Privacy Policy

Last updated: 2026-10-04

Your privacy matters to us. This policy explains what we collect, why, and how it's protected.

1. Overview

This Privacy Policy explains what information Portfonia collects, how it is used, and the choices you have. It covers the Portfonia web application and the reports it emails you.

2. Information We Collect

Account information: your email address and authentication credentials, handled by our authentication provider.

Holdings and investment data: positions, brokers/custodians, and quantities you upload, plus any investment-style questionnaire responses you provide.

Usage information: basic session and activity data needed to operate the Service securely (for example, sign-in timestamps and idle-timeout enforcement).

Payment and credit information: purchases are processed by Paddle as Merchant of Record. Paddle collects your payment details and billing information under its own privacy notice; we receive transaction records such as order ID, amount, currency, country, and the email used at checkout, but never your full card number. We also keep a record of your credit balance and every credit added or used.

3. How We Use Your Information

We use your data solely to generate and deliver your portfolio reports and to operate, secure, and improve the Service. We do not sell your data, and we do not use your holdings to build or improve any third-party product.

We use payment and credit records to provide your plan, process refunds, and meet accounting and tax obligations.

4. Data Storage and Security

Holdings data is encrypted at rest. Access to production systems is restricted, and administrative actions are logged.

No system is perfectly secure, and we cannot guarantee absolute security, but protecting your data is treated as a first-class engineering requirement, not an afterthought.

5. Third-Party Processing

Generating a report involves sending portions of your data to third-party large-language-model providers to compose the report text. By default, every such call is configured to opt out of the provider using your data for model training.

A narrow, owner-approved exception applies to two specific, non-analytical processing steps: public-market search-query generation, and translating a finished report into your display language. These two steps are routed directly to a single named provider's own first-party API instead of through the training opt-out described above, because that is the only way to reach that specific low-cost model. That provider's standard API terms permit using submitted data to improve its models, so this exception accepts that risk for those two steps only — it is not backed by a no-training data agreement. To limit the exception's reach, the routing is hard-pinned with no automatic fallback to a different provider if it becomes unavailable. The translation step does process report text derived from your holdings, since it translates the finished report itself; the search-query step does not, since it only uses public market/macro themes.

Payments are processed by Paddle, which acts as Merchant of Record and handles your payment information under its own privacy notice.

6. Data Retention

We retain your account and holdings data for as long as your account is active. Some operational records (for example, upload-job metadata) are automatically purged after a short retention window. You may request deletion of your account at any time (see "Your Rights" below).

When your account is deleted, your holdings, investment-style settings, reports, and other personal data are removed. Credit and transaction records are kept, no longer linked to your email address, for accounting and tax purposes.

7. AI Agent access

If you create an API token, we store a one-way hash of it together with its name and its creation, expiry and last-use times. Each request made with a token is logged with the time, the token used, the endpoint and dates requested, the result, and the IP address and User-Agent of the caller. We keep these logs for 90 days to protect your account and to detect misuse. When your holding snapshots are read through the API, we email you a notice at most once a day, with a link that revokes all your tokens. Data returned through the API is delivered to the agent you chose; how that agent stores or uses it is under your control.

8. Your Rights

You can review and update your holdings and profile information directly in the Service. You can request deletion of your account by contacting us; deletion removes your holdings, investment-style settings, and authentication account as described in Data Retention.

9. Cookies and Sessions

We use session cookies to keep you signed in and to enforce automatic sign-out after a period of inactivity. We do not use third-party advertising or tracking cookies.

10. Children's Privacy

The Service is not directed to, and not knowingly used by, anyone under 18. We do not knowingly collect information from minors.

11. Applicable Law

We handle personal data in accordance with the data-protection laws that apply to us, including those of the country where you live where they apply.

12. Changes to This Policy

We may update this Privacy Policy as the Service evolves. Material changes will be reflected on this page with an updated effective date.

13. Contact

Questions about this Privacy Policy, or requests regarding your data, can be sent to info@portfonia.com.