How Globefin collects, uses, and protects your information — written to be read, not skimmed past.
globefin.org is a free educational platform teaching comparative finance — how different societies allocate capital, manage risk, and regulate markets. It is owned and operated by Library B Development Corporation, a Kentucky non-profit corporation ("Globefin", "we", "us", "our"). This policy explains what personal data we handle when you visit the site or create an account, and what you can do about it.
For the purposes of the EU and UK General Data Protection Regulation, Library B Development Corporation is the data controller for the information described here. You can reach us at any time at admin@globefin.org.
The short version. Most of Globefin — the lessons, the Knowledge Base, Web Apps, Discussions — now sits behind a free account, so we know who you are while you use it. We collect what we need to run your account and your learning, plus analytics about how the site is used. We do not sell your data and we do not run advertising networks. The Knowledge Base also holds information about companies and named individuals drawn from public filings; if that includes you, section 9 explains what to do.
We collect information in three ways: what you give us, what is generated as you use the site, and what is collected automatically by our servers and by the third-party services embedded in our pages.
| Category | Examples | Source |
|---|---|---|
| Account data | Your real first and last name, email address, password (stored only as a cryptographic hash), profile address, account creation date, last login, and whether your email is verified. | You, at signup |
| Signup record | The IP address you signed up from and an approximate location derived from it. This is recorded and sent to our administrator as a new-member notice. | Automatic, at signup |
| Profile data | Any optional details you add — headline, country, profile photo — plus your directory-listing and messaging preferences. | You, optionally |
| Résumé data | If you fill in a résumé: professional summary, skills, job titles, employers, locations, dates and descriptions of roles, schools, degrees, fields of study, and years attended. | You, optionally |
| Learning data | Lessons viewed and completed, quiz answers and scores. For SIE preparation: every practice question attempted and whether you answered it correctly, flashcard ratings and review schedule, mock exam scores, and your projected readiness score. | Generated as you learn |
| Content you submit | Discussions and posts, moderation actions you take, lesson corrections and review-tool suggestions, Web Apps pages you create, messages to other members, and anything else you post. | You |
| AI helper usage | When you use the helper inside a Web App: which member, which page, which model, how many tokens, what it cost, and when. Not your question, the answer, or any of the data from the app. Kept so that we can manage cost and enforce the daily limit. | Generated as you use it |
| Page unlock attempts | Failed attempts to open a password-protected Web App page: which member, which page, how many, and when. Kept so a page cannot be guessed at repeatedly, and cleared when the password is changed. | Generated as you use it |
| Invitation data | If you invite someone: their email address, the first name you give, your personal note, and whether the invitation was accepted. | You, about someone else |
| Correspondence | Emails you send us and our replies, including support and correction requests. | You |
| Technical data | IP address, browser type and version, device and operating system, referring page, pages requested, timestamps. Failed login attempts are recorded with the email address tried and the IP address, to throttle brute-force attacks. | Automatic (server logs) |
| Analytics data | Pages viewed, clicks and interactions, session and device identifiers, and approximate location, collected by the analytics providers named in section 5. | Automatic (third parties) |
We do not ask for and do not want special category data — information about your health, race or ethnicity, religion, political opinions, sexual orientation, trade union membership, biometrics, or genetics. Please don't put such information into your profile, your résumé, or content you submit.
Globefin is an educational site. We never ask for your financial account details — no bank account numbers, no brokerage credentials, no card numbers. If anyone claiming to be Globefin asks you for these, it is not us; please report it to admin@globefin.org.
We use the information above to:
We do not sell your personal data, we do not share it with data brokers, and we do not use it to build advertising profiles. We do not use your personal data to train our own AI models.
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR:
Every page on Globefin loads a small number of third-party services. We want you to know exactly which, because each one can see your IP address and something about your visit.
| Service | Provider | What it does |
|---|---|---|
| Google Analytics 4 | Measures page views, sessions, and general usage patterns. Sets cookies and collects a device identifier, IP address, and approximate location. | |
| Heap | Heap (Contentsquare) | Product analytics — records interactions such as clicks and page views so we can see how features are actually used. |
| reCAPTCHA v3 | Distinguishes people from bots on our forms. Google receives your IP address and behavioural signals from the page, and uses them under its own terms. | |
| Fonts, icons, and libraries | Google Fonts, Font Awesome, jsDelivr, jQuery CDN | Serve typefaces, icons, and JavaScript libraries. These providers see your IP address as a consequence of serving the file. |
| Email delivery | SendGrid (Twilio) | Sends verification, password-reset, invitation, and notification emails on our behalf. |
Analytics currently run as soon as a page loads, before you have made any choice about them. We are being direct about this rather than describing an approval step that does not yet exist. If you would prefer not to be measured, you can block these scripts with your browser's settings or a content blocker, or use Google's Analytics opt-out add-on — the rest of the site will work normally.
We do not host third-party advertising networks and we do not use cross-site tracking pixels for advertising.
You can block or delete cookies in your browser settings. If you block strictly necessary cookies, you will not be able to log in.
Globefin is open about how it is built: our lessons are drafted with the help of large language models and published before they are reviewed, then corrected on an ongoing basis. That is what makes our global, comparative scope possible, and the Terms of Use set out what it means for accuracy. Several features also send text to AI providers while you use them.
Every lesson carries a review tool that lets you run the page through several independent AI models — which may include services operated by Anthropic (Claude), OpenAI (GPT), Google (Gemini), xAI (Grok), Mistral, and DeepSeek — to surface factual errors, missing context, or unclear passages, and then send the findings worth keeping to our editors. Requests may be routed through an intermediary such as OpenRouter.
When you use that tool, the lesson text and anything you type into it are transmitted to the provider you select and handled under their privacy policy and retention practices, not ours. The suggestions you choose to submit are stored by us with your account identifier, so our editors can act on them.
Some Web Apps carry a built-in helper you can ask questions of. It is the AI feature that handles the most sensitive information on Globefin, so it is worth reading this even if you skip the rest.
What is sent. When you ask the helper a question, three things go to the model provider: your question, the recent back-and-forth of that conversation, and a summary of what you currently have open in the app. That last part is what makes the helper useful and is also the part to understand. In a spreadsheet it is a sample of your cells and formulas. In the accounting app it is your company name, your headline figures, and your most recent invoices and bills, including customer and supplier names and amounts.
Where it goes. Requests are sent from our server to OpenRouter, which routes them to the model provider serving that request. We do not send your name, your email, or anything else identifying you: the provider receives the question and the app summary, not who asked it.
What we keep. We do not store your questions or the helper's answers. We record that a request happened — which member, which page, which model, how many tokens, what it cost, and when — so that we can manage cost and enforce the daily limit. That log holds no part of what you asked or what the sheet contained.
If your figures are confidential, do not ask the helper about them. The app itself keeps everything in your browser and sends nothing anywhere; it is the helper, and only the helper, that transmits what you are working on. A page with no helper never sends your data at all, and you can use any app without ever opening the helper panel.
Members can point AI tools at a discussion — to summarise it, argue the other side, or check factual claims. When someone runs a tool, the recent posts in that discussion are sent to an AI provider to be read. That includes posts written by other members. AI never posts on its own; a member must run it and choose to publish the result, and anything published is labelled as AI and shown under that member's name.
Some study material, including SIE practice questions and flashcards, is generated with AI models. Review happens after publication, as it does elsewhere on the site. This process uses lesson and topic material, not your personal data.
Please do not enter personal, confidential, or sensitive information into any AI feature on Globefin. Once text leaves our servers for a third-party model, it is governed by that provider's terms, and we cannot recall it. The same applies to anything you write in a discussion that someone might later run a tool against.
AI-assisted drafting can produce errors, material is published before it is checked, and review is continuous rather than complete. Nothing on Globefin is financial, investment, tax, or legal advice — see our Terms of Use for the full statement.
Globefin asks for real names, like LinkedIn, because the community is built on identifiable scholarship and professional connection. Most of the site now requires an account, so what follows is visible to signed-in members rather than to the open web:
You control what optional information goes into your profile and résumé, and you can edit or remove it at any time from your account settings.
The Knowledge Base is a structured record of innovation activity: organisations, the people connected to them, funding rounds, grants, patents, acquisitions, and hiring. It is compiled from public sources — including SEC filings retrieved through EDGAR (Form D, Form C, Form 1-A, S-1), USPTO patent records, USAspending federal grant data, state programme lists, and contributions from members.
Some of this is personal data about identifiable individuals — for example, the names and roles of officers, directors, and promoters listed on a Form D filing. These people did not give it to us and are not Globefin members. We think it is worth being explicit about that, and about what it means:
If you appear in the Knowledge Base and want your entry corrected, restricted, or removed, write to admin@globefin.org with enough detail to identify the record. You do not need a Globefin account to ask, and you do not have to explain why. We will act on well-founded requests, and we will tell you what we did.
Web Apps lets you publish a single self-contained HTML page that Globefin serves inside an isolated frame. We store the page's source code, its title, summary, tags, any link you add, its size, its visibility status, and a count of views. Your name is shown as its author on published pages.
Web Apps pages run as ordinary web pages in your browser. They cannot read your Globefin session, cookies, or account, but a page written by another member is that member's code, not ours. It may load resources from external sites, which would let those sites see your IP address. Never type a password or personal information into a Web Apps page.
Downloading a page. You can download any published page and open it on your own computer. A downloaded copy runs without the isolation it has here — that isolation comes from instructions we send with the page, and a file on your disk is served by nobody. Such a copy can send data over the internet to whoever wrote it, and can keep data on your machine between sessions.
It cannot go looking through your files. It can read anything you open in it — so if you open a workbook or a set of accounts in a downloaded page, that page is in a position to transmit them. Open downloaded pages from people you have reason to trust, and never type a password into one.
Automated checks. We run automated checks over pages published here, looking for patterns worth a human look — code that sends data somewhere, asks for passwords, or hides what it does. This reads the page's own published source, which is already visible to every member, and nothing about you.
Password-protected pages. If you put a password on a page, we store it only as a hash and never in a form we could read. We record failed unlock attempts — which member, which page, how many, and when — so that a page cannot be guessed at repeatedly. Globefin staff can read the contents of any page, including a password-protected one, so that published material can be moderated.
Publishing a page also licenses it for others to reuse. That is a licensing question rather than a privacy one, and it is covered in the Terms of Use.
The Commitments tool timestamps an idea without revealing it. We do not store the text you enter. What we store is a salted cryptographic hash of it, the optional public label you choose, the timestamp, and its position in a public append-only chain — plus your account identifier if you were signed in when you made it.
The chain is public. Anyone can see the hashes, the timestamps, the order, and any labels. A hash reveals nothing about the underlying text. The secret salt is shown to you once and never retained by us, which means we cannot recover your commitment for you and cannot reconstruct what you wrote.
If you invite someone to Globefin, you give us their email address and optionally their first name and a personal note. We use it to send that one invitation, to tell you whether they joined, and to prevent duplicate or abusive invitations. Please only invite people who would welcome hearing from you — you are responsible for having a reasonable basis to share their address with us.
If you have received an invitation and would like your address removed from our records, write to admin@globefin.org and we will delete it.
We share personal data only in these circumstances:
We do not sell personal data, and we do not "share" it for cross-context behavioural advertising as those terms are defined under California law.
Globefin is a global project with a global audience, and our providers — including our hosting, analytics, email, and AI providers — may be located outside your country, including in the United States. Where we transfer personal data out of the EEA or the UK, we rely on an adequacy decision where one applies, or otherwise on Standard Contractual Clauses or an equivalent safeguard. You may request a copy of the relevant safeguard by writing to admin@globefin.org.
When you delete your account, we delete or anonymise your personal data within a reasonable period, except where we must keep something to comply with a legal obligation, resolve a dispute, or enforce our terms, and except for the openly licensed and append-only material described above. Backups are overwritten on a rolling cycle.
We take reasonable and appropriate technical and organisational measures to protect your information: encrypted connections (HTTPS), passwords stored only as salted hashes and never in plain text, protection against cross-site request forgery, throttling of repeated failed logins, access to production data limited to those who need it, and prompt patching of the software we run.
Administrator access. Globefin administrators can use a "view as member" tool that lets them see the site as you see it, in order to reproduce a fault or investigate abuse. We think you should know it exists and how it is bounded: it cannot be used to change your password or email, delete your account, or send messages in your name, a banner is displayed throughout, and every use is logged against the administrator who did it.
No system is perfectly secure, and we cannot guarantee absolute security. Please use a strong, unique password for Globefin, and tell us immediately at admin@globefin.org if you believe your account has been compromised. If you are a security researcher and have found a vulnerability, we would genuinely like to hear from you at the same address.
Depending on where you live, you may have some or all of the following rights over your personal data. These apply whether or not you are a member — including if you appear in the Knowledge Base or were invited by someone else.
To exercise any of these, email admin@globefin.org. We will respond within the period the applicable law requires — normally within one month under the GDPR, and within 45 days under the CCPA/CPRA. We may need to verify your identity first, which usually means confirming you control the account's email address. An authorised agent may act for you where the law allows, with proof of authorisation.
Some things we genuinely cannot undo: we cannot recover a Commitment's original text, we cannot remove an entry from the middle of the commitment chain, and we cannot recall copies of openly licensed material that others have already taken. Where that is the case we will say so plainly rather than leave you waiting.
If you are in the EEA or UK and you are not satisfied with our response, you have the right to lodge a complaint with your national data protection authority. We would appreciate the chance to address it first.
Globefin is intended for adults and for older students studying finance. Accounts are not available to children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has created an account, write to admin@globefin.org and we will delete it.
We may update this policy as Globefin grows — new pillars, new tools, new providers. When we do, we will revise the "last updated" date at the top of this page. If a change is material — for example, a new purpose for your data — we will give you notice by email or a prominent notice on the site before it takes effect. Continuing to use Globefin after a change takes effect means you accept the revised policy.
Questions about this policy, a request to exercise your rights, or a privacy concern — all go to the same place, and a person reads them.
admin@globefin.org