Privacy Policy
Last updated: September 2026
Informed Portfolio is built to need as little of your personal data as possible. Here's exactly what we collect and why, in plain English.
1. What we collect
Without an account: analyses run anonymously; we keep standard server logs (IP, timestamps) for security and abuse prevention, and we record product-usage analytics — which pages and features are used, and where visitors arrive from — using a first-party analytics cookie (details and how to opt out in §4). With an account: your email, an irreversibly hashed password (bcrypt — we never store or see the plain password), an optional display name, and the things you choose to save: portfolios (tickers + weights), analyses, and monitoring settings. If you write to us through the contact form we also store that message with your name and email address, so your enquiry survives an email-delivery failure (see §7 for how long).
2. What we use it for
To run the product: signing you in, saving and re-opening your work, sending the monitoring alert emails you set up, and enforcing plan limits. That's it.
3. What we never do
We do not sell your data, share it with advertisers, or build advertising profiles. We don't ask for — and you should never enter — brokerage credentials, account numbers, or balances. Portfolios here are ticker lists and percentages, not linked accounts. (One honest caveat: if you use the optional screenshot import, whatever is visible in the image you choose to upload is sent for reading — see §6.)
4. Cookies & analytics
We use only first-party cookies. Essential ones keep the app working: an httpOnly session cookie so you stay signed in, a short-lived security cookie during Google sign-in, and a small preference cookie that remembers which entry lane you picked. When you run the free tools without an account, we also set a functional device cookie (a random ID, kept for up to a year) and keep a 30-day usage counter against it, plus a looser counter keyed to a hashed, truncated form of your IP address, to enforce the free allowance of 10 runs per 30 days. These exist only to enforce that limit and to measure the feature (limit crossings are recorded against the random device ID): they are not used for advertising, never track you across sites, and elapsed counters are deleted automatically. Signing in removes the limit and the need for them. For analytics we use PostHog, which sets a first-party analytics cookie (plus a matching browser-storage entry) holding a random ID, so it can recognize a returning browser and measure which pages and features are used. It receives page paths, feature events, and referrer/campaign tags — never your name, email address, holdings, or balances. When you sign in, we link that activity to your account by an opaque account ID and your plan, so we can understand the product experience. It is first-party only — no cross-site or advertising tracking, and we never sell or share it. PostHog honors your browser's Do Not Track signal, and you can block or clear its cookie in your browser without affecting the app. We ask for your consent before setting this cookie — it isn't set unless you accept, and you can change your choice anytime from “Cookie settings” in the footer. We also use Cloudflare Web Analytics for aggregate traffic stats, which is cookieless (and needs no consent).
5. Service providers
We use a small number of processors to operate the product, and share the minimum each one needs: a market-data provider (receives the tickers being analyzed), an email delivery service (receives your email address and the contents of the emails we send you), our cloud hosting and database provider, and two product-analytics providers (PostHog — receives page and feature events and, once you sign in, an opaque account ID and plan, and sets a first-party analytics cookie; and Cloudflare Web Analytics — cookieless aggregate traffic; see §4). Neither receives your name, holdings, or balances.
6. The AI provider — including screenshot import
Two features send data to our AI provider (Anthropic's API), and it's worth being specific about what: AI Insights sends the condensed, derived figures from the analysis being explained — not your email address or account details. Screenshot import sends the image you upload, because reading the holdings out of it is the whole feature. Before that image leaves our servers we resize it to a pixel ceiling and re-encode it, which strips embedded metadata such as camera and location EXIF tags; we don't store the image afterwards, and we never use your data to train models. Anthropic processes it as our service provider under their API terms. A brokerage screenshot can show your name, an account number and your balances — so if you'd rather not send those, crop to the holdings table first, or type the tickers in instead. Screenshot import is entirely optional and every tool works without it.
7. Retention & deletion
Saved work is kept while your account exists. Deleting a portfolio, analysis, or monitor removes it. Messages you send us through the contact form are stored — your name, email address and the message itself — so that an enquiry is never lost if our email delivery fails; we keep them for up to 24 months and then delete them automatically. To delete your whole account and its data, or a contact message you've sent us, contact us at support@informedportfolio.com — we'll process it promptly. (Self-serve account deletion is on the roadmap.)
8. Security
Passwords are bcrypt-hashed, sessions are httpOnly cookies, traffic runs over HTTPS in production, and API keys are kept server-side only. No system is perfectly secure, but we follow standard practices and keep the data we hold to a minimum.
9. Changes & contact
If this policy changes materially we'll note it here with a new date. Questions: support@informedportfolio.com or the contact page.