Privacy Policy
Last updated: 15 August 2026
What we collect
Your account email, and whatever you choose to enter: portfolio names, holdings (ticker, quantity, buy price/date/currency), and sell records. If you sign in with Google, we receive the basic profile info Google shares for authentication (name, email).
How it's used
Solely to run the app for you: showing your holdings, computing valuations and gains, rendering your charts, and sending the daily performance email if that feature is enabled for your account. We don't use your data for advertising, and we don't sell it.
Where it's stored
Account data and holdings are stored in Supabase (Postgres), access-controlled so each account can only read its own data. The app runs on Cloudflare (Pages for the site, Workers for scheduled price updates and email). Market prices and FX rates come from Twelve Data and are cached server-side — this cache is shared infrastructure and doesn't contain your personal or holdings data.
Third parties
Sub-processors involved in running the app: Supabase (database & auth), Cloudflare (hosting & scheduled jobs), Twelve Data (market price/FX data), and Google (only if you use "Continue with Google"). None of them receive your holdings data except Supabase, which stores it on our behalf.
Your choices
This is an early-stage internal tool and self-serve account deletion/export isn't built yet. To request deletion or an export of your data in the meantime, contact the developer directly — see the Terms page.
Security
Connections are encrypted (HTTPS/TLS). Row Level Security is enforced at the database level so accounts can't read each other's data. See the Terms for the "as is," no-warranty basis this runs on.
Changes
This policy may be updated as the app evolves; the "last updated" date above will change accordingly.