Privacy Policy
Last updated: 2026-06-06
What we collect
- Account data: email address, optional display name and avatar.
- Authentication metadata: IP address and device/browser fingerprint of recent sessions, retained ≤180 days.
- Application data: dashboards, watchlists, paper-trading state, AI Copilot conversations, deep-research outputs, ML strategies, RL backtests, and other content you create.
- Brokerage connection data (if you link a broker via SnapTrade): an opaque per-user secret used to sign broker requests, plus connection status events. The secret is encrypted at rest with AES-256.
What we do not collect
- We do not load third-party analytics, advertising, or tracking pixels by default.
- We do not sell, rent, or trade your data.
- We do not collect biometric or government-ID data.
Why we collect it (lawful basis)
- Contract performance — to provide the service you signed up for.
- Legitimate interest — to detect abuse, prevent fraud, and keep the platform working.
- Legal obligation — to retain records where finance regulations require it.
Where it lives
Application data is stored in Supabase (US-East-1) with row-level security ensuring you can only read your own records. Static assets and serverless functions run on Vercel (US-East-1). Brokerage data is processed via SnapTrade. AI Copilot prompts are sent to the LLM provider configured for your tenant.
If you access the service from outside the US, your data may be transferred to and processed in the United States. We rely on Standard Contractual Clauses where required.
How long we keep it
- Copilot messages: 365 days, then deleted automatically.
- Activity log: 730 days.
- Webhook events: 180 days.
- Sessions: 180 days from last activity.
- Brokerage balance snapshots: 730 days.
- All other application data: until you delete it or your account.
Your rights
- Access: export everything we hold on you in JSON from Profile → Data Management → Export.
- Deletion: delete your account from Profile → Delete Account. We hard-delete the auth record and cascade-wipe every linked row; SnapTrade is torn down in the same flow.
- Correction: edit your profile fields directly in Profile.
- Sign out everywhere: revoke all active refresh tokens from Profile → Sessions.
- Object / restrict: contact us; we will honour valid requests within 30 days.
Cookies
We set first-party cookies and localStorage entries strictly necessary for authentication (Supabase session) and for remembering your theme preference. We do not set advertising or analytics cookies.
If you opt to enable Sentry for error reporting (private project setting), Sentry sets its own cookie on its origin only, never on ours.
Security
We enforce HSTS, CSP, X-Frame-Options DENY, COOP, and per-user row-level security on every database table. Brokerage credentials are encrypted at rest with a key stored in Supabase Vault. Authentication uses PKCE; MFA (TOTP) is supported with one-time recovery codes.
Contact
Privacy questions or rights requests: privacy@finvision.app. For a data-protection complaint, contact your local supervisory authority.