only)GetEarningsCalendar, GetStockSummary, GetWatchlistStocks, GetWatchlistRatioRanking, ListNews, MarkEarningsEvent
Ratio refresh queue (which tracked companies reported after their numbers were last imported; derived from ratios and earnings events, plus whether any user holds or watches the stock — never who)✓ (admin only)ListRefreshDue, ReportRefreshQueue
WatchlistsListWatchlists, GetWatchlistStocks, GetWatchlistRatioRanking, GetWatchlistStocksWithLatestRatios, AddStockToWatchlist, RemoveStockFromWatchlist, CreateWatchlist, ArchiveWatchlist, RenameWatchlist, SetWatchlistFavorite
Comments / NotesGetStockComments, SearchComments, AddStockComment, EditStockComment, SetCommentPrivacy, DeleteStockComment
Investment ThesesGetThesis, UpsertThesis (replaces the current thesis text; prior versions are kept as revision history)
AlertsListAlerts, CreateAlert, UpdateAlert, SetAlertEnabled, DeleteAlert
Portfolio holdings (up to five named portfolios per user, each with its own accounts, transactions and cash balances; positions are computed from the transactions, never stored — cash balances are stored directly as the latest assertion, never a ledger; each account may also carry a user-asserted tax treatment — Tax-free, Tax-deferred or Taxable — which is never inferred or verified, only what the user states; accounts and portfolios are archived, never deleted; each portfolio's figures are never combined with another's)ListPortfolios, ListHoldings, ListPortfolioTransactions, SharesHeldOn, AddPortfolioTransaction, SetOpeningPositions, EditPortfolioTransaction, DeletePortfolioTransaction, SetCashBalance, ListAccounts, CreateAccount, RenameAccount, ArchiveAccount, CreatePortfolio, RenamePortfolio
Documents (PDF metadata + RAG)ListDocuments, AskDocument
OAuth sessions & account identityWhoAmI (email, user ID, admin status of the signed-in account), LogoutFromMcp

Tools that modify your data (watchlists, DCF valuations, comments, investment theses, alerts, ratios, news, custom metrics, desk checklist tasks, portfolio transactions) are explicitly marked as such in the MCP tool catalog (destructiveHint: true for delete/replace; readOnlyHint: false for additive create). Your AI assistant will surface these distinctions when proposing actions. AddFinancialRatio, AddNewsItem, EditNewsItem, DeleteNewsItem, AddStock, AddStockListing, EditStock, DeleteStock, ReportNewsDigest, MarkEarningsEvent, ListRefreshDue, and ReportRefreshQueue are admin-only and reject calls from non-admin users.

3. Third-Party Services

The InvestJournal MCP server calls the following third-party APIs:

No other third-party services receive your data through the MCP server.

4. Data Storage

5. Data Retention

Your data is retained as long as your InvestJournal account is active. If you delete your account, all associated data (stocks, valuations, watchlists, comments, investment theses, alerts, custom metrics, checklist tasks, documents, and embeddings) will be deleted.

OAuth refresh tokens issued to your AI client are retained for up to 30 days from issuance, with rotation on each use. You can revoke active sessions at any time via https://mcp.investjournal.io/sessions or by calling the LogoutFromMcp tool.

6. Data Sharing

We do not sell, trade, or share your personal data with third parties, except:

7. Security

8. Your Rights

You have the right to:

9. Changes to This Policy

We may update this privacy policy from time to time. Changes will be reflected by updating the "Last Updated" date at the top of this document.

10. Contact

If you have questions about this privacy policy, please contact us at: