Legal
Privacy Policy
We hold your account, your portfolios, and the research you create with them. We do not sell personal information and we run no advertising trackers. When a paid subscription begins, our servers may tell Meta that it did — a hashed email and the fact of the purchase, never what you research — and you can switch that off. We never store your IP address or your card details. This page covers both the website and the Portfolio Lens application, which share one data controller.
Effective
Contents
- Who we are, and what this covers
- The short version
- Personal information we collect
- How we use it, and on what legal basis
- Artificial intelligence, and what never reaches a model
- Who we share it with
- International transfers
- How long we keep it
- What survives deletion, and why
- Your rights and choices
- Security
- Administrator access to your account
- Children
- Changes to this policy
- How to contact us
1. Who we are, and what this covers
Portfolio Lens, Inc. is a Delaware corporation based in the United States. We are the data controller for personal information collected through https://getportfoliolens.com and through the Portfolio Lens application at https://app.getportfoliolens.com. One company, one document; where a practice differs between the marketing site and the application, this policy says so explicitly rather than leaving you to guess.
For any privacy question or request, contact insight@getportfoliolens.com. That is the address for all data-subject requests and it is monitored by a person.
2. The short version
This section is a summary and is not a substitute for the detail below, but nothing below contradicts it.
| Question | Answer |
|---|---|
| Do you sell my personal information? | No. We never have. We do share a narrow conversion record with Meta when a paid subscription begins — see 3.3 and 10.3 — and you can switch that off under Account → Data & Privacy. |
| Do you store my card number? | No. Payment happens on a page hosted by Stripe. We hold references to your Stripe customer and subscription — not a card number, not an expiry date, and not the last four digits. |
| Do you store my IP address? | No. Where we need to tell visitors apart, we store a salted one-way hash of the address. |
| Does the marketing website track me? | No. It sets no cookies, runs no analytics, and contains no advertising pixel or third-party tracker. |
| Does the application measure how I use it? | Yes, in a form that carries no identity — see 3.3. A second, richer stream that could be linked to you is off unless you switch it on. |
| Do my portfolio holdings leave your systems? | No. They are never sent to an AI model provider or to any other third party. See 5. |
| Can I get my data out, and can I delete it? | Yes, both, from Account → Data & Privacy, without emailing anyone and without charge. |
3. Personal information we collect
3.1 What you give us
- Your account. Your email address, an optional display name, and your time zone. The time zone exists so a daily summary arrives at a sensible hour for you.
- Your credentials. Authentication is handled by Amazon Cognito, which stores your password hashed. We never see or hold your password in any form. We hold the fact that you have enrolled an authenticator app or a passkey — not the secret behind either.
- Your subscription. If you subscribe, you enter your card details directly into a checkout page hosted by Stripe. We store identifiers that let us ask Stripe about your subscription — a Stripe customer reference, a subscription reference, the price you are on, and its status and renewal date.
- Your portfolios and holdings. Portfolio names, and for each position a ticker, a quantity or weight, and any label you add. If you import a file we keep its name and the rows we parsed from it, and we keep the successive versions of a portfolio so you can see what changed. This is the most sensitive information in the product and it is treated accordingly: every route that reads it answers 404 rather than 403 to anyone who is not its owner, so the existence of another member's portfolio is not disclosed by the difference.
- The research you create. Company analyses you start, notes you write on them, forecasts you record and lock, tickers you watch, themes you track or retire, podcast channels you follow, and the questions you put to a council review together with the memos and syntheses it returns.
- Your settings and choices. Whether you want the daily summary and what it should cover, your saved sandbox defaults, and a dated record of every consent you granted or withdrew.
- Which advertisement brought you here, if one did. When you arrive from one of our advertisements the link carries our own campaign labels — the name we gave the campaign and the advertisement, nothing about you — and if you go on to create an account we record them against it so we can tell which campaigns are worth running. We do not store the click identifier that Facebook or Google attaches to such a link, because that is an identifier those companies can tie back to you. Arriving without an advertisement records nothing, and the labels are never shared with the advertising platform or anyone else.
- Your country, as a class. When you start a checkout or open Account → Data & Privacy, our edge network tells our servers which country your connection came from, and we record one of four classes — United States, the UK and the European Economic Area, elsewhere, or unknown — together with the version of this policy in force at the time. Nothing finer than the class is kept, and never an address. It decides one thing: whether the advertising measurement described in 3.3 applies to you by default.
- Your messages to us. Anything you send when you contact us for support.
3.2 What is created as you use the product
Using Portfolio Lens produces records that are about you even though you did not type them: the jobs run on your behalf and their outcomes, the notifications queued for your daily summary, whether an email we sent you was delivered, bounced, or opened, one-off export requests and the address you asked us to send them to, and the audit record of any administrator who viewed your account.
3.3 What is collected automatically
The marketing website collects nothing in your browser. It sets no cookies of any kind, stores nothing in local or session storage, and loads no analytics, advertising pixel, or third-party tracker. Requests to it are logged by our content-delivery network and load balancer for security and abuse investigation in the ordinary way.
The application has two separate measurement streams, and the difference between them matters.
- Application health measurement, which is on by default and carries no identity. We record which screen was opened, which action was taken, whether it succeeded, how long it took, and any error code. Each event is tied to a random correlator minted in your browser tab that dies when you close the tab and is stored in no cookie and joined to no account. There is no field in which an account identifier, an email address, a portfolio name, or a ticker could be recorded — the accepted shape is a closed list of outcomes, counts, timings and error codes, and anything else is discarded before it is written. This stream is not consent-gated, because identity is removed rather than gated. Records are deleted after 14 days.
If your browser sends a Global Privacy Control signal we honour it here anyway, even though anonymous operational data would not strictly require it, and the correlator is discarded rather than reused if the signal appears part-way through a visit. - Product analytics that could be linked to you, which are off until you turn them on. This is a distinct stream, it is default-deny, and nothing is collected under it unless you switch it on under Account → Data & Privacy. A Global Privacy Control signal keeps it off regardless of that setting, and we record that we saw the signal as well as acting on it.
Advertising and conversion measurement. We advertise Portfolio Lens on Meta's platforms. We do not use the Meta Pixel or any Meta software to track your activity on this website or inside the application, and no request to a Meta domain is ever made from your browser because of anything you do here. Instead, when an eligible paid subscription begins, our servers may send Meta two conversion events through its Conversions API — one when a subscription checkout completes with a card, and one when the first payment on that subscription succeeds — so that we can tell which of our advertisements are worth running. What that integration is permitted to send is fixed in code and is limited to: the fact and time of the event, an opaque event identifier we generate, the currency and the amount we kept (net of tax), a hashed copy of your email address as the matching key, and, on the checkout event only, your browser's user-agent string because Meta requires it for that kind of event. We do not send your name, your account identifier, your portfolios or holdings, the securities or tickers you research, your notes, forecasts or questions, your payment details, your IP address, or any advertising click identifier. Whether it applies to you at all is decided by the country class in 3.1 and your choice: for members whose connection came from the United States it is on unless you switch it off or your browser sends a Global Privacy Control signal; for everyone else it is off unless you switch it on. The switch is under Account → Data & Privacy. Meta processes what it receives under its own terms and privacy documentation. The user-agent string is deleted within seven days; the record of each event — the identifier, the decision we made and Meta's response, never an email in any form — is kept for thirteen months.
3.4 What we deliberately do not collect
- Your IP address. Where we need to distinguish one visitor from another for abuse protection or to attach to a consent record, we store a salted one-way hash and never the address. The component that produces it refuses to run when the salt is missing, so there is no configuration in which a raw address is written by accident.
- Your card details. They are entered on Stripe's own page and never reach our infrastructure. This is why checkout is hosted rather than embedded.
- Identifying fields in our logs. Logs are filtered before they are written; email addresses and similar fields are replaced with a marker. Where a log line needs to name a member it uses an internal account identifier, never an email address and never the identifier your sign-in provider uses.
- Anything bought from a data broker. We do not enrich, append to, or verify your record against any outside source.
4. How we use it, and on what legal basis
| Purpose | Legal basis (UK/EU GDPR) |
|---|---|
| Running your account, and taking payment for your subscription | Performance of a contract (Art. 6(1)(b)) |
| Producing the analyses, factor and exposure runs, forecasts, grades and council reviews you ask for | Performance of a contract (Art. 6(1)(b)) |
| Confirming your email address, and sending security and account notices | Performance of a contract / steps taken at your request (Art. 6(1)(b)) |
| Sending the daily summary and any other non-essential email | Your consent (Art. 6(1)(a)), withdrawable at any time |
| Measuring the health of the application using records that carry no identity | Our legitimate interest in operating a working service (Art. 6(1)(f)) |
| Product analytics that could be linked to you | Your consent (Art. 6(1)(a)), off unless granted |
| Measuring whether our advertising works, by telling Meta when a paid subscription begins | Your consent (Art. 6(1)(a)) where you are in the UK or the EEA — off unless you turn it on. Our legitimate interest in measuring our advertising (Art. 6(1)(f)) elsewhere, with a right to opt out at any time. |
| Protecting the service from abuse, fraud and automated attack | Our legitimate interest in securing the service (Art. 6(1)(f)) |
| Keeping records of consent, unsubscribes, suppressions and administrator access | Compliance with a legal obligation (Art. 6(1)(c)) |
| Keeping billing records for tax and accounting | Compliance with a legal obligation (Art. 6(1)(c)) |
We do not use your personal information for any purpose materially different from these without telling you first.
5. Artificial intelligence, and what never reaches a model
Portfolio Lens uses large language models from third-party providers to draft company analyses, summarise podcast episodes, and run council reviews. Being specific about what those providers receive is more useful than a general assurance, so:
What is sent to a model provider is public source material. Company filings from the SEC, earnings-call transcripts, podcast transcripts, and the prompt templates we write. That material is identical whichever member asked for it, and it is requested per company rather than per member.
What is never sent to a model provider: your name, your email address, your account identifier, your portfolio names, your holdings, your quantities or weights, the notes you write, or the forecasts you record. Your holdings are not batched into a request to a market-data provider either, because a request shaped like one member's portfolio would itself reveal that portfolio.
We have not yet completed a written verification that every model provider excludes what we send from training, and we would rather say so than imply otherwise. Until that verification is recorded, the boundary above is enforced on the data instead of relying on the assurance: member-authored text is not placed in a prompt at all.
No decision about you is made solely by automated means. The models draft research about companies and grade forecasts against published outcomes. Nothing in the product profiles you, scores you as a person, or makes a decision producing legal effects for you, so the right to human review of an automated decision does not arise. Nothing produced by the product is investment advice, and the disclaimer that says so is part of the terms.
6. Who we share it with
We do not sell your personal information, and we never have. We do not share it with data brokers or enrichment services, and there is no advertising pixel on the website or in the application. The one advertising network that receives anything is Meta, in the narrow, server-side form described in 3.3 — and only when your country class and your choice allow it.
The organisations that process personal information on our behalf, or receive it in their own right, are:
| Recipient | What they do | What reaches them |
|---|---|---|
| Amazon Web Services | Hosting, database, file storage, queues, outbound email, logs, and the sign-in system that holds your password | Everything. AWS acts as our processor under contract and does not use it for its own purposes. |
| Stripe Payments Inc. | Subscriptions, hosted checkout, the billing portal, invoices | Your email address, your account identifier, and the card details you enter on Stripe's own page. Stripe is also a controller in its own right for fraud prevention and regulatory reporting, so its own privacy policy governs that use. |
| Meta Platforms, Inc. | Advertising network — measuring which of our advertisements led to paid subscriptions | Only when a paid subscription begins and only if your country class and your choice allow it: the fact and time of the event, an opaque event identifier, the currency and amount we kept, a hashed copy of your email address and, on the checkout event, your browser's user-agent string. See 3.3 for what is never sent. Meta is a controller in its own right for what it does with that information under its own terms. |
| Anthropic, OpenAI, Google, xAI | Large language model inference | Public filings, transcripts and prompt templates only — see 5. No member-identifying or member-authored content. |
| Financial Modeling Prep | Market prices and company fundamentals | Ticker symbols. Never your identity, and never your portfolio as a set. |
| SEC EDGAR | Primary source for filings | A declared identifying user-agent for our systems and the documents we request. A public government service; no account and no member data. |
| GitHub | Source hosting, continuous integration, deployment identity | Source code and build logs. No member data. |
We may also disclose information to professional advisers where necessary for the services they provide to us, to an acquirer or successor in a merger or sale of the business, and to authorities where we are legally compelled. Where we are compelled, we will tell you unless we are prohibited from doing so.
We deliberately use no third-party analytics service, no customer-data platform and no session-replay tool. The only advertising network that receives anything from us is Meta, in the form described above. Should that ever change, this policy changes on the same day and not afterwards.
7. International transfers
Our infrastructure is in the United States and your information is stored there. If you are in the United Kingdom, the European Economic Area, or Switzerland, that transfer is made under the European Commission's Standard Contractual Clauses together with the UK Addendum where applicable. Those jurisdictions may not provide the same protections as your home country's law.
Portfolio Lens, Inc. has not appointed a representative in the European Union under Article 27 GDPR. You can reach us directly at insight@getportfoliolens.com and we will respond within the statutory time limits.
8. How long we keep it
Retention is set per record type rather than by a single blanket period, and the periods below are the ones our systems actually enforce.
| What | How long |
|---|---|
| Your account, portfolios, holdings, analyses, notes, forecasts, council reviews and settings | For as long as you have an account. Removed when you delete it. |
| Billing and subscription records | 7 years, for tax and accounting, with the link to your account severed on deletion |
| Record of a privacy request and that we honoured it | 7 years, with the link to your account severed |
| Administrator access audit records | 7 years |
| Email delivery and engagement records | 2 years |
| Queued notifications, and the job history of work run for you | 90 days |
| Links we email you, such as an export download | 90 days, and the download link itself expires within minutes |
| Export requests and the address you asked us to send one to | 30 days |
| Application-health records that carry no identity | 14 days |
| The generated daily report about application health | 13 months. It describes the application and names no individual. |
| Your browser's user-agent string, held from a checkout until its conversion event is sent | 7 days |
| The record of each advertising conversion event — its identifier, the decision we made and Meta's response, never an email in any form | 13 months, with the link to your account severed on deletion |
| Your country class and the policy version it was recorded under | For as long as you have an account. Removed when you delete it. |
| Consent records | Kept as evidence of consent, with the link to your account severed on deletion |
| Unsubscribe and suppression records | Kept indefinitely — see 9 |
9. What survives deletion, and why
Deleting your account removes your account and everything you created with it. Four things deliberately outlive it, and we would rather name them than let you discover them:
- Your email address on our suppression list, if you unsubscribed. An opt-out has to outlive the account or deleting and recreating an account would become a way to undo an unsubscribe. This is a legal requirement as well as the right behaviour.
- The record that you made a privacy request and that we honoured it, with the link to your account severed. Proof that a deletion happened cannot itself be deleted.
- Billing records, for the tax period we are required to keep them, with the link to your account severed. Cancelling your subscription with Stripe and asking Stripe to erase its own customer record is a separate request to Stripe, because Stripe is a controller in its own right.
- Administrator access audit records. An audit trail that the subject of it can erase is not an audit trail. These carry identifiers only, never identity.
Everything else is removed. Application-health records are unaffected by deletion for the simple reason that they were never linked to you and cannot be found by your identity.
10. Your rights and choices
10.1 Exporting and deleting, without asking us
You can export everything we hold about your account, and delete your account, from Account → Data & Privacy. You do not need to email us, you do not need to give a reason, and there is no charge. An export is prepared in the background and delivered through a private link that expires a few minutes after you request it.
Deletion is not instant, on purpose. When you request it we sign you out everywhere immediately and schedule the deletion for seven days later, so a mistaken or malicious request can be undone. You can cancel within that window by signing in again. After it runs, deletion is permanent and we cannot recover the account.
10.2 Your rights
Depending on where you live, you may have the right to know what personal information we hold and why, to receive a copy of it in a portable form, to correct it, to have it deleted, to object to or restrict our processing of it, and to withdraw consent at any time. Withdrawing consent does not affect processing carried out before you withdrew it. You are entitled to exercise these rights free from discrimination.
10.3 If you are in California — Your Privacy Choices
You have the right to know, to delete, to correct, to receive a portable copy, and to limit the use of sensitive personal information. You also have the right to opt out of the sale of personal information and of sharing it for cross-context behavioural advertising.
We do not sell personal information. We do share it in one narrow form: when a paid subscription begins, our servers may send Meta the conversion record described in 3.3 — a hashed email address and the fact of the purchase, never what you research — which counts as sharing for cross-context behavioural advertising under California law. There is still no advertising pixel on this website or in the application, and nothing is shared because you merely visited or browsed.
Do Not Sell or Share My Personal Information. To opt out, sign in and switch off Allow advertising measurement under Account → Data & Privacy. The choice takes effect immediately, applies to every device you sign in from, and is recorded as a dated entry in your consent history. If you do not have an account there is nothing to opt out of: the marketing website shares nothing about you with anyone. You may also make the request by email (10.6), including through an authorised agent. We have no actual knowledge of selling or sharing the personal information of anyone under 16.
We honour the Global Privacy Control signal where your browser sends one. In the application it switches advertising measurement off regardless of your stored setting and records that it did, it keeps consent-gated analytics off, and it also switches off the anonymous application-health stream, which we are not strictly required to do.
Do Not Track. Some browsers send a Do Not Track header. There is no agreed standard for what a service should do in response, and we do not treat it as a distinct instruction — but the behaviour it asks for is what this site does anyway, since we run no trackers. Global Privacy Control, which does have an agreed meaning, we honour as described above.
10.4 If you are in the UK or the EEA
You have the rights set out in Articles 15 to 22 of the GDPR, and you may lodge a complaint with your national supervisory authority. We would rather you told us first, but you are not required to.
The advertising measurement described in 3.3 does not apply to you unless you turn it on yourself under Account → Data & Privacy; that switch is your consent, it is off by default, it is never pre-selected, and you may withdraw it at any time with immediate effect on future events.
10.5 Unsubscribing
Every non-essential email carries a one-click unsubscribe link and the standard List-Unsubscribe headers, so your mail client's own unsubscribe button works. It takes effect immediately, requires no login and no confirmation step, and applies permanently to that address unless you ask us to reverse it.
Security notices, confirmation emails and notices about your subscription are transactional rather than marketing. They are part of running your account, so unsubscribing from the daily summary does not stop them.
10.6 How to make a request
Email insight@getportfoliolens.com. We will acknowledge your request and respond within 30 days, or within 45 days for requests under California law, extendable once where permitted. We may need to confirm your identity before acting, and we will ask for no more information than that requires. You may use an authorised agent where the law allows; we will ask the agent to prove both their identity and their authority. We do not charge for any of this and we will not ask you to create an account to make a request.
Your choices can occasionally be limited — where meeting a request would affect someone else's rights, prevent us providing a service you asked for, or conflict with a legal obligation. If that happens we will tell you which of those applies rather than simply declining.
11. Security
Data is encrypted in transit and at rest. Application secrets are held in a managed secrets store rather than in code or configuration. Access to production systems is limited to the small number of people who need it, and administrators must have multi-factor authentication. Deployments and schema changes are reviewed and tested before they reach production.
No system is perfectly secure and we will not claim otherwise. If a breach occurs that affects you, we will notify you and the relevant regulator within the time limits the law sets.
12. Administrator access to your account
A small number of administrators can view member records in order to run the service. Every such view is written to an audit record — who looked, at what, and when — in the same database transaction as the read itself, so a look that was not recorded is not a look that can happen. Administrators must have multi-factor authentication enrolled and must have signed in recently before these screens will load.
13. Children
Neither the website nor the application is directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, contact us and we will delete it.
14. Changes to this policy
If we change this policy we will update the effective date at the top. Where a change materially affects how we use information you have already given us, we will email you before it takes effect rather than relying on you to re-read this page. Where a change describes a new technology — a tracker, a pixel, or a new recipient of your data — this page changes on the same day that technology goes live, and not afterwards.
15. How to contact us
Portfolio Lens, Inc. is the entity responsible for the processing described here. Email insight@getportfoliolens.com for any privacy question, to exercise any right, or to complain about how we have handled your information. It is monitored by a person and it is the route for every request this policy describes.