Privacy & Cookie Policy
Last updated: September 2026
AuraCenzo Holdings LLC d/b/a CaptureDiv
This single document covers both privacy and what is stored on your device. It replaces the separate Privacy Policy and Cookie Policy, which described the same things in two places and disagreed in one of them. The old cookie-policy address still works and brings you here.
1. Who we are, and who this is for
CaptureDiv is operated by AuraCenzo Holdings LLC. It is a research and analysis tool for dividend investors. It is not a broker, it does not hold money or securities, it does not connect to your brokerage accounts, and it does not give investment advice.
Intended market: CaptureDiv™ is designed for US-based investors. Our data covers US-listed securities, pricing is in US dollars, and nothing here is tailored to non-US tax treatment, regulation, or market structure. We do not market the service outside the United States.
2. What we collect
We collect three kinds of information.
- What you give us. Your email address, your display name, and the holdings you enter into your portfolio.
- What your use of the service produces. Which features you used and how often, including counts of AI requests measured against your plan's limits.
- What arrives with any web request. Your IP address and basic device and browser information.
We do not collect brokerage credentials, account numbers, or card details, and there is nowhere in the product to enter them.
3. Why we use it
Each thing we collect is used for a stated purpose, and for nothing else.
- To run the service you signed up for — we use your holdings to produce your analysis, keep you signed in, and take payment.
- To keep the service working and secure — diagnosing faults, preventing abuse, and measuring use against your plan's limits.
- To send you email you asked for — the Weekly Briefand any other notification you switch on. You can turn each one off, and unsubscribing stops the mail without affecting your account.
- To keep the records the law requires — tax and financial records arising from payments.
We do not sell personal information, we do not share it for advertising, and we run no advertising or behavioural profiling of any kind.
4. What is stored on your device
Nothing is stored on your device until you act. Loading a public page — the home page, pricing, a stock page, these policies, the sign-in page — sets no cookies and writes nothing to browser storage. Everything described below is written only when you sign in or change a setting.
Your sign-in session. When you sign in, the token that keeps you signed in is held on your own device, in this site's browser storage rather than in a cookie, so blocking cookies does not stop you signing in. Clearing this site's data in your browser removes it, and you will be signed out. It lasts until you sign out or the session expires.
One cookie. A single first-party cookie records whether you collapsed the app sidebar, so the layout you chose survives a reload; it is set only when you toggle the sidebar, lasts seven days, carries no identifier, and is not read by anyone else.
Your interface preferences. A small set of choices is kept in browser storage so you do not have to make them again: your income goal in Income Lab™, how far you have read in the Education Hub, which checklist items you ticked while planning a trade, and which one-off notices you have dismissed. Some dismissals last only until you close the tab. None of these identify you, none of them leave your device, and clearing your browser data for this site removes all of them.
What is not on your device. Your holdings, your account details and market data we have fetched are held in our systems, not in your browser (see sections 5 and 8). No market or filing data is cached on your device.
You can clear all of the above through your browser's settings for clearing site data. There is nothing here to switch off selectively, because none of it is optional or used for tracking — everything listed is required either to keep you signed in or to remember a choice you made.
5. Your portfolio data
The holdings you enter are used to give you personalised analysis, income projections and the alerts you have switched on. They are stored against your account in our database and are visible to you.
We do not sell your portfolio data, we do not share it with other users, and we do not use it to build any profile of you beyond the analysis you are shown. Where producing your analysis requires sending portfolio content to a provider, that provider is named in section 8.
6. AI analysis, and what is shared between users
Some AI-written text is generated once and shown to every reader rather than to you alone. The coaching note for a ticker is stored against that ticker, and the daily opportunities summary is stored against that date. When you open either, you may be reading text produced by another reader's request, and text your request produces may later be shown to someone else.
What can be shared is limited by what those stores are keyed to — a company or a calendar day. They contain no holdings, no position sizes, no email address and nothing identifying the account whose request produced them.
Text that is about you — your portfolio review, earnings reviews, your outlook and your chat history — is stored against your account, is never shown to another user, and is removed when you delete your account.
7. Automated processing and CaptureGrade™
CaptureGrade™ is produced by a fixed set of arithmetic rules applied to figures a company has filed. It is not produced by an AI model, it takes no account of who is reading it, and the same company produces the same grade for every user.
The grade is a statement about a security, not about a person. No grade, score or automated inference is used to decide anything about you: what you can access is determined by your subscription status, or by a manual administrative action, and by nothing else.
The AI-written text described in section 6 is descriptive. Nothing in the product reads that text and changes what you are entitled to as a result.
Because of this, we carry out no automated decision-making that produces legal effects or similarly significant effects for you. Nothing on the site is investment advice, and every grade and projection is a research output for you to judge.
8. Who else processes your data
We use a small number of providers, each for a stated purpose, and each may use what it receives only to provide that service to us. Every provider that receives account or portfolio content — our hosting, database and authentication provider, Anthropic, Stripe and Resend — is covered by that provider's data processing terms, which take effect on our acceptance of its terms of service. Our network provider, Cloudflare, offers such terms on separate signature and we have not yet completed that step; it carries traffic to and from the site and stores no account content. One further recipient exists only if you sign in with Google: the platform we build and run this service on, Lovable, operates that sign-in broker and receives the identity Google returns — your name, email address and profile picture — and no portfolio content passes through it. Lovable publishes data processing terms but includes them only with its Business and Enterprise plans; we are not on such a plan, so those terms do not currently apply to it, as is also the case for Cloudflare above.
- Our hosting, database and authentication provider — runs the application and stores your account, portfolio and analysis. It issues the sign-in session described in section 4.
- Lovable — the platform this service is built and run on, and the operator of the sign-in broker used when you choose “Continue with Google”. If you use that option, Google’s consent screen names Lovable rather than us, because the Google application registration belongs to the platform; the browser is sent to Lovable’s broker, which receives Google’s response for your name, email address and profile picture and exchanges it for the sign-in session issued by our authentication provider. Signing in with an email address and password does not involve Google or that broker.
- Anthropic — produces the AI-written analysis. Where your request concerns your own portfolio, the tickers and position details in that request are sent as part of it.
- Stripe — processes payments (see section 9).
- Resend — delivers email. Messages we send you, including the Weekly Brief, contain the tickers and position details from your portfolio, so their content passes through Resend in order to be delivered.
- Financial Data (financialdata.net) — supplies dividend, market and filing data. It receives no information about you: we request data about a security, never about a reader.
- Cloudflare — serves the site over its network, so requests to this site pass through it.
Market and filing data we fetch is cached on our servers, keyed to the security it describes rather than to the person who looked it up, so the cache reveals nothing about who read what.
No analytics and no trackers. We run no third-party analytics, no tracking pixels and no advertising scripts. On 1 September 2026 we measured a cold page load on every class of page on this site — marketing pages, these policies, the sign-in page, public stock pages and the signed-in app — and no host outside this site's own infrastructure was contacted. Two departures exist, and both are departures rather than background requests: choosing a plan sends you to Stripe's own checkout page, where Stripe's cookie policy applies, and choosing “Continue with Google” sends you to the sign-in broker and to Google, as described above. Usage we do record is stored in our database against your account, not in your browser.
9. Payments
Payments are processed by Stripe, Inc. Card numbers are entered on Stripe's own pages and are never sent to us or stored by us. We hold the subscription status Stripe reports back, which is what determines your access.
10. Where your data is processed
Your account data — your profile, portfolio and analysis — is stored in the United States.
The providers named in section 8 are US-based or operate globally, so using the service involves your data being processed in the United States. Some of those providers include the European Commission's Standard Contractual Clauses in the terms that apply to us; we have not confirmed a transfer mechanism for every provider, and we do not claim one where we have not.
We do not market the service outside the United States, as stated in section 1. If you use it from elsewhere, this is where the processing happens.
11. How long we keep it
Your account data is kept for as long as your account exists. You can delete your account yourself at any time from Settings, under Danger Zone; you do not need to email us to do it, and nothing is held back pending review.
Deleting your account. Deletion of your data in our own systems happens while you wait, in the same request. It covers every place your account identifier, your email address, or a stored result keyed to your account appears. If any step of it fails, we stop and do not remove the account itself: you keep your sign-in, you are told the deletion did not complete and which parts did, and running it again is safe. If a step succeeds but the service writes a further row while the deletion is still running, that is recorded and cleared by a second pass in the same request. Four things behave differently, and each is stated as the longest the data can exist for:
- Payments. Your subscription is cancelled and your customer record at Stripe is deleted as part of the same request. If Stripe does not respond, your account deletion still goes ahead and the cancellation is completed separately; email us if you want confirmation. Invoices and payment records are kept for up to 7 years where tax and financial-records law requires it; that retention cannot be waived on request.
- Email suppression. If you unsubscribed or an address bounced, one record survives deletion on purpose: the address, the reason and the date. Erasing it would let a later sign-up silently re-permit mail you asked us to stop. It is used for nothing else.
- The record that the deletion ran. We keep a record of each deletion — which kinds of data were cleared, when, and whether any part of it failed — for up to 3 years. It exists so a deletion that did not fully complete can still be found and finished later. It holds no content from your account.
- Copies already sent elsewhere. Prompts already sent for AI analysis, and email already delivered, are held on those providers' own retention schedules. We cannot recall them.
Backups. Our database is backed up in encrypted form by the platform that hosts it. Deleted data can survive in those backups until they age out of that schedule. Backups are used to restore the service after a failure; they are not a second copy we read from or work with.
Records kept without you attached. Two kinds of record outlive an account in a form no longer linked to anyone. A record that an administrative action took place is kept, with the acting account removed, for up to 24 months. Engine diagnostics — failed data-quality checks and model errors — are kept for up to 180 days and refer to a stock symbol rather than to a person. Neither can be traced back to you.
Records of email we sent. For each message we send — including an invitation sent before any account exists — we keep the address it went to, which message it was, and whether the provider accepted it, for up to 400 days. It is how we can answer "I never received it". If you have an account, these records are also removed when the account is deleted, whichever comes first.
Logs about our own machinery. We keep records of our scheduled jobs — when a job ran, what it processed, whether it failed. These contain no personal information and are not linked to any account. They are kept for up to 400 days.
Each period above is the outer bound: the longest that data may exist, not a schedule on which it is removed. Data is often gone sooner.
12. Security
Rather than describe our security in general terms, we state the specific measures in place, each of which can be checked:
- All traffic between your browser and the site is encrypted in transit with TLS.
- Row-level security is enabled on every table your account can reach, so a signed-in account can only read the rows that belong to it.
- Card details never reach us: payment pages are hosted by Stripe, and no card field is ever posted through our site.
- Passwords are handled by our authentication provider, which stores them hashed; we never see or store your password.
If we discover a breach affecting your personal data, we will notify affected users promptly by email, describing what happened and what data was involved.
Security research. If you believe you have found a security vulnerability, email info@capturediv.com. We will respond within 90 days. We will not pursue legal action against anyone who reports in good faith, does not access or modify other users' data, and gives us 90 days to respond before disclosing publicly.
13. Your rights
These are offered to everyone who uses CaptureDiv, wherever you live, and most of them you can exercise yourself without asking us.
- Know what we hold. Your portfolio, profile and analysis are visible in the app, and section 2 lists every category we collect.
- Get a copy. You can export your account data from Settings.
- Correct it. Your profile and holdings are editable at any time.
- Delete it. Settings, under Danger Zone. What that removes and what outlives it is set out in section 11.
- Stop email you no longer want. Unsubscribe from any email or turn the notification off. It stops the mail and affects nothing else about your account.
- Tell us if you would rather we did not. If there is something in section 3 you do not want us doing with your data, say so and we will stop it or explain why we cannot.
- Opt out of sale or sharing. There is nothing to opt out of: we do not sell personal information and do not share it for advertising.
- Not be treated differently for exercising any of these. Nothing above changes your price or your access.
For anything you cannot do yourself, email info@capturediv.com.
14. Children
CaptureDiv is not directed to children under 18 and we do not knowingly collect information from them. If you believe a child has created an account, email us and we will remove it.
15. Changes to this policy
We may update this policy. The date at the top changes whenever it does, and we will tell you by email or with a notice in the app when a change is significant.
16. Contact
AuraCenzo Holdings LLC d/b/a CaptureDiv
info@capturediv.com
See also our Terms of Service and Disclaimer.