Back to Home

Privacy Policy

Last updated: April 19, 2026

1. Introduction

Welcome to AssetsFlow. We respect your privacy and are committed to protecting your personal data. This privacy policy explains how we collect, use, and safeguard your information when you use our service.

2. Information We Collect

2.1 Personal Information

  • Email address (for account creation and authentication)
  • Account credentials (securely stored via Supabase)
  • Portfolio and financial data you enter into the application

2.2 Automatically Collected Information

  • Browser type and version
  • Device information
  • IP address (anonymized)
  • Usage data and analytics (only if you consent to analytics cookies)

3. How We Use Your Information

  • To provide and maintain our service
  • To authenticate your account and keep you logged in
  • To store and manage your portfolio data
  • To improve our service through analytics (only with your consent)
  • To communicate with you about service updates
  • To ensure security and prevent fraud

4. Cookies and Tracking

We use cookies to enhance your experience. Our cookie policy includes:

4.1 Essential Cookies (Required)

  • Authentication cookies: Keep you securely logged in (Supabase tokens)
  • Cookie consent: Remember your cookie preferences

4.2 Optional Cookies

  • Analytics cookies: Help us understand how you use the app (only with consent)
  • Functional cookies: Remember your preferences like theme settings

5. Data Storage and Security

Your data is stored securely using Supabase, a trusted platform with enterprise-grade security. We implement:

  • Encrypted data transmission (HTTPS/TLS)
  • Secure authentication mechanisms
  • Regular security audits
  • Access controls and data isolation

6. Your Rights (GDPR)

Under GDPR, you have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your data ("right to be forgotten")
  • Data portability: Receive your data in a machine-readable format
  • Object: Object to processing of your data
  • Withdraw consent: Withdraw cookie consent at any time

7. Data Retention

We retain your personal data only as long as necessary to provide our services. If you delete your account, we will delete your personal data within 30 days, except where required by law.

8. Third-Party Services

We use the following third-party services:

  • Supabase: Authentication and data storage
  • Market Data APIs: Real-time stock prices and financial data

9. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us at:
privacy@assetsflow.app