Privacy Policy
Effective date: February 22, 2026 · Last updated: July 28, 2026
SmartFolio ("we", "us", or "our") operates the SmartFolio web and mobile application (the "App"). This policy explains what information we collect, how we use it, and your rights regarding your data.
1. Information We Collect
- Account information: When you sign up or sign in, we store your account identity details such as your name and email address as needed to operate your account securely.
- Financial data: The App stores portfolio data you enter, including stock and mutual fund holdings, buy/sell transactions, quantities, prices, broker commissions, dividends, and tax records.
- Email forwarding (optional): If you enable auto sync features, you may set up forwarding rules in your own email account to send brokerage confirmations to our import inbox. We do not request direct inbox credentials, and we only process emails you explicitly forward.
- Document parsing: To read trades and dividends out of forwarded brokerage emails, attached PDFs, and portfolio screenshots, the content and its extracted text are sent to OpenAI via the OpenRouter API gateway. We ask for your permission in the App before this happens — a per-file confirmation in the statement import flow, and a disclosure in the email auto-sync setup before you create any forwarding rule.
- Session information: We may store basic device/session details (for example device type and OS version) to help you manage active sessions and account security.
- Push notifications: If you allow notifications, we store a device push token so we can send you alerts you have enabled (for example dividend announcements and your daily brief). You can turn notifications off at any time in your device settings or in the App.
2. How We Use Your Information
- To create and manage your account.
- To store and display portfolio, transaction, and dividend records.
- To parse brokerage trades/dividends from messages you explicitly forward.
- To process subscription status and premium feature access where applicable.
- To send service notices (for example account security alerts).
- To diagnose issues, improve reliability, and improve App quality.
3. AI Coach and Third-Party AI Providers
The App's optional AI features work by sending relevant portfolio data to a third-party AI provider that generates the response. This covers the ask-anything chat, the score explainer and score chat, the daily read card, and the daily morning brief — as well as the document parsing described in Section 1.
We ask for your explicit permission before any of your data is sent to the AI provider. You can grant or withdraw this permission at any time in the App's settings. If you do not consent, these features are disabled and no portfolio data is sent to the AI provider; the rest of the App continues to work normally. Withdrawing consent also stops the automated features described below.
- What we send: the holdings, transactions, quantities, prices, cost basis, and portfolio composition relevant to your request, along with the question you ask the coach. We do not send your name, email address, phone number, or password.
- Who we send it to: OpenAI, accessed via the OpenRouter API gateway. Data sent to power these features is processed by OpenAI and OpenRouter under their own privacy and data-processing terms, and is not used to train their models. See openai.com/policies/privacy-policy and openrouter.ai/privacy.
- Automated features: if you have consented and have notifications enabled, we generate a daily morning brief for you. Producing it sends the same categories of portfolio data to the AI provider on a schedule, without you opening the App. It is only ever generated for accounts that have granted AI consent, and you can stop it by withdrawing consent or by turning the daily brief off in notification settings.
- Why: solely to generate the coaching response, brief, or extracted records you requested. We do not use this data for advertising, and we do not sell or share it for marketing.
- Features that do not use your data: general market commentary, company announcement summaries and similar market-wide content are generated from public exchange data only, and contain no personal or portfolio information.
4. Other Third-Party Services
We use the following third-party service providers to run the App. Each processes data only to deliver its part of the service, under its own privacy terms, and each is contractually or by policy required to protect your data to a standard equivalent to this policy. We do not sell, rent, or share your personal or financial data with third parties for advertising or marketing purposes.
- OpenAI and OpenRouter — the AI features and document parsing described in Sections 1 and 3. openai.com/policies/privacy-policy, openrouter.ai/privacy
- Supabase (self-hosted on Hetzner infrastructure in Germany) — authentication, database, and file storage. This is where your account and portfolio data live. hetzner.com/legal/privacy-policy
- Apple and Google — Sign in with Apple and Google Sign-In, when you choose to sign in that way. We receive your name and email address from the provider you use. apple.com/legal/privacy, policies.google.com/privacy
- RevenueCat — subscription management and in-app purchase validation. It receives a pseudonymous user ID, subscription status, and device information. revenuecat.com/privacy
- PostHog — product analytics. We record screen views and feature-usage events linked to your user ID and email so we can diagnose issues and improve the App. We do not send symbols, holdings, amounts, prices, or the contents of your questions to analytics. posthog.com/privacy
- Expo push notification service and the Apple and Google push gateways — delivery of the notifications you have enabled.
- Cloudflare — email routing for the optional auto-sync inbox, and network protection. Account numbers are redacted at this layer and raw forwarded emails are not stored. cloudflare.com/privacypolicy
- Resend — delivery of service and announcement emails. resend.com/legal/privacy-policy
5. Data Retention
We retain account and portfolio data while your account is active. If you request account deletion, we will delete personal and financial records within 30 days unless retention is required for legal, security, or compliance reasons.
Raw forwarded emails are not stored — only the trade and dividend records extracted from them, which are kept as part of your portfolio data. Prompts sent to the AI provider are retained by that provider under its own terms and are not used to train its models.
6. Your Rights
- Access the personal data we hold about you.
- Correct inaccurate profile data.
- Grant or withdraw consent for AI data sharing at any time in the App's settings. Withdrawing it also stops the automated daily brief.
- Delete your account and associated data by contacting us.
- Stop email forwarding any time by removing your forwarding rules.
- Export your portfolio and transaction data where export tools are available.
7. Data Security
We use industry-standard security controls, including encryption in transit, authenticated APIs, and access controls. No platform can guarantee absolute security, but we continuously work to protect your information.
If a data breach affects your personal information, we will notify affected users within 72 hours of becoming aware of it.
8. Children's Privacy
The App is not directed at children under 13. We do not knowingly collect personal information from children under 13.
9. Contact Us
For questions, data requests, or support, contact us at hello@smart-folio.app.
10. Changes to This Policy
We may update this policy from time to time. For material changes, we will provide notice before changes take effect. Continued use of the App after the notice period means you accept the updated policy.
