Prosecution Insights
Last updated: August 08, 2026
Application No. 18/604,379

AUTO-TUNING PERMISSIONS USING A LEARNING MODE

Non-Final OA §103
Filed
Mar 13, 2024
Priority
Jun 26, 2019 — continuation of 11/968,241
Examiner
HAILU, TESHOME
Art Unit
2434
Tech Center
2400 — Computer Networks
Assignee
Amazon Technologies Inc.
OA Round
4 (Non-Final)
78%
Grant Probability
Favorable
4-5
OA Rounds
10m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 78% — above average
78%
Career Allowance Rate
555 granted / 711 resolved
+20.1% vs TC avg
Strong +24% interview lift
Without
With
+23.5%
Interview Lift
resolved cases with interview
Typical timeline
3y 3m
Avg Prosecution
16 currently pending
Career history
729
Total Applications
across all art units

Statute-Specific Performance

§101
14.5%
-25.5% vs TC avg
§103
56.3%
+16.3% vs TC avg
§102
15.1%
-24.9% vs TC avg
§112
7.7%
-32.3% vs TC avg
Black line = Tech Center average estimate • Based on career data from 711 resolved cases

Office Action

§103
DETAILED ACTION This office action is in reply to applicant communication filed on December 24, 2025. Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Claims 1-20 have been cancelled. Claims 21-40 have been amended. Claims 21-40 are pending. Response to Argument Applicant’s arguments filed on December 24, 2025 with respect to the 35 U.S.C. 103 rejections have been fully considered but are moot in view of new ground(s) of rejection. Applicant’s arguments filed on December 24, 2025 with respect to the double patenting rejection have been fully considered, but maintained until the terminal disclaimer filed in view of US 11,968,241. Applicant’s argues that the prior art on record fails to teach the amended limitation of independent claims. However, upon further consideration, a new ground(s) of rejection is made using the newly find prior arts to Weingarten (US Pub. No. 2019/0052659). Double Patenting The nonstatutory double patenting rejection is based on a judicially created doctrine grounded in public policy (a policy reflected in the statute) so as to prevent the unjustified or improper timewise extension of the “right to exclude” granted by a patent and to prevent possible harassment by multiple assignees. A nonstatutory double patenting rejection is appropriate where the claims at issue are not identical, but at least one examined application claim is not patentably distinct from the reference claim(s) because the examined application claim is either anticipated by, or would have been obvious over, the reference claim(s). See, e.g., In re Berg, 140 F.3d 1428, 46 USPQ2d 1226 (Fed. Cir. 1998); In re Goodman, 11 F.3d 1046, 29 USPQ2d 2010 (Fed. Cir. 1993); In re Longi, 759 F.2d 887, 225 USPQ 645 (Fed. Cir. 1985); In re Van Ornum, 686 F.2d 937, 214 USPQ 761 (CCPA 1982); In re Vogel, 422 F.2d 438, 164 USPQ 619 (CCPA 1970); and In re Thorington, 418 F.2d 528, 163 USPQ 644 (CCPA 1969). A timely filed terminal disclaimer in compliance with 37 CFR 1.321(c) or 1.321(d) may be used to overcome an actual or provisional rejection based on a nonstatutory double patenting ground provided the reference application or patent either is shown to be commonly owned with this application, or claims an invention made as a result of activities undertaken within the scope of a joint research agreement. A terminal disclaimer must be signed in compliance with 37 CFR 1.321(b). The USPTO internet Web site contains terminal disclaimer forms which may be used. Please visit http://www.uspto.gov/forms/. The filing date of the application will determine what form should be used. A web-based eTerminal Disclaimer may be filled out completely online using web-screens. An eTerminal Disclaimer that meets all requirements is auto-processed and approved immediately upon submission. For more information about eTerminal Disclaimers, refer to http://www.uspto.gov/patents/process/file/efs/guidance/eTD-info-I.jsp. Claims 21-40 are rejected on the ground of non-statutory double patenting as being unpatentable over claims 1-20 of U.S. Patent No. 11,968,241. Although the claims at issue are not identical, they are not patentably distinct from each other because the instant application and ‘241 is directed to a method of implementing an access control management system. Claim Rejections - 35 USC § 103 In the event the determination of the status of the application as subject to AIA 35 U.S.C. 102 and 103 (or as subject to pre-AIA 35 U.S.C. 102 and 103) is incorrect, any correction of the statutory basis for the rejection will not be considered a new ground of rejection if the prior art relied upon, and the rationale supporting the rejection, would be the same under either status. The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102 of this title, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. This application currently names joint inventors. In considering patentability of the claims the examiner presumes that the subject matter of the various claims was commonly owned as of the effective filing date of the claimed invention(s) absent any evidence to the contrary. Applicant is advised of the obligation under 37 CFR 1.56 to point out the inventor and effective filing dates of each claim that was not commonly owned as of the effective filing date of the later invention in order for the examiner to consider the applicability of 35 U.S.C. 102(b)(2)(C) for any potential 35 U.S.C. 102(a)(2) prior art against the later invention. Claims 21-25 and 27-40 are rejected under 35 U.S.C. 103 as being unpatentable Parimi (US Pub. No. 2017/0295181) in view of Weingarten (US Pub. No. 2019/0052659). As per claim 21 Parimi discloses: A system, comprising: one or more computing devices configured to implement an access control management system, configured to: (paragraph 2 of Parimi, this disclosure relates generally to security technology and, more particularly, to a method, a device and/or a system of activity-based access control in heterogeneous information technology infrastructure environments). Generate an effective access control policy for the principal; (paragraph 192 of Parimi, the state of the art may aggregate groups of privileges into roles (e.g., associated with role privileges 1708), and/or assign them to a user 104 as permissions (e.g., user permissions 1706)) and (paragraph 138 of Parimi, the secure rule definitions 1504 include the rule, violation triggering conditions, and/or remediation actions 1510. [0142] 4. For every rule in the SRD 1504, defaults should exist for triggering conditions, and/or remediation actions 1510). Monitor, during a learning mode, access requests of the principal to a plurality of services or resources in the computing environment under the effective access control policy; (paragraph 23 of Parimi, the method further includes monitoring an activity of the user when accessing any of the set of heterogeneous cloud-based services over a period of time using a processor and a memory. In addition, the method includes dynamically adjusting access privileges to the set of heterogeneous cloud-based services based on the monitoring of the activity of the user over the period of time) and (paragraph 28 of Parimi, policy based automation module may perform the following to remove unused privileges: (1) finds a user permission, a role privilege, and/or a role access control list of the user, (2) finds the operations performed by the user from the history, (3) analyzes the operations performed by the user, (4) finds the operations likely to be performed by the user frequently using a machine learning algorithm of a computer, (5) finds the required privileges for operations identified, (6) creates a unique role specific to the user, (7) updates the user permission with the newly created role for the specific user, and/or (8) removes any other roles assigned to the user). Determine, based at least in part on the access requests of the principal observed during the learning mode, that one or more permissions in the effective access control policy are associated with one or more unused service or resources; determining that the one or more permissions in the effective access control policy are associated with one or more unused service or resources. (Paragraph 28 of Parimi, policy based automation module may perform the following to remove unused privileges: (1) finds a user permission, a role privilege, and/or a role access control list of the user, (2) finds the operations performed by the user from the history, (3) analyzes the operations performed by the user, (4) finds the operations likely to be performed by the user frequently using a machine learning algorithm of a computer, (5) finds the required privileges for operations identified, (6) creates a unique role specific to the user, (7) updates the user permission with the newly created role for the specific user, and/or (8) removes any other roles assigned to the user). Parimi teaches the method of having machine learning algorithm to control access of information technology infrastructure (See abstract of Parimi), but fails to clearly disclose: Identify different source of access control polices for different aspects of a computing environment; aggregate permission from two or more distinct access control policies associated with a principal from the identified different sources to generate an effective access control policy and modifying one or more of the two or more distinct access control policies in response to the determination that the one or more permissions in the effective access control policy. However, in the same field of endeavor, Weingarten teaches this limitation as, (paragraph 71 of Weingarten, in some embodiments, the access policies are synthesized through the data collected from the continuous monitoring of endpoints through agents and the determination of baseline usage of users and/or endpoint devices. In some embodiments, the aggregate of the access policies applied to each individual and/or endpoint device comprise a network access policy as a whole. In some embodiments, the access policies can be inferred or generated directly from the baseline usage of users and/or endpoint devices, and then updated manually or automatically through AI analysis. In some embodiments, because the network can be managed by individual agents installed on endpoint devices and a central server, the access policies can be implemented on any and all levels of the network) and (paragraph 87 of Weingarten, in some embodiments, the agents can regulate network access by employing AI techniques to generate access policies for an endpoint, allowing or restricting connection to, from, and/or of an endpoint and/or an asset, setting authentication criteria for a connection, establishing roles for endpoints, change and/or update policies at endpoints). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of Parimi and include the above limitation using the teaching of Weingarten in order to ensure the security of each of the plurality or user/endpoint devices by applying proper security aggregated policies (see paragraphs 5, 71 and 87 of Weingarten). Claim 33 is rejected under the same reason set forth in rejection of claim 21. As per claim 22 Parimi in view of Weingarten discloses: The system as recited in claim 21, wherein the set of access control policy includes two or more of a delegation policy, a resource policy, a user account policy, a user group policy, a role policy, and an organization policy. (Paragraph 27 of Parimi, the policy may be a time-based policy, a rule-based policy, a predictive policy, a role-based policy, a context-based policy, a risk-score based policy, a segment based policy, and/or a customized policy) and (paragraph 62 if Parimi, the infrastructure security server 100 may include a policy based automation module 606 to enable an administrator of the infrastructure security server 100 to automatically adjust a privilege 110 of the user 104 based on a policy of an organization responsible for security of access to the set of heterogeneous cloud-based services (e.g., 108A, 108B)). Claim 34 is rejected under the same reasons set forth in rejection of claim 22. As per claim 23 Parimi in view of Weingarten discloses: The system as recited in claim 21, wherein effective access control policy automatically changes as the set of access control policies associated with the principal changes. (Paragraph 62 of Parimi, the infrastructure security server 100 may include a policy-based automation module 606 to enable an administrator of the infrastructure security server 100 to automatically adjust a privilege 110 of the user 104 based on a policy of an organization responsible for security of access to the set of heterogeneous cloud-based services (e.g., 108A, 108B)). Claim 35 is rejected under the same reasons set forth in rejection of claim 23. As per claim 24 Parimi in view of Weingarten discloses: The system as recited in claim 21, wherein a particular policy in the set of access control policies is a temporarily policy that is temporarily associated with the principal. (Paragraph 91 of Parimi, the revocation 1800 of access may be manual, semi-automatic, or completely automatic (e.g., privileges unassigned due to recent non-usage 1108). The grant 1800 of access may be manual (e.g., privilege assigned upon approval 1110), semi-automatic (e.g. privilege assigned upon approval 1110), or completely automatic (e.g., privilege auto assigned upon recent usage 1106). These newly granted access privileges (user privileges 1710) may be set to expire after some time. A newly granted access privilege (e.g., user privileges 1710) may be time limited with a TTL (time to live) based on a set of policies). Claim 36 is rejected under the same reasons set forth in rejection of claim 24. As per claim 25 Parimi in view of Weingarten discloses: The system as recited in claim 21, wherein the principal is associated with an application in the computing environment and the effective access control policy is associated with the application. (Paragraph 62 of Parimi, the policies may be applicable to one or more authorization systems covering all aspects of the information technology (IT) infrastructure (e.g., physical, virtual, containers, private cloud, public cloud infrastructures, applications, SaaS applications, and/or devices, etc.)) As per claim 27 Parimi in view of Weingarten discloses: The system as recited in claim 21, wherein to generate the effective access control policy, the access control management system is configured to: resolve a permission conflict between two or more access control policies in the set of access control policies; or remove a redundant permission between two or more access control policies in the set of access control policies. (Paragraph 138 of Parimi, provide the ability for the system user 904 to create new SRDs 1504. [0144] 6. Provide the ability for the system user 904 to modify any existing SRDs 1504. These modifications should create new SRDs 1504 specific to the system user 904. [0145] 7. Find any SRDs 1504 that conflict with each other, and/or flag them. [0146] 8. Group SRDs 1504 to create a “Security Profile” (SP) 1512. [0147] 9. Do not allow the system user 904 to add two conflicting SRDs 1504 to the same SP 1512. [0148] 10. Provide the ability for the system user 904 to create, and/or modify SPs 1512. [0149] 11. Provide the system user 904 with the ability to share SRDs 1504, and/or SPs 1512 with others via some network (e.g., social network)). Claim 37 is rejected under the same reasons set forth in rejection of claim 27. As per claim 28 Parimi in view of Weingarten discloses: The system as recited in claim 21, wherein to remove the one or more permissions from the effective access control policy, the access control management system is configured to: perform one or more removal actions selected from a set of removal actions, the set of removal actions including two or more of:(a) removing the principal from a group, (b) releasing the principal from a role, (c) modifying permissions of a group or a role, (d) adding the principal to a new group with different permissions, and (e) deprovisioning a service or resource. (Paragraph 28 of Parimi, policy based automation module may perform the following to remove unused privileges: (1) finds a user permission, a role privilege, and/or a role access control list of the user, (2) finds the operations performed by the user from the history, (3) analyzes the operations performed by the user, (4) finds the operations likely to be performed by the user frequently using a machine learning algorithm of a computer, (5) finds the required privileges for operations identified, (6) creates a unique role specific to the user, (7) updates the user permission with the newly created role for the specific user, and/or (8) removes any other roles assigned to the user). Claim 38 is rejected under the same reasons set forth in rejection of claim 28. As per claim 29 Parimi in view of Weingarten discloses: The system as recited in claim 21, wherein to remove the one or more permissions from the effective access control policy, the access control management system is configured to: split a group associated with the principal into two or more groups with different permissions; and assign the principal to one of the two or more groups. (Paragraph 102 of Parimi, the risk score 210 may be multi-dimensional across heterogeneous authorization systems (e.g., 112A, 112B). The multiple dimensions may be at least one of a risk score 210 based on a privilege 110, a risk score 210 based on a group of privileges 110, a risk score 210 based on a user, a risk score 210 based on a group, a risk score 210 based on a role (e.g., associated with role privileges 1708), a risk score 210 based on a project, a risk score 210 based on a service, a risk score 210 based on an application, a risk score 210 based on one of the set of heterogeneous cloud-based services (e.g., 108A, 108B), a risk score 210 based on an authorization system (e.g., 112A, 112B), a risk score 210 based on a network, a risk store 210 based on context, a risk score 210 based on an infrastructure, a risk score 210 based on an action, a risk score 210 based on an operation, a risk score 210 based on a software, a risk score 210 based on a hardware, a risk score 210 based on a configuration, a risk score 210 based on a configuration violation, a risk score 210 based on a common vulnerability, a risk score 210 based on a risk exposure, a risk score 210 based on one of the heterogeneous authorization systems (e.g., 112A, 112B), a risk score 210 based on a geographic region, a risk score 210 based on a logical region, a risk score 210 based on a task, a risk score 210 based on a function, a risk score 210 based on a company, and/or a risk score 210 based on an enterprise). Claim 39 is rejected under the same reasons set forth in rejection of claim 29. As per claim 30 Parimi in view of Weingarten discloses: The system as recited in claim 21, wherein the computing environment is provided by a multi-tenant resource provider network that provides virtualized compute and storage resource for a plurality of tenants. (Paragraph 255 of Parimi, the central component of infrastructure security server 900 also computes the risk scores 210 and analyses the risk 1102 at any granularity. It also provides visibility 1508 and insights of the risk score 210 analysis, and allows benchmarking with peers. It provides work flow and notifications. It supports auditing, reporting and compliance. It has a multi-tenant data store. The infrastructure security server 100 allows its security settings to be configured and/or modified by the system user 904 including policy-based automation 606 (e.g., using rules, policies and profiles) to grant/revoke privileges). As per claim 31 Parimi in view of Weingarten discloses: The system as recited in claim 21, wherein the access control management system is configured to: modify the effective access control policy based at least in part on whether a number of access requests observed for a particular service or resource during the learning mode exceeds a threshold. (Paragraph 28 of Parimi, policy based automation module may perform the following to remove unused privileges: (1) finds a user permission, a role privilege, and/or a role access control list of the user, (2) finds the operations performed by the user from the history, (3) analyzes the operations performed by the user, (4) finds the operations likely to be performed by the user frequently using a machine learning algorithm of a computer, (5) finds the required privileges for operations identified, (6) creates a unique role specific to the user, (7) updates the user permission with the newly created role for the specific user, and/or (8) removes any other roles assigned to the user). As per claim 32 Parimi in view of Weingarten discloses: The system as recited in claim 21, wherein the access control management system is configured to: add a particular permission to the effective access control policy based at least in part on the access requests observed during the learning mode. (Paragraph 28 of Parimi, policy based automation module may perform the following to remove unused privileges: (1) finds a user permission, a role privilege, and/or a role access control list of the user, (2) finds the operations performed by the user from the history, (3) analyzes the operations performed by the user, (4) finds the operations likely to be performed by the user frequently using a machine learning algorithm of a computer, (5) finds the required privileges for operations identified, (6) creates a unique role specific to the user, (7) updates the user permission with the newly created role for the specific user, and/or (8) removes any other roles assigned to the user). As per claim 40 Parimi in view of Weingarten discloses: The method as recited in claim 33, further comprising the access control management system: generating a recommendation to remove the one or more permissions from the effective access control policy, wherein the removing of the one or more permissions is performed in response a user approval of the recommendation. (Paragraph 91 of Parimi, the grant 1800 of access may be manual (e.g., privilege assigned upon approval 1110), semi-automatic (e.g. privilege assigned upon approval 1110), or completely automatic (e.g., privilege auto assigned upon recent usage 1106)). Claim 26 is rejected under 35 U.S.C. 103 as being unpatentable Parimi (US Pub. No. 2017/0295181) in view of Weingarten (US Pub. No. 2019/0052659) and further in view of Kraemer (US Pub. No. 2007/0113270). As per claim 26 Parimi in view of Weingarten discloses: The system as recited in claim 25, wherein the access requests are generated in response to historical or synthetic client traffic. (Paragraph 28 of Parimi, policy based automation module may perform the following to remove unused privileges: (1) finds a user permission, a role privilege, and/or a role access control list of the user, (2) finds the operations performed by the user from the history, (3) analyzes the operations performed by the user, (4) finds the operations likely to be performed by the user frequently using a machine learning algorithm of a computer, (5) finds the required privileges for operations identified, (6) creates a unique role specific to the user, (7) updates the user permission with the newly created role for the specific user, and/or (8) removes any other roles assigned to the user). The combination of Parimi and Weingarten teaches the method of having machine learning algorithm to control access of information technology infrastructure (See abstract of Parimi), but fails to clearly disclose: The learning mode is conducted during a pre-production phase of the application. However, in the same field of endeavor, Chang teaches this limitation as, (paragraph 9 of Kraemer, in a preferred embodiment, the learning mode is enabled at a time of initial deployment of a networked computer system). Therefore, it would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to modify the teaching of Parimi and Weingarten to include the above limitation using the teaching of Kraemer in order to secure the computing system by handling the access request oof the computing resource according to the pre learned method during the learning phase (see abstract of Kraemer). Conclusion The prior art made or record and not relied upon is considered pertinent to applicant’s disclosure is Tovar (US Pub. No. 2011/0231890). Tovar discloses: Various embodiments of the present invention include methods and systems for managing Internet access. An exemplary method for managing Internet access includes three steps. First a request is received to access the Internet. Second, a determination is made whether the request is being made during a restricted time period. Third, Internet access is selectively managed Internet access for an end user via a computing device, by blocking Internet access if the determination is that the request was made during a restricted time period or granting Internet access if the determination is that the request was made outside the restricted time period. Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to TESHOME HAILU whose telephone number is (571)270-3159. The examiner can normally be reached M-F 8 a.m. - 5 p.m.. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Ali Shayanfar can be reached at (571) 270-1050. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /TESHOME HAILU/Primary Examiner, Art Unit 2434
Read full office action

Prosecution Timeline

Show 2 earlier events
Mar 31, 2025
Response Filed
Jun 16, 2025
Final Rejection mailed — §103
Sep 16, 2025
Request for Continued Examination
Sep 19, 2025
Response after Non-Final Action
Sep 24, 2025
Non-Final Rejection mailed — §103
Dec 24, 2025
Response Filed
May 05, 2026
Final Rejection mailed — §103
Jul 06, 2026
Response after Non-Final Action

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12695636
PROOF OF DATA RETENTION WITH BLOCKCHAIN
1y 11m to grant Granted Jul 28, 2026
Patent 12694044
DATA PROCESSING SYSTEMS AND METHODS FOR AUTOMATICALLY DETECTING AND DOCUMENTING PRIVACY-RELATED ASPECTS OF COMPUTER SOFTWARE
1y 7m to grant Granted Jul 28, 2026
Patent 12688294
VIRTUAL TRUSTED PLATFORM MODULE IMPLEMENTATION METHOD AND RELATED APPARATUS
3y 2m to grant Granted Jul 21, 2026
Patent 12688264
WATERMARKING DIGITAL MEDIA FOR CONTENT VERIFICATION WITH DIFFERENTIAL DETECTION
1y 7m to grant Granted Jul 21, 2026
Patent 12682119
METHODS, COMPUTER DEVICES, AND NON-TRANSITORY COMPUTER-READABLE RECORD MEDIA FOR LEARNING OF WATERMARKING MODEL USING COMPLEX ATTACK
1y 11m to grant Granted Jul 14, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

4-5
Expected OA Rounds
78%
Grant Probability
99%
With Interview (+23.5%)
3y 3m (~10m remaining)
Median Time to Grant
High
PTA Risk
Based on 711 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month