Privacy Policy

Last updated: October 9, 2026 · Effective: April 7, 2026

Portfolio Analytics ("we," "us," or "our") is operated by Petru Ceciltan, based in Israel. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our web application at www.portanalytic.com.

1. Information We Collect

1.1 Account Information

When you create an account, we collect:

  • Name and email address (provided directly or via Google OAuth)
  • Password (stored as a bcrypt hash, never in plain text)

1.2 Portfolio Data

You provide the following data when using the service:

  • Investment transactions (buy, sell, dividend entries)
  • Portfolio names and configurations
  • Cash flow entries (deposits, withdrawals)
  • Investment capital entries
  • Broker statement files you import: the CSV or XLSX file itself is kept for 7 days and then deleted automatically, so that import problems with a particular broker's format can be diagnosed and fixed. It is readable only by the site owner, and it is deleted immediately if you delete your account.
  • Files you send for an import template: if a file will not import and you choose to send it, from the import dialog or from Settings, then the file itself, the broker name and any note you add are kept until the template is built and deleted 7 days after that. They are never held longer than 30 days. Only the site owner can read them, and he is told by email when one arrives. Everything goes at once if you delete your account. You are told in the app and by email when the template is ready.
  • Bug reports you send: what you write in "Report a bug", with the screen you were on, the app version, your language, the window size and your browser, so the problem can be reproduced and you can be answered. Nothing from your portfolio is attached.
  • Invite links: if you sign up through a member's invite link, the code of that link is kept with your account, so that member can see how many people joined through it. They see a number, never your name or address.

1.3 Authentication Data

  • Two-Factor Authentication (TOTP): encrypted secret key for authenticator apps
  • Trusted Device tokens: hashed tokens stored for 30 days to skip 2FA on recognized devices
  • Session identifiers: for single-device session enforcement
  • WebAuthn/Passkey credentials: public keys for biometric authentication

1.4 Technical Data

We automatically collect:

  • IP address and approximate location
  • Browser type, device type, operating system
  • Pages visited and interaction patterns (via Google Analytics)
  • Referring URL

2. How We Use Your Information

PurposeLegal Basis (GDPR)
Providing the portfolio tracking serviceContractual necessity
Account creation and authenticationContractual necessity
Sending verification and password reset emailsContractual necessity
Sending up to two reminder emails after sign-up, each with an unsubscribe linkLegitimate interest
Reading and answering the bug reports you sendLegitimate interest
Two-factor authentication and securityLegitimate interest (security)
Analytics and service improvementConsent (via cookie banner)
Preventing fraud and abuseLegitimate interest

3. Third-Party Services

We use the following third-party services:

ServicePurposeData Shared
Google Analytics (GA4)Usage analyticsIP address, page views, device info
Google Tag ManagerTag managementPage interactions
Google OAuthSocial sign-inEmail, name (from Google)
Gmail SMTPTransactional and reminder emailsRecipient email, email content
The site owner's own server (European Union)The application and the PostgreSQL database it reads and writes, on an encrypted diskAll user data, server logs, request data
CloudflareDNS, content delivery and protection against attack, in front of every request to this siteIP address, request metadata
Aiven (PostgreSQL, European Union)One encrypted copy of the database taken each night and kept off the server, so an account can be restored after a failureAll user data
Yahoo Finance APIStock price dataStock symbols (no user data)

About the translation option. The language switcher is off by default. If you choose a language, the translation is loaded from this site and applied in your browser. No text from the page is sent to anyone. Portfolio names, holdings, instrument names, tickers, amounts, percentages, dates and your own name are never translated.

Your choice is remembered in your browser (localStorage pa_lang) so the page opens in that language next time. If you have an account it is also saved to it, so the same language applies when you sign in on another browser or device. Switching back to English clears the stored preference.

Language popularity. When a language is chosen in the switcher, we add 1 to a counter for that language so the menu can list the languages our visitors actually use first. The counter is the only thing stored: no account, no session, no IP address and no timestamp is recorded against it, so a choice cannot be traced back to the person who made it.

We do not sell, rent, or share your personal data with any third parties for marketing purposes.

4. Data Retention

Data TypeRetention Period
Account dataUntil account deletion + 7-day grace period
Portfolio & transaction dataUntil account deletion
Authentication tokens24 hours (JWT), 30 days (trusted devices)
Email audit logs30 days (auto-deleted)
Imported statement files7 days (auto-deleted)
Files sent for an import templateUntil the template is ready + 7 days, 30 days at most (auto-deleted)
Bug reports you sendKept so the problem can be fixed, and no longer linked to you once your account is deleted
Analytics data14 months (Google Analytics default)
Server logs30 days

When you delete your account, all associated data is permanently removed after a 7-day grace period. During this period, you can cancel the deletion by logging back in.

How to delete your account

You can delete your Portfolio Analytics account, and everything in it, at any time from the Android app or the website:

  1. Sign in to the app or at www.portanalytic.com
  2. Open Settings, then Delete account
  3. Confirm

If you cannot sign in, email [email protected] from the address on the account and ask for it to be deleted.

Deleting the account removes your profile, portfolios, transactions, cash entries, watchlists, notifications, sign-in history and any files you sent for an import template. They are removed for good after a 7-day grace period, and signing in again within those 7 days cancels the deletion.

You can also delete part of your data without closing the account: any portfolio, transaction, cash entry or watchlist entry can be deleted from its own screen in the app, and it is removed straight away.

Two things are kept for a limited time and then removed automatically: server logs, which record requests to the site, for up to 30 days, and the nightly off-site copy of the database, which is replaced by the next night's copy. Usage statistics in Google Analytics expire after 14 months.

5. Data Security

We implement the following security measures:

  • Encryption in transit: all data transmitted via HTTPS/TLS
  • Encryption at rest: the disk the database lives on is encrypted, and so is the nightly off-site copy
  • Password hashing: bcrypt with salt rounds
  • Two-factor authentication: TOTP-based, available on every account, and strongly recommended
  • Single-device sessions: only one active session per account
  • Rate limiting: protection against brute-force attacks
  • Content Security Policy: Helmet.js CSP headers
  • Parameterized queries: protection against SQL injection
  • XSS prevention: HTML escaping on all user-generated content

6. Your Rights (GDPR)

If you are located in the European Economic Area (EEA), you have the following rights:

  • Right to Access: request a copy of your personal data
  • Right to Rectification: correct inaccurate personal data
  • Right to Erasure: request deletion of your data ("right to be forgotten")
  • Right to Data Portability: receive your data in a machine-readable format (CSV export)
  • Right to Restrict Processing: limit how we use your data
  • Right to Object: opt out of analytics tracking
  • Right to Withdraw Consent: withdraw consent for analytics at any time

To exercise any of these rights, contact us at the email below. We will respond within 30 days.

7. Cookies & Tracking

We use the following cookies and local storage:

  • Authentication token (localStorage): keeps you logged in
  • Device trust token (localStorage): remembers trusted devices for 30 days
  • UI preferences (localStorage): card collapse states, column visibility
  • Google Analytics cookies: _ga, _ga_* for usage analytics
  • Language choice (localStorage pa_lang): set only if you pick a language in the translation switcher, so the page opens in that language next time. If you are signed in, the same code is stored on your account so the choice follows you to another browser. Choosing English again removes both.

8. International Data Transfers

Your data may be processed in:

  • European Union: the site owner's own server, which holds the application and the live database
  • European Union: Aiven, which holds the nightly off-site copy of the database
  • Cloudflare's global network: every request reaches the nearest of its locations before it is passed to the server
  • US: Google Analytics, Google OAuth

In short: what you type in stays in the EU. Your portfolios, transactions, prices and account details are held on a server in the European Union and copied each night to another one, also in the European Union. What leaves it is the usage analytics described above, and, only if you choose to sign in with Google, your email address and name.

Where data is transferred outside the EEA, we rely on adequacy decisions, Standard Contractual Clauses, or the service provider's compliance frameworks.

9. Children's Privacy

Portfolio Analytics is not intended for users under 16 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 16, we will delete it promptly.

10. Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours
  • Notify affected users without undue delay if the breach is high-risk
  • Document the breach, its effects, and remedial actions taken

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date. Continued use of the service after changes constitutes acceptance of the revised policy.

12. Contact Us

For privacy-related inquiries, data requests, or to exercise your rights:

  • Data Controller: Petru Ceciltan
  • Email: [email protected]
  • Website: ceciltan.com

If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority in the EU member state of your habitual residence.