← Delfi

Privacy Policy

Version 1.1 — August 2026

1. Data controller

The controller of personal data is Casini Luigi, based in Italy. For anything relating to privacy: privacy@delfi-memory.com.

2. What data we collect

Delfi collects and processes the following personal data:

  • Access data — email address (for magic-link authentication), IP address (in security logs).
  • User profile — display name, language preference, the tone you prefer to be accompanied with, investor profile (if filled in).
  • Financial data you provide — portfolios, positions, predictions, personal notes, financial projects. This data is entered voluntarily by you.
  • Conversations with Pizia — messages exchanged with the AI assistant, including text content and any attachments.
  • Usage data — anonymous browsing statistics collected through Umami (cookie-less analytics, no personally identifiable data).
  • Invitation requests — if you ask to be invited before having an account, we keep the email address you leave us, any message you write and your browser language, so we can reply. This is the only data we process about people who are not yet registered.

3. Purposes and legal basis

Data is processed for the following purposes:

  • Providing the service (legal basis: performance of a contract, Art. 6.1.b GDPR) — authentication, operation of the AI assistant, management of portfolios and positions.
  • Improving the service (legal basis: legitimate interest, Art. 6.1.f GDPR) — aggregated, anonymous analysis of platform usage.
  • Handling invitation requests (legal basis: pre-contractual measures at the request of the data subject, Art. 6.1.b GDPR) — assessing the request and sending the invitation. The request starts with you: if you don't send it, we know nothing about you.

Delfi does not train its own artificial intelligence models, does not sell user data, and does not pass it to third parties for marketing or commercial profiling. On what the language model providers do with it, see section 4.

4. Recipients of the data

For the AI assistant to work, the content of conversations is sent to third-party language model providers and to the services that route requests to them. These are the only categories of recipient: no other party receives users' personal data, and in particular it is not received by advertisers, financial intermediaries, issuers, or anyone who would process it for commercial purposes.

The providers we use change over time — some are added, some are dropped. That is why we do not list them on this page, where a list would go stale without you noticing: an up-to-date list of the providers your content may be sent to is available at any time, by writing to privacy@delfi-memory.com from your account's address. We will reply with the names.

When you configure your own API keys (BYOK mode), data goes to the provider you chose. In every case, providers receive only the content of the current conversation and the context needed to answer, never your entire history.

Use of content by providers. The terms that apply depend on the provider and on the plan under which each answer is served. Several providers reserve the right to use the content they receive — prompts and responses — to develop and improve their own models and services, and in some cases provide that such content may be reviewed by their staff. These terms are set by each provider, can change over time, and Delfi is not in a position to guarantee or alter them. The paid plans of most providers exclude the use of content for training: by configuring your own API keys (BYOK mode) you choose the provider and the plan, and therefore the terms that apply to your content.

No other third party has access to users' personal data.

5. International transfers

Some providers are based outside the European Union — in the United States and in other third countries. Where the European Commission has adopted an adequacy decision, the transfer takes place on that basis; otherwise we rely on the standard contractual clauses adopted by the European Commission and on the safeguards offered by each provider.

We would rather tell you than stay quiet: some of those countries have no adequacy decision from the European Commission, and for them contractual clauses have recognised limits — no private contract can bind the authorities of a foreign state.

For this reason at first sign-in we ask for your explicit consent, naming the transfer, before you tick the box: this is the condition set out in Art. 49(1)(a) GDPR, and your acceptance is recorded with the date and the version of the documents you read. You can withdraw that consent at any time by writing to privacy@delfi-memory.com: withdrawal cannot undo transfers that already happened, but from that moment your content stops leaving — and with it the conversational part of the service stops, which is the only part that sends it. The rest of Delfi keeps working.

Finally, there is a route that does not go through us at all: by configuring your own API keys (BYOK mode) and choosing a provider based in the Union, your conversations follow the path you chose.

6. Data retention

  • Account data is kept until you delete it.
  • On account deletion, the data that identifies you — username, email, display name — is removed immediately, and your username becomes available again. A technical record remains for 30 days which no longer contains data capable of identifying you, and which exists so that a deletion made by mistake can be undone; after that term, it too is erased.
  • Security logs (IP, sign-ins) are kept for a maximum of 90 days.
  • Invitation requests are kept for a maximum of 12 months from when we receive them, then automatically deleted. If you open an account in the meantime, the request data is no longer needed and is deleted sooner.

7. Your rights

Under the GDPR, you have the right to:

  • Access — to know what data we hold about you. You can ask Pizia "what do you remember about me?" at any time.
  • Rectification — to correct inaccurate data through Settings or through your conversation with Pizia.
  • Erasure — to delete Pizia's data (start over) or your entire account, from Settings. As these are irreversible operations, a second confirmation is asked: your password, or a code sent to your email address if you sign in by link.
  • Portability — to receive a copy of your data in a machine-readable format, to take elsewhere. You request it by writing to privacy@delfi-memory.com from your account's address: we prepare it and send it within thirty days, free of charge. There is not yet a button that generates it by itself, and we would rather tell you than let you find out.
  • Objection — to object to processing based on legitimate interest.
  • Complaint — to lodge a complaint with the competent supervisory authority (in Italy, the Garante per la protezione dei dati personali — garanteprivacy.it).

To exercise your rights, write to privacy@delfi-memory.com.

7.1 One single limit on the right to erasure

The rules of use provide for account suspension in the cases described there. While a suspension is in progress, deletion of your data and of your account is temporarily suspended: the data under review is retained as evidence, under Art. 17(3)(e) GDPR, which allows a deletion request not to be acted upon where processing is necessary for the establishment, exercise or defence of legal claims.

This limitation is not open-ended: it operates for a maximum of 30 days from the opening of the review, after which deletion becomes available again even if the review is still in progress. During suspension the rest of the platform keeps working, and the interface tells you the date on which the limitation ends. If you believe the suspension is wrong, you can contest it by writing to privacy@delfi-memory.com; your right to complain to the supervisory authority remains unaffected.

8. Cookies and tracking

Delfi does not use profiling cookies. Authentication uses a JWT stored in the browser (localStorage). Usage statistics are collected through Umami, a self-hosted analytics system that uses no cookies and collects no personally identifiable data.

9. Disclaimer

Delfi does not provide financial advice and is not authorised to provide it. What Pizia returns is for information only and is not investment advice tailored to your situation. The same holds for the other fields you can discuss inside Delfi — legal, tax, insurance, property, pension or health matters: they are not advice and do not replace a qualified professional. You are solely responsible for your own decisions. The full perimeter is in the Legal notice.

10. Market data — sources and attribution

Some market and macroeconomic data shown in the platform comes from external sources whose terms require attribution. We give it here, valid across all of Delfi:

  • This product uses the FRED® API but is not endorsed or certified by the Federal Reserve Bank of St. Louis.
  • Powered by CoinGecko — cryptocurrency data.
  • Source: U.S. Energy Information Administration — energy data.
  • Source: European Central Bank — euro area yields and exchange rates. The data may be processed further by Delfi.

11. Changes to this policy

This policy may be updated from time to time. The current version will always be available on this page. Where changes are substantial, users will be informed through the platform.

Delfi Legal notice Terms Italiano

© 2026 Delfi — Personal Wealth Intelligence