Privacy Policy
Last updated: June 2026
Informed Portfolio is built to need as little of your personal data as possible. Here's exactly what we collect and why, in plain English.
1. What we collect
Without an account: analyses run anonymously; we keep standard server logs (IP, timestamps) for security and abuse prevention. With an account: your email, an irreversibly hashed password (bcrypt — we never store or see the plain password), an optional display name, and the things you choose to save: portfolios (tickers + weights), analyses, and monitoring settings.
2. What we use it for
To run the product: signing you in, saving and re-opening your work, sending the monitoring alert emails you set up, and enforcing plan limits. That's it.
3. What we never do
We do not sell your data, share it with advertisers, or build advertising profiles. We don't ask for — and you should never enter — brokerage credentials, account numbers, or balances. Portfolios here are ticker lists and percentages, not linked accounts.
4. Cookies
One httpOnly session cookie keeps you signed in. We also use a privacy-respecting product-analytics service (PostHog), which may set a cookie to measure which pages and features are used so we can improve the product. We do not use advertising or cross-site tracking cookies, and we don't sell or share this data.
5. Service providers
We use a small number of processors to operate the product: a market-data provider (receives the tickers being analyzed), an email delivery service (receives your email address for alert digests), our cloud hosting/database provider, a product-analytics provider (PostHog, which receives anonymized usage events such as pages and features used), and — when you use AI Insights — Anthropic's API receives the (non-personal) analysis results being explained. We share the minimum needed for each function.
6. Retention & deletion
Saved work is kept while your account exists. Deleting a portfolio, analysis, or monitor removes it. To delete your whole account and its data, contact us at support@informedportfolio.com — we'll process it promptly. (Self-serve account deletion is on the roadmap.)
7. Security
Passwords are bcrypt-hashed, sessions are httpOnly cookies, traffic runs over HTTPS in production, and API keys are kept server-side only. No system is perfectly secure, but we follow standard practices and keep the data we hold to a minimum.
8. Changes & contact
If this policy changes materially we'll note it here with a new date. Questions: support@informedportfolio.com or the contact page.