Skip to main content
← Back

Privacy Policy

Last updated: May 25, 2026

1. Information We Collect

Information you provide. When you create an account we collect your email address, display name, and username. You may optionally add a profile picture and a preferred display currency. As you use the app, we store the portfolio data you enter — your holdings (tickers, share counts, average costs, purchase dates), brokerage accounts (names, types, institutions), options positions, realized sale history, and daily portfolio value snapshots.

Information collected automatically. For security, fraud prevention, and debugging, our servers automatically log technical data with each request: your IP address, your browser/device user-agent string, the endpoint accessed, response status, and timestamps. This is kept in a security audit log (see Data Retention below).

Screenshots you upload. If you use the AI scan feature, the brokerage screenshot you upload is processed to extract holdings and then discarded — we do not store the image after extraction.

2. How We Use Your Information

We use your information to:

  • Provide and maintain the portfolio tracking service
  • Authenticate your identity and secure your account
  • Fetch live stock prices and company data for your holdings
  • Process brokerage screenshots when you use the AI scan feature
  • Detect, prevent, and investigate abuse, fraud, and security incidents

We do not sell your personal information, and we do not use it for advertising or share it with advertisers.

3. Third-Party Services (Sub-Processors)

We rely on the following third-party providers to operate Prowis Invests. Each processes only the data needed for its function:

  • Supabase — Authentication and database hosting (Canada region). Your account credentials and portfolio data are stored here.
  • Amazon Web Services — Application hosting and content delivery. Web requests, including IP addresses inherent to internet traffic, are processed here.
  • Finnhub — Live stock market data. We send the ticker symbols you hold to retrieve prices and company profiles. No personal information is shared.
  • Anthropic (Claude) — AI-powered screenshot analysis. Uploaded brokerage screenshots are sent for processing and are not retained by Prowis afterward.
  • Sentry — Error monitoring. Receives application error reports that may include a random account identifier (not your name or email) and technical context; configured to exclude personal data by default.
  • Upstash — Rate limiting. Processes your IP address to enforce per-user request limits and prevent abuse.
  • exchangerate-api.com — Currency exchange rates. No personal information is shared.

A current sub-processor list is maintained at /sub-processors. Some of these providers (e.g., Sentry) may process limited technical data in the United States.

4. Data Retention

Your account and portfolio data is retained for as long as your account is active. If you delete your account, all associated data — holdings, accounts, options, sale history, and snapshots — is permanently removed.

Security audit logs, including IP addresses, are automatically deleted after 90 days.

5. Data Security

We implement industry-standard security measures including encrypted connections (HTTPS/TLS), row-level security policies on our database, and secure authentication via Supabase Auth. API keys are stored server-side and never exposed to the client.

6. Your Rights

Depending on where you live, you have the right to:

  • Access and export your portfolio data at any time (Profile → Export)
  • Update or correct your personal information
  • Delete your account and all associated data (Profile → Delete account)
  • Withdraw consent to optional processing

We will not discriminate against you for exercising any of these rights. If you have a concern we cannot resolve, you may lodge a complaint with the Office of the Privacy Commissioner of Canada, the Commission d'accès à l'information du Québec, or your local data-protection authority.

7. Cookies

We use essential cookies only — for authentication session management. We do not use tracking cookies or third-party analytics cookies.

8. Where Your Data Is Stored

Your account and portfolio data is stored in Canada. Certain sub-processors listed above may process limited technical data (such as error reports or request metadata) in the United States.

9. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any material changes by posting the new policy on this page with an updated revision date.

10. Contact

If you have questions about this privacy policy or wish to exercise your rights, contact us at support@prowis.ca.