Privacy Policy
Written against the system that actually exists: the tables, the columns and the retention jobs. It is longer than a template because a template would have to be vague, and vague is what you write when you do not know what your own software stores.
This policy has not been reviewed by a privacy lawyer and is not in force. Three sub-processors in section 6 are still undecided and are marked as such; each will be named here before it processes anything. Until then the hosted product is not accepting accounts, so there is no personal data in it beyond the marketing-site waiting list described in section 2.
01Who we are
The controller of personal data described in this policy is [LEGAL ENTITY, TRADING AS “PORTFOLEO”], reachable at privacy@portfoleo.ai.
We have not appointed a data protection officer, because we are not required to and because claiming one that does not exist would be worse than saying so. Privacy questions go to a human at the address above.
If you run the desktop or self-hosted build, you are the controller of everything in it. It stores its data on your machine and does not report to us. This policy then applies only to this website.
02What we collect, exactly
Grouped by where it lives. Everything in the “Hosted product” group exists only once the hosted product opens and you create an account.
This website, portfoleo.ai
- Waiting-list email address and a timestamp, if you submit one. That is the only thing this site collects.
- Edge request logs held transiently by our edge provider for delivery, abuse prevention and rate limiting. These include an address and a user-agent string.
- No cookies, no analytics, no advertising pixels, no session recording, no fingerprinting. This site loads no third-party resource of any kind, which you can confirm in your browser’s network panel.
Hosted product, app.portfoleo.ai
- Account
- Email address and its normalised form, a password hash (Argon2id — we never store the password), email-verification timestamps, two-factor secret reference and hashed recovery codes if you enable it, failed-login counter, lockout timestamp, last login time.
- Organisation
- Name, slug, plan, seat count, founding seat number if any, region, creation and deletion timestamps, and your role within it.
- Sessions
- A hash of the session token (never the token), a hash of the request-forgery token, the first address the session was seen from, a hash of the user-agent string, and creation, last-seen and expiry timestamps. Sessions are server-side records so that revoking one takes effect at once.
- Billing
- Provider customer and subscription identifiers, plan, interval, status, amount, currency, period end, cancellation and refund timestamps. No card number, no expiry, no security code and no bank detail ever reaches us — the merchant of record holds all of that.
- Your keys
- For each credential you connect: its name from a fixed list, the encrypted value, a truncated cryptographic fingerprint, the last four characters as a display hint, and the time it was last used. The plaintext is never returned by any endpoint and never appears in a log.
- Your content
- Preferences and workspace layouts, watchlists, saved backtest runs and their artifacts, alert rules and fired alerts, copilot sessions and their turns and your feedback on them, workflow definitions and runs, simulated portfolios and their positions and paper orders, documents you add to your private retrieval corpus, and an activity log of what happened in your organisation.
- Usage and metering
- Counters per organisation and window, such as copilot queries per day and backtest minutes per day, plus rate-limit buckets. Model spend is recorded as tokens and cost with a flag for whether it ran on your key or ours.
- Security audit
- Login success and failure, key writes and reads, plan changes, session revocation and organisation deletion, each with actor, target, address and time. Metadata carries fingerprints; it never carries a secret value.
- Support correspondence
- What you write to us and what we write back.
- Application logs
- Operational logs with a redaction filter on the root logger. Query strings are omitted from access logs, and known credential shapes and in-flight secret values are scrubbed before a record is written.
We do not ask for and do not want any special-category data under the GDPR, or any sensitive personal information under the CCPA as amended: no government identifiers, no health data, no biometrics, no precise geolocation, no racial, political, religious, union or sexual-life data. Do not put any of it into the product. Your positions and research are commercially sensitive but are not a special category in law, and we treat them as confidential regardless.
03Why we process it, and on what lawful basis
| Data | Purpose | Lawful basis |
|---|---|---|
| Account, organisation, sessions | To create and run your account and to keep you signed in | Performance of a contract |
| Your content, your keys | To deliver the analytics you asked for and to make the provider requests you asked for | Performance of a contract |
| Billing records | To take payment, apply the right plan limits, and issue refunds | Performance of a contract; legal obligation for tax records |
| Usage counters, rate-limit buckets | To enforce published plan limits and to keep one account from degrading the service for everyone else | Performance of a contract; legitimate interests |
| Security audit log, application logs, edge logs | To detect and investigate abuse, to answer “what happened to my account”, and to fix defects | Legitimate interests in the security of the service |
| Waiting-list email | To tell you when access opens | Consent, withdrawable in one reply |
| Support correspondence | To answer you and to keep a record of what was agreed | Performance of a contract; legitimate interests |
| Product announcement email | To tell you about changes that affect you | Legitimate interests for service notices; consent for anything promotional |
Where we rely on legitimate interests we have considered your interests and rights against ours, and you can object — see section 8. Service notices about security, billing and material changes are not marketing and cannot be unsubscribed from while you hold an account.
04What we never do
- We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined by the CCPA as amended. There is nothing to opt out of because there is no such disclosure to opt out of.
- We do not train models on your content. Your prompts, documents, runs and positions are not added to any training set and are not promoted into any corpus shared with another customer.
- We do not put analytics or advertising code on this website or in the product.
- We do not read your content for any purpose other than running the service for you, other than where you ask us to look at something in support, or where we must investigate a specific security incident, which is recorded in the audit log.
- We do not return your API keys to anyone, including you.
- We do not use dark patterns to keep you. Cancellation and deletion are self-serve and take the same number of clicks as signing up.
05How long we keep things
| Data | Kept for | Then |
|---|---|---|
| Session records | 14 days idle, 30 days absolute | Expired and removed; revocation is immediate |
| One-time email tokens | Until used, or their short expiry | Consumed or expired |
| Your content, active account | While the account exists | — |
| Your content, after downgrade | 90 days over-limit, read-only | Purged, unless you upgrade or export first |
| Copilot sessions | Per plan, 5 to 500 most recent | Oldest dropped |
| Encrypted keys, after you delete one | 30 days, inactive | Purged; recoverable in that window if you deleted by mistake |
| Account after deletion | Soft-deleted, purged within 30 days | Purged |
| Security audit log | 12 months | Purged |
| Application logs | [TO BE SET], target 30 days | Rotated and purged |
| Edge request logs | Per our edge provider’s default | Rotated by them |
| Billing and tax records | 7 years, or as local law requires | Kept as a legal obligation, even after account deletion |
| Encrypted backups | 30 days | Rotated; a deletion propagates as backups age out |
| Waiting-list email | Until access opens or you ask us to remove it | Deleted |
Deleting your account removes it from the live system immediately and from backups as those backups rotate out within 30 days. We will not restore a deleted account from a backup in order to satisfy a later request, because that would defeat the deletion.
06Sub-processors
Everyone who can touch personal data on our behalf, what for, and where. Three rows are still undecided; each will be named here before it processes anything, and the change will appear on the changelog.
| Provider | What it does | Data it can see | Region |
|---|---|---|---|
| Cloudflare | DNS, edge delivery, static hosting for this website, the waiting-list store, and network-layer protection | Request metadata including address and user-agent; the waiting-list email | Global edge, United States configuration |
| Application host | Runs the hosted product and its database | Everything in section 2 under “Hosted product”, at rest and in memory | [UNDECIDED — US] |
| Transactional email provider | Sends verification, password reset, billing and security notices | Your email address and the content of those messages | [UNDECIDED] |
| Merchant of record | Takes payment, calculates and remits tax, hosts the billing portal, issues invoices | Your billing identity and payment instrument — which they hold, and we do not | [UNDECIDED] |
| Model provider | Answers copilot requests when you use the included quota on the hosted tier | The prompt you wrote and the figures the engine computed for it | United States |
| Your own providers | Whatever you connect a key for — market data, models, webhooks | Whatever those requests contain, under your agreement with them | Theirs |
| Error tracking | Records exceptions so defects get fixed | Stack traces and request context, with the redaction filter applied to its transport | [UNDECIDED] |
If you connect your own model key, requests go to that provider under your account and their policy for your account governs. If you use the included quota on the hosted tier, requests go under ours. If you run the desktop build against a local model, no request leaves your machine and there is no row here at all. The full breakdown is on the security page.
07International transfers
The hosted product runs in the United States at launch. If you are in the European Economic Area, the United Kingdom or Switzerland, using it means your data is transferred to and processed in the United States.
The transfer mechanism — standard contractual clauses, the applicable data privacy framework, or both, plus a transfer impact assessment — is [TO BE COMPLETED WITH COUNSEL]. This is one of the reasons this document is still marked draft: publishing a confident transfer story we have not put in place would be exactly the kind of claim this project refuses to make.
There is no European data residency option today. Section 11 of the security page lists that alongside the other gaps.
08Your rights, and how to use them
Depending on where you live you have some or all of the following. We apply them to everyone who asks, regardless of jurisdiction, because running two standards is how the weaker one wins.
- Know and access — what we hold about you and a copy of it.
- Correct — fix anything inaccurate.
- Delete — erase your account and content, subject to records we must keep for tax or legal reasons.
- Port — receive your content in a machine-readable format.
- Restrict or object — ask us to pause a processing activity, or object to one based on legitimate interests.
- Withdraw consent — at any time, without affecting processing done before you withdrew it.
- Opt out of sale or sharing — there is nothing to opt out of, as section 4 explains. Global Privacy Control signals are honoured anyway.
- Limit use of sensitive personal information — we do not collect any.
- Non-discrimination — exercising a right never changes your price or your service.
- Human review — we do not make automated decisions with legal or similarly significant effects about you. Plan limits are contractual terms you agreed to, not profiling.
How to exercise them
- Email privacy@portfoleo.ai from the address on the account, or use the account screen where a self-serve control exists.
- We verify identity proportionately — usually by confirming control of the account email. We will not ask you for a government identity document to answer a privacy request.
- We respond within 30 days, and within 45 days for CCPA requests, extending only where the law allows it and telling you if we do.
- An authorised agent may act for you with written permission.
- There is no fee unless a request is manifestly unfounded or excessive, and we will say so before charging anything.
If you are unhappy with how we handled a request you can complain to your supervisory authority. We would rather you told us first so we can fix it.
09Cookies
This website sets no cookies at all. That is why you have not been shown a consent banner: there is nothing to consent to. You can verify it in your browser’s storage panel.
The hosted product sets exactly two, both strictly necessary, both first-party, both with the host prefix that forces secure transport and a fixed path and forbids a domain attribute:
- Session
- An opaque random value that identifies your server-side session record. Necessary to stay signed in. Lifetime up to 14 days idle and 30 days absolute; cleared on sign-out.
- Request-forgery token
- A random value that the page reads and sends back on state-changing requests, bound to your session record. Necessary to prevent another site acting as you. Same lifetime.
No analytics cookie, no advertising cookie, no third-party cookie, no local-storage identifier used for tracking. The product does use local browser storage for things you would expect to be local, such as your drawing layer on a chart and your scratchpad notes; that data stays in your browser.
10How we protect it
The mechanisms are described in detail on the security page, including their limits. In summary: encryption in transit everywhere, per-organisation envelope encryption for your connected credentials, tenant isolation enforced in the application and again in the database, opaque revocable sessions, redacted logs, an audit trail, encrypted backups with a rehearsed restore, and an explicit list of the certifications we do not hold.
If a breach affects your personal data we will notify you and the relevant authority within the periods the law requires, and we will publish what happened on the changelog rather than quietly patching it.
11Children
The service is for adults. It is not directed at children, we do not knowingly collect personal data from anyone under 18, and if we learn we have, we delete it.
12Changes to this policy
Material changes are announced by email and on this page before they take effect, recorded on the changelog, and the previous version stays available. Adding a sub-processor is a material change and is announced in advance.
13Contact
- Privacy requests and questions: privacy@portfoleo.ai
- Security reports: security@portfoleo.ai
- Everything else: support@portfoleo.ai
- Postal address: [TO BE COMPLETED]