Privacy Policy
Portfolio Dashboard · Last updated: 31 July 2026
Portfolio Dashboard ("the App") is a personal investment tracking tool built for Indian investors. This policy explains what data we collect, where it is stored, and what we do — and don't do — with it. It covers both the native apps (Android, iOS, macOS) and the browser preview at portfoliodashboard.pages.dev/app/.
1. Data We Collect
| Data Type | Purpose | Stored Where |
|---|---|---|
| Email address | Google Sign-In for authentication and subscription management | Firebase Authentication |
| Broker API credentials | Fetching holdings and trades from your broker | Device Keychain/Keystore (native). In memory only, never persisted, in the browser preview |
| Portfolio data (holdings, trades, NAV, goals) | Displaying your portfolio, calculating P&L and returns | Your device. In the browser preview, your browser's local storage for that session |
| Subscription status | Managing your free trial or paid plan | Firebase Firestore, keyed by your email |
| Payment submission (plan, amount, timestamp) | Verifying a UPI payment you have made | Firebase Firestore |
| Backup files you choose to upload | Restoring your data on another device | Your Google Drive, or our Firebase Storage if you pick that destination |
2. How Your Data Is Stored
- Locally on your device — portfolio data (holdings, trades, mutual funds, NPS, EPF, gold, fixed deposits, insurance, goals) is stored on your device. It doesn't leave the device unless you export it or turn on a backup.
- Encrypted backups — full backups and credential exports are encrypted with AES-256 using a passphrase you choose. We cannot decrypt them. Keep the passphrase safe: without it, a backup cannot be recovered by anyone, including us.
- Broker credentials — held in your device's secure storage (iOS Keychain, Android Keystore, macOS Keychain) and never sent to our servers. In the browser preview they live in memory only and are gone on refresh.
- Firebase — your email address, trial and expiry dates, plan, and payment submissions are stored in Firebase Authentication and Firestore. This is what the paywall checks.
- Firebase Storage (optional) — if you select Firebase Storage as your backup destination, encrypted backup files are uploaded to our Firebase project under
backups/<your email>/. The contents are encrypted with your passphrase, so we can store the file but cannot read it.
3. Google Drive Access
Drive backup and shared-portfolio sync are optional. When you enable either, the
App requests the drive.file scope, which is the narrowest Drive scope
Google offers: it grants access only to files the App itself creates, plus any file
you explicitly choose in the Google file picker. The App cannot list, read, or
modify the rest of your Drive.
- Automatic and manual full backups are written to your Drive encrypted with your passphrase.
- Some per-asset sync files (for example US stocks and mutual fund holdings) are written to your own Drive as plain JSON so you can inspect or move them yourself.
- Shared-portfolio sync works through a file in Drive that you share with the people you choose. Sharing is done by you, in Drive, and can be revoked there.
- Drive files are yours. Deleting them in Drive removes them; we hold no copy.
- On macOS, Google Drive backup is unavailable (an OAuth client limitation). In the browser preview, Drive access is restore-only and lasts for the current session.
4. What We Do NOT Do
- We do not sell, share, or rent your data to any third party.
- We do not use analytics or tracking SDKs. There is no Google Analytics, Firebase Analytics, Crashlytics, or Mixpanel in the App, and no analytics or cookies on this website.
- We do not display advertisements.
- We do not have access to your broker credentials, your passphrase, or the contents of your encrypted backups.
- We do not read your portfolio data. Where a file passes through infrastructure we run, it is encrypted with a key we don't hold.
5. Third-Party Services
- Firebase Authentication, Firestore and Storage — Google Sign-In, subscription records, and optional backup storage. Subject to Google's privacy policy.
- Google Drive — optional backup and shared-portfolio sync, using the
drive.filescope described above. - Yahoo Finance — live stock prices. Only ticker symbols are requested; no personal data is sent.
- AMFI / MFAPI.in — mutual fund NAV data. Only scheme identifiers are requested.
- Broker APIs (mStock, Fyers, Zerodha) — used to fetch your holdings when you provide credentials. In the native apps this traffic goes directly from your device to the broker.
- Cloudflare Pages — hosts this website and the browser preview, and handles standard request logging (including IP address) as part of serving traffic.
- Our CORS proxy — browsers block direct calls to Yahoo Finance and AMFI, so in the browser preview those two requests are relayed through
/api/proxy/on this site. The relay sees the ticker or scheme being requested and the connection's IP address. It carries no credentials and no portfolio data, and it is not used by the native apps. - Your UPI app — payments are made through your own UPI app. We never see your bank or card details; we only record that a payment for a plan was submitted.
6. Data Deletion
You can delete your data at any time:
- Sign out — clears your authentication session.
- Uninstall the App — removes locally stored data (portfolio, credentials, trade caches). Backups you uploaded remain until you delete them.
- Delete backups — remove the files from your Google Drive, or ask us to delete anything under
backups/<your email>/in Firebase Storage. - Request account deletion — email problemsolverdeveloper@gmail.com and we will delete your Firebase account, subscription record, payment submissions, and any Firebase Storage backups within 7 days.
7. Children's Privacy
Portfolio Dashboard is not intended for use by children under 18. We do not knowingly collect data from minors. If you believe a child has provided us with personal information, contact us and we will delete it.
8. Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Continued use of the App after changes constitutes acceptance of the updated policy.
9. Contact
Questions about this policy or your data: problemsolverdeveloper@gmail.com