Privacy Policy
Last updated: July 29, 2026
Portfolio Copilot is built around a simple idea: your portfolio is personal. This policy explains exactly what we collect, why we collect it, who processes it on our behalf, and the control you have over it.
Portfolio Copilot provides AI-generated insights for informational purposes only and does not provide financial, investment, legal or tax advice. Nothing on this platform should be interpreted as a recommendation to buy, sell or hold any security. Always conduct your own research before making investment decisions.
1. Information we collect
We only collect what the product needs to work.
- Account details. Your email address, password credentials handled by our authentication provider, and the first name you enter during onboarding.
- Portfolio holdings. The stock symbols, quantities, average purchase prices, and portfolio names you add. This is used to personalise your briefs, news, and analysis.
- AI prompts and conversations. The questions you ask the AI Assistant and the responses generated for you, so conversations remain available to you within a session.
- Usage analytics. Aggregated, non-identifying information such as pages visited, feature usage, device type, and approximate region, used to diagnose problems and improve the product.
- Technical logs. Error reports, request timestamps, and IP-derived metadata generated automatically when you use the service.
- Cookies and local storage. See the Cookies section below.
We do not ask for, and do not want, your brokerage login credentials, bank details, government identifiers, or payment card numbers.
2. How we use your information
- To create and secure your account and keep you signed in.
- To generate your personalised daily brief, portfolio pulse, and news relevance scoring.
- To power AI features such as the Assistant, report insights, and 'why it matters' explanations.
- To operate, monitor, debug, and improve the service.
- To send transactional emails such as sign-in links, password resets, and email verification.
- To comply with legal obligations and enforce our Terms of Service.
We do not sell your personal information, and we do not use your holdings for advertising or share them with brokers, exchanges, or data brokers.
We never sell your portfolio holdings or investment data to advertisers, brokers, or data brokers.
3. AI features and how your data is processed
When you use an AI feature, the relevant context — typically your holdings for the selected portfolio, the news article or filing you asked about, and your prompt — is sent to a third-party AI model provider to generate a response. That context is transmitted over encrypted connections and used to produce your answer.
AI providers used by Portfolio Copilot are engaged as processors under terms that prohibit training their foundation models on our customers’ inputs or outputs. AI responses are generated probabilistically and can be incomplete or wrong; they are never a substitute for your own research or a licensed adviser.
You should verify important information using official company filings and other trusted sources before making financial decisions.
4. Third-party services
We rely on a small number of trusted providers to deliver the service. Each processes data only on our instructions.
- Backend, database, and authentication. Supabase hosts our managed Postgres database and handles account authentication and session management.
- AI model providers. Large language model providers accessed through our AI gateway generate summaries, briefs, and assistant responses.
- Hosting and delivery. Our application and edge functions are hosted on managed cloud infrastructure with a global CDN.
- Email delivery. Transactional emails (verification, password reset) are sent through an email delivery provider from our own verified domain.
- Market data and news sources. Public market data, exchange filings, and news feeds are retrieved from third-party sources. Requests for this data do not include your identity.
- Analytics. Privacy-respecting product analytics, where enabled, measure aggregate feature usage.
5. Cookies and similar technologies
We keep our use of cookies deliberately minimal. Portfolio Copilot does not use advertising, retargeting, or cross-site tracking cookies.
- Essential cookies and local storage. Strictly necessary for the service to function. They store your authentication session so you stay signed in, protect against cross-site request forgery, and maintain short-lived state such as the article you asked the Assistant to analyse. These cannot be disabled without breaking sign-in.
- Preference storage. Remembers lightweight choices such as your selected portfolio or last-used tab, so the app opens where you left off.
- Analytics cookies (where enabled). Used only to count aggregate page views and feature usage so we can see which parts of the product are useful. They do not build advertising profiles and are not shared with advertisers.
Managing your preferences. You can block or delete cookies at any time in your browser settings (typically under Privacy and Security), and most browsers let you clear site data for a single domain. Blocking essential cookies will sign you out and prevent the app from working. You can also use your browser’s private browsing mode, or send a “Do Not Track” / Global Privacy Control signal, which we honour for optional analytics. To request that we disable optional analytics for your account, email support@getportfoliocopilot.com.
6. Data retention
- Account details and portfolio holdings are retained for as long as your account is active.
- Cached news, briefs, quotes, and AI-generated report summaries are short-lived and purged automatically by a scheduled cleanup job.
- Technical and error logs are retained for a limited period for security and debugging, then deleted automatically.
- When you delete your account, your personal data and holdings are removed, except where we are legally required to retain records.
7. Security
All traffic is encrypted in transit with TLS, and data is encrypted at rest by our infrastructure providers. Access to your rows is enforced at the database level with row-level security policies scoped to your user account, so one user’s data cannot be read by another. Internal access to production data is restricted and logged. No system is perfectly secure, but we design for least privilege by default.
8. Your rights
Depending on where you live, you may have some or all of the following rights. We honour these requests regardless of jurisdiction.
- Access a copy of the personal data we hold about you.
- Correct inaccurate account information — most fields can be edited directly in the app.
- Delete your account and associated data.
- Export your holdings in a portable format.
- Object to or restrict certain processing, including optional analytics.
- Withdraw consent where processing is based on consent.
To exercise any of these rights, email support@getportfoliocopilot.com. We aim to respond within 30 days.
9. Children's privacy
Portfolio Copilot is not directed at children and is not intended for anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us with data, contact us and we will delete it.
10. International transfers
Our providers may process data in regions outside your own. Where that happens, transfers are covered by the providers’ standard contractual safeguards and encryption in transit and at rest.
11. Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected in the “Last updated” date above, and significant changes affecting how we use your data will be communicated by email or in the app.
12. Contact us
Questions, privacy requests, or concerns? Email support@getportfoliocopilot.com and we'll get back to you as soon as possible.