Privacy

Privacy Policy

This policy describes the information Fillfolio collects and how it is used to provide portfolio tracking, brokerage sync, analytics, and billing.

Information we collect

We collect user data to operate Fillfolio. Fillfolio may collect account details such as your email address, authentication identifiers, portfolio names, saved assets, transactions, cash ledger entries, import preferences, settings, billing status, and support ticket messages. Fillfolio does not keep original uploaded files. Values you enter or import become account records. Payment card details are handled by Stripe and are not stored by Fillfolio.

How we use information

We use information to provide the app, protect account access, save portfolio records, process subscriptions, enable read-only brokerage sync, respond to support requests, improve reliability, prevent abuse, and comply with legal, tax, security, and payment obligations.

Connected brokerage data

If you connect a brokerage, Fillfolio may process connection identifiers, brokerage/institution names, account labels, account identifiers, balances, cash balances, positions, securities, quantities, prices, activity history, sync timestamps, and encrypted connection secrets or related sync credentials. This data is used to display synced holdings and activity in a read-only portfolio experience.

Blockchain wallet data

If you add a blockchain wallet, Fillfolio may process wallet labels, public addresses or xpubs, chain identifiers, token symbols, quantities, prices, balances, net worth summaries, sync timestamps, and provider responses needed to display read-only wallet holdings. Wallet addresses and xpubs are treated as privacy-sensitive account data.

Connected bank data and consent

If you connect a bank, Fillfolio may process institution names, account labels, account types and subtypes, currencies, one normalized balance and its current-or-available source, keyed duplicate-detection fingerprints, connection status, provider-authorized product and data-scope labels, consent records, and sync timestamps needed to show cash, cash-management balances, credit-card debt, and net worth. Before opening the bank connection flow, Fillfolio records your explicit consent, its version, purpose, requested products, timestamp, and the policy links shown to you. Fillfolio also requires recent first-factor identity reverification and a separate authenticator-app or single-use recovery-code verification before opening the connection flow. This bank-action step-up is operated by Fillfolio and does not change the authentication provider's session-factor state. The bank connection service handles institution credentials; Fillfolio does not receive or store bank usernames, passwords, or one-time authentication codes.

Authenticator and account security data

Fillfolio may process an encrypted authenticator seed, keyed hashes of single-use recovery codes, hashed assurances bound to your authenticated Clerk session and security-policy version, short-lived assurances bound to an intended bank action, replay counters, lockout and rate-limit state, reset timestamps, and pseudonymized security audit events. Account MFA is optional on every plan, while bank connection actions always require the shared factor. Authenticator and recovery codes are never intentionally logged. Recovery codes are shown once, and only protected hashes are retained. Security audit events are retained for up to 12 months.

Bank-data minimization

The connection is configured read-only. Fillfolio uses a short recurring initializer because a balance-only setup cannot establish a connection by itself, and the recurring product allows the provider to maintain updated account data. The connection provider or an institution may request broader permissions to establish and maintain that connection. Fillfolio limits its provider API calls to connection and institution metadata, account metadata and balances, connection updates, and revocation. It does not retrieve transaction history, account-login credentials, identity documents, or account numbers through the bank connection. It stores an encrypted connection token and minimized normalized institution, account, balance, consent, product-audit, and sync fields only. It does not initiate transfers or payments.

Stripe billing data

Stripe processes card details and may provide Fillfolio with customer identifiers, subscription status, invoices, payment status, billing email, and limited payment metadata. Fillfolio uses that information to activate plans, show billing status, and support payment questions.

Hosting and operational data

Hosting, security, and infrastructure services may process request metadata such as IP address, user agent, URLs, timing, security events, and operational logs needed to run and protect the service. User data is stored in private application databases. Fillfolio does not put account data in a public storage bucket.

Google Search Console and GA4

Google Search Console may process site ownership, indexing, query, click, impression, and technical search-performance information for fillfolio.com. If Google Analytics 4 is enabled and you grant analytics consent, GA4 may process page views, events, device/browser details, approximate location, and analytics cookie identifiers to help us understand product usage.

Google Sheets™ add-on data

The Fillfolio Google Sheets™ add-on may locally read, create, format, and update Fillfolio-managed ranges in the active spreadsheet. It does not scan other Google Drive™ files, request Google Drive™-wide access, or send spreadsheet cell contents back to Fillfolio. Portfolio reports move one way from Fillfolio into the spreadsheet you selected. Fillfolio may receive a pseudonymous spreadsheet identifier hash, the selected export scope, masked-value setting, row counts, sync status and timestamps, the add-on's declared permissions, and the signed-in Fillfolio account used to authorize the connection. The spreadsheet name is not sent or stored.

Browser extension data

The Fillfolio browser extension can look up a public market price after you explicitly select a confirmed ticker such as NVDA. That request sends only the normalized symbol. It does not send surrounding page text, form contents, page URLs, full page contents, or browsing history. Public price checks can work without a Fillfolio login. If you connect the extension to a paid Fillfolio account, the browser stores a revocable extension token locally. Fillfolio stores only a hash of that token. The toolbar dashboard and personal holding overlay then fetch read-only portfolio values for that account. You can disconnect from the popup or settings page to remove the local token and revoke it on Fillfolio. The extension uses browser storage for the token, privacy mode, selected-ticker helper preference, a cached dashboard snapshot, and a cached market-symbol index. It cannot trade, custody assets, place orders, or write to web pages.

Google API Limited Use

Fillfolio's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Fillfolio does not sell Google Workspace™ data or use it for advertising, lending or eligibility decisions, data-broker services, or artificial-intelligence and machine-learning model training. Google Workspace™ data is not transferred to third-party AI services.

AI features and third-party AI

Fillfolio does not run a conversational AI and does not train models on portfolio data or Google Workspace™ data. If you connect MCP, an approved AI client can read the same holdings, cash, liabilities, activity, and summaries already in your account. That client is a third-party data collector under its own policy. Revoke access from Settings. AI export is a ZIP you download. Fillfolio does not send that file to an AI. If you upload it to an AI, that AI's policy applies. Fillfolio does not generate self-harm or crisis responses because it does not chat. Third-party AI safety is the host's responsibility.

Third-party data collectors

Fillfolio relies on third-party data collectors including Clerk for authentication, Stripe for billing, read-only brokerage, bank, and wallet connection services, infrastructure and security services, Google services for search diagnostics and consent-based analytics, market-data services, and AI clients you authorize through MCP. Email you send to support is processed to answer that request. We do not sell personal information, and these parties process information as needed to support Fillfolio.

Processing locations

Fillfolio data is primarily processed using infrastructure in Europe and may be accessed by authorized personnel in the United States for security, support, and service operations. Service providers may process data in other jurisdictions under their contractual and legal safeguards. Fillfolio does not sell or license connected financial data.

Local storage, cookies, and consent

The app uses browser storage for preferences such as theme, selected portfolio, sidebar state, privacy mode, and table density. Authentication and payment providers may use cookies or similar technologies to keep sessions secure. GA4 analytics scripts are loaded only when a measurement ID is configured and analytics consent is granted in the browser.

Retention and deletion

We keep account and portfolio information while your account is active or as needed for security, billing, dispute handling, and legal obligations. Fillfolio does not keep original uploaded files. Imported values become account records. Account deletion requests go to [email protected]. When an account is deleted, Fillfolio revokes connections and removes connection tokens, Sheets metadata, extension token hashes, MCP grants, and billing access as described. When you disconnect a bank or delete your account, Fillfolio requests provider revocation and removes connected account, balance, and token data within 24 hours in the normal course. If revocation is temporarily unavailable, derived balance data is removed and the encrypted token may be retained solely for retry for up to seven days before local deletion. Minimized bank webhook metadata is retained for 30 days, sync and error logs for 90 days, and consent and security audit records for up to 12 months. If you use destructive account-security reset, Fillfolio immediately invalidates the authenticator factor, recovery codes, and outstanding assurances; removes or schedules revocation of connected banks; removes visible bank data; revokes active Fillfolio sessions; and applies a one-hour re-enrollment hold. No email or SMS notification is sent for that self-service reset. To request deletion or export help, contact [email protected]. For Google Sheets™, expired pending connection records are deleted within 24 hours, active minimized connection metadata is retained while connected, and add-on access tokens expire after 90 days unless rotated. Disconnecting immediately invalidates access and scrubs spreadsheet identifiers and token material; the minimized revocation record is deleted after 30 days. Google Sheets™ sync logs are deleted after 90 days. Account deletion removes all remaining Google Sheets™ connections and sync logs. For the browser extension, Fillfolio stores only a hash of the extension token while the connection is active. Disconnecting or account deletion revokes the token and removes the stored hash. Pending unused connection codes expire and are deleted in the normal course.

Security

Fillfolio uses HTTPS, protected routes, server-side access checks, encrypted sync secrets where applicable, and trusted providers for authentication, brokerage sync, infrastructure, and payments. No internet service can be guaranteed perfectly secure, but we design around reasonable safeguards.

Contact

Questions, deletion requests, export requests, or privacy concerns can be sent to [email protected].

Mailing address

Mailing address: 99 WALL ST #884, NEW YORK, NY 10005, USA. This address is for business correspondence. Customer support is fastest by email.