Privacy Policy
Effective Date: September 21, 2026 • Last Reviewed: September 2026
1. Overview & Commitment to Financial Privacy
Portfolio Dashboard ("we", "our", or "the Platform") is engineered specifically for investors who prioritize data confidentiality. We recognize that investment records, net worth valuations, and transaction histories represent highly sensitive personal data. This Privacy Policy sets forth our strict parameters regarding data access, transient processing, client-side encryption, and user rights.
2. Data Architecture & Read-Only Synchronization
Unlike conventional fintech platforms that require full read/write brokerage account integrations, Portfolio Dashboard operates on a decoupled, read-only data model:
- Zero Storage of Banking or Trading Credentials: We never request, process, or store passwords, PINs, OTPs, or API keys for your demat accounts, brokerage accounts, or bank logins.
- User-Controlled Sheet Source: Portfolio holdings and daily transaction ledgers are sourced exclusively from Google Sheets managed by you. Access permissions are strictly read-only and may be revoked by you at any time directly through your Google account.
- In-Memory Aggregation: Portfolio calculations (e.g. net worth, asset allocation weightings, bond yields) are performed ephemerally in memory to render your dashboard, without permanent mirroring of underlying sheet rows in third-party relational databases.
3. Authentication & Session Security
To prevent unauthorized access to your dashboard:
- Cryptographic Sessions: User authentication is validated via signed, encrypted JSON Web Tokens (JWT) stored in HTTP-only, secure cookies that cannot be accessed by client-side scripts.
- Inactivity Timeouts: A continuous client session watcher detects idle interaction. After 10 minutes of inactivity, or upon reaching the maximum 30-minute session duration, the active session is securely terminated, requiring re-authentication.
- Single Active Session Store: Concurrent active session timestamps are tracked to prevent credential sharing and stale token replay attacks.
4. Client-Side Balance Masking (Privacy Mode)
Portfolio Dashboard features an integrated privacy mode. When toggled on, financial values across KPI cards, asset tables, and sector allocations are replaced with masked asterisks (••••••). This allows users to inspect trends, review allocation ratios, and share screens in public or professional environments without exposing net worth or absolute balance amounts.
5. Third-Party Data Providers & Processing
Yahoo Finance API: We query public market pricing data to calculate live percentage changes for Indian benchmark indices (e.g. NIFTY 50, NIFTY BANK) and individual equities. No personal identifiers or portfolio quantities are ever transmitted to Yahoo Finance.
Google Gemini AI: When you request AI-powered portfolio insights or risk analysis, aggregated statistics (e.g. sector allocation percentages, top positive/negative movers) are sent in an anonymized prompt structure. No personally identifiable information (PII), names, or external account IDs are transmitted.
6. Cookies & Tracking
We do not use advertising cookies, third-party tracking pixels, or cross-site tracking technologies. We use strictly essential cookies required for session authentication and CSRF protection, and local storage strictly for UI preferences (theme preference, font scale, and privacy toggle state).
7. Data Protection Rights & Inquiries
You maintain full sovereignty over your personal data. For questions regarding our data practices or to submit a data deletion request, please reach out to our privacy officer:
Privacy Officer: Portfolio Dashboard Data Governance
Email: privacy@portfolio-tracker.example.com
Address: 100 Financial Way, Bengaluru, Karnataka 560001, India