Privacy Policy
Last updated 10 July 2026
This Privacy Policy explains how BlueBed.ai Pte. Ltd. (“BlueBed.ai”, “we”, “us”), a company incorporated in Singapore, collects, uses, and protects personal data when you use levelbox.ai (the “Service”). We are the data controller for that personal data. We handle it in line with Singapore’s Personal Data Protection Act (PDPA) and, where they apply to you, the EU/UK GDPR and California’s CCPA/CPRA (see the region-specific sections below).
1. What we collect
- Account data — your email address and a password, or, if you sign in with Google, the basic profile (email and name) Google shares. Authentication is handled by our processor Supabase; we do not store your raw password.
- Waitlist data — the email address you give us to join a waitlist.
- Data you create in the Service — the watchlists and symbols you save, your screening choices, and, if you choose to import a portfolio (e.g. from IBKR), the positions and figures in that import.
- Technical data — standard server logs (such as IP address, browser type, and timestamps) and information stored via cookies (see §7).
We do not intentionally collect sensitive categories of data, and we do not send your personal data to market-data providers (those receive only ticker symbols).
2. How we use it
- to create and operate your account and provide the Service;
- to run the screener and return the analysis you request;
- to communicate with you about the Service, including waitlist and account messages;
- to secure, debug, and improve the Service and prevent abuse;
- to comply with our legal obligations.
2a. Marketing & product communications
If you create an account, we may send you two optional email streams: a daily digest of screening results (“top wheeling candidates”) and a weekly note with market insights and product updates. These are sent on the basis of your account with us and, where required, your consent. You can unsubscribe from either or both at any time from your account’s profile page, or via the unsubscribe link in those emails. Turning them off does not affect essential account and security emails, which we still need to send you.
3. Legal bases (EU/UK users)
Where the GDPR applies, we rely on: performance of a contract (to provide the Service you sign up for); legitimate interests (to secure and improve the Service); consent (for non-essential cookies and optional communications, which you may withdraw at any time); and legal obligation (to meet record-keeping and regulatory duties).
4. Sharing and processors
We do not sell your personal data. We share it only with service providers that process it on our behalf under contract — notably Supabase (authentication and database hosting) and our cloud hosting provider — and with authorities where required by law, or in connection with a corporate transaction. These providers may process data on our instructions only.
5. International transfers
We are based in Singapore, and our providers may store or process data in other countries, including the United States and the European Union. Where we transfer personal data across borders, we take steps required by applicable law (such as standard contractual clauses and ensuring a comparable standard of protection under the PDPA) to protect it.
6. Retention
We keep your personal data for as long as your account is active and, after it is closed, for the maximum period permitted or required under applicable law — for example, to meet tax, accounting, audit, and regulatory obligations, and to resolve disputes — after which we delete or anonymise it. You can ask us to delete your account data sooner (see §8), subject to those legal retention requirements.
7. Cookies
We use essential cookies to keep you signed in and to secure the Service. We also use analytics and performance cookies to understand how the Service is used and to improve it; these may involve third-party analytics providers. This includes campaign and referral parameters (for example which link or ad you arrived from, and advertising click identifiers such as Google’s gclid) and the page you landed on, which may be retained and associated with your account if you sign up. Non-essential cookies are used only with your consent where the law requires it (for example in the EU/UK), and you can manage or withdraw cookie consent through your browser settings or any cookie controls we provide.
8. Your rights
Subject to the laws that apply to you, you may have the right to access, correct, update, or delete your personal data, to object to or restrict certain processing, to withdraw consent, and to data portability. EU/UK (GDPR) users may also lodge a complaint with their supervisory authority. Singapore (PDPA) users may request access to and correction of their data. California (CCPA/CPRA) residents have rights to know, delete, and correct their personal information and to opt out of sale or sharing — we do not sell or share personal information in the CCPA sense. To exercise any right, email danielkoh@bluebed.ai; we will respond as required by the applicable law.
9. Security
We use reasonable technical and organisational measures to protect personal data, including encryption in transit and access controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
10. Children
The Service is not directed to anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
11. Changes
We may update this Policy from time to time. We will revise the “Last updated” date above and, for material changes, take additional steps to notify you where appropriate.
12. Contact
For privacy questions or requests, contact our data protection contact at danielkoh@bluebed.ai. BlueBed.ai Pte. Ltd., Singapore.