Privacy Policy

InvestJournal MCP Server

Effective Date: May 7, 2026 · Last Updated: July 30, 2026


1. Introduction

InvestJournal ("we", "our", "us") operates an MCP (Model Context Protocol) server that allows AI assistants like Claude to access your stock research data. This privacy policy explains what data is accessed, how it is used, and your rights.

2. Data We Access

When you connect to the InvestJournal MCP server, the following data from your InvestJournal account may be accessed by the AI assistant on your behalf:

Data TypeReadWriteDestructiveTools
Stocks✓ (admin only)✓ (admin only)GetStockSummary, ListStocks, SearchStocks, AddStock, EditStock, DeleteStock
Market prices (shared market data, not user data)GetPriceHistory, GetLatestPrice
DCF ValuationsGetDcfValuations, GetLatestDcf, CalculateDcf (stateless), SaveDcfValuation, DeleteDcfValuation, SetDcfVerdict
Financial Ratios✓ (admin only)✓ (admin only)GetStockRatios, AddFinancialRatio
My Data (your own custom metrics, e.g. backlog or store count — private to your account)AddMyMetrics, GetMyMetrics, DeleteMyMetric, and the yourMetrics section of GetStockRatios
News (press releases)✓ (admin only)✓ (admin only)ListNews, AddNewsItem, EditNewsItem, DeleteNewsItem, ReportNewsDigest
WatchlistsListWatchlists, GetWatchlistStocks, GetWatchlistRatioRanking, GetWatchlistStocksWithLatestRatios, AddStockToWatchlist, RemoveStockFromWatchlist, CreateWatchlist, ArchiveWatchlist, RenameWatchlist, SetWatchlistFavorite
Comments / NotesGetStockComments, SearchComments, AddStockComment, EditStockComment, SetCommentPrivacy, DeleteStockComment
Investment ThesesGetThesis, UpsertThesis (replaces the current thesis text; prior versions are kept as revision history)
AlertsListAlerts, CreateAlert, UpdateAlert, SetAlertEnabled, DeleteAlert
Documents (PDF metadata + RAG)ListDocuments, AskDocument
OAuth sessions & account identityWhoAmI (email, user ID, admin status of the signed-in account), LogoutFromMcp

Tools that modify your data (watchlists, DCF valuations, comments, investment theses, alerts, ratios, news, custom metrics) are explicitly marked as such in the MCP tool catalog (destructiveHint: true for delete/replace; readOnlyHint: false for additive create). Your AI assistant will surface these distinctions when proposing actions. AddFinancialRatio, AddNewsItem, EditNewsItem, DeleteNewsItem, AddStock, EditStock, DeleteStock, and ReportNewsDigest are admin-only and reject calls from non-admin users.

3. Third-Party Services

The InvestJournal MCP server calls the following third-party APIs:

No other third-party services receive your data through the MCP server.

4. Data Storage

5. Data Retention

Your data is retained as long as your InvestJournal account is active. If you delete your account, all associated data (stocks, valuations, watchlists, comments, investment theses, alerts, custom metrics, documents, and embeddings) will be deleted.

OAuth refresh tokens issued to your AI client are retained for up to 30 days from issuance, with rotation on each use. You can revoke active sessions at any time via https://mcp.investjournal.io/sessions or by calling the LogoutFromMcp tool.

6. Data Sharing

We do not sell, trade, or share your personal data with third parties, except:

7. Security

8. Your Rights

You have the right to:

9. Changes to This Policy

We may update this privacy policy from time to time. Changes will be reflected by updating the "Last Updated" date at the top of this document.

10. Contact

If you have questions about this privacy policy, please contact us at: