← Back to app

Privacy Policy

Last updated: 21 June 2026

SyncWealth is a personal portfolio-intelligence tool. This policy explains what information we collect, why we collect it, where it is stored, and the rights you have over your data. We aim to collect as little as possible and to give you full control over what we hold.

What data we collect

We collect only the information needed to run your account and provide the service:

  • Account details: your email address and a hashed password. Passwords are never stored in plain text (see Security below).
  • Portfolio data: the transactions, holdings, and account structure you enter, along with any tags, notes, or labels you attach to them.
  • AI analyses and journal: the analyses you generate, their results, and any journal or research entries you write inside the app.
  • Profile and preferences: display settings, base currency, and other configuration you choose.
  • Anthropic API key (optional): if you provide your own Anthropic Claude API key, we store it encrypted at rest so the app can make analysis requests on your behalf.

We do not connect to your bank or brokerage accounts, and we do not collect financial credentials. The portfolio you see is built from the data you enter manually.

How we use your data

We use the data you provide to:

  • Display your portfolio, calculate performance, and show the metrics and analyses you request.
  • Run AI analyses by sending the relevant portfolio context to the Anthropic Claude API.
  • Authenticate you and keep your session secure.
  • Maintain, debug, and improve the reliability of the service.

We do not sell your personal data, and we do not use your portfolio data for advertising.

Where your data is stored

Your data is held in two managed databases: Upstash Redis (our key-value store for live application state) and Supabase (our structured datastore for account and portfolio records). Both are operated by reputable third-party providers and are hosted in cloud-region infrastructure within the European Union, unless a region change is announced here in advance.

The application itself is hosted on Vercel, which serves the app and processes requests in transit. Data in transit is protected with industry-standard TLS encryption.

Third parties we share data with

SyncWealth relies on a small set of third-party services to function. We share only what each service needs to perform its role:

  • Anthropic (Claude API): receives the portfolio context relevant to an analysis you request so it can return AI output. Anthropic processes this as our subprocessor.
  • Market-data providers: we fetch prices and instrument data from Yahoo Finance and other public market-data sources. These are read-only lookups of public symbols and do not include your personal data.
  • Polymarket: we read publicly available, attributed market-probability data on a read-only basis. No personal data is sent to Polymarket.
  • Upstash and Supabase: our database providers, which store the data described above.
  • Vercel: our hosting and edge-delivery provider, which processes requests to serve the application.
  • Resend: our email provider. When you contact support (or we send you an account email), Resend processes the recipient address and message content to deliver it. It is not used for marketing.
  • Sentry: our error-monitoring provider. If the app hits an error, a diagnostic report is sent to Sentry so we can fix it. We configure it to strip personal data, request contents and any secrets before anything is transmitted, so reports contain technical error details, not your portfolio.

Security and your API key

We take reasonable technical measures to protect your data. Passwords are hashed with bcrypt and are never stored or transmitted in plain text. Your session is maintained with a signed token (JWT).

If you supply your own Anthropic API key, it is encrypted at rest using AES-256-GCM. It is decrypted only in memory, only when needed to make a request on your behalf, and is never exposed in the app interface after you save it.

Cookies and sessions

We use a session token to keep you signed in and to authenticate your requests. This is strictly necessary for the app to work. We do not use third-party advertising or tracking cookies.

Your rights

You stay in control of your data. From within the app you can:

  • Access: view all the portfolio and account data we hold about you.
  • Export: download a complete copy of your data at any time.
  • Delete: delete your account. Deletion uses a 30-day soft-delete grace period, during which you can restore the account. After 30 days, your data is permanently purged.

Depending on your location, you may also have rights to correct your data or to object to certain processing. To exercise any of these, contact us using the details below.

Data retention

We keep your data for as long as your account is active. When you delete your account, the data enters the 30-day soft-delete window and is then permanently removed. Encrypted backups, where they exist, are rotated out on a routine schedule. We do not retain your data longer than is necessary to provide the service or meet legal obligations.

Children

SyncWealth is intended for adults only. The service is not directed to anyone under 18, and we do not knowingly collect data from minors. If you believe a minor has provided us with personal data, contact us and we will remove it.

Changes to this policy

We may update this policy from time to time. When we make material changes, we will revise the date at the top of this page. Continued use of SyncWealth after an update means you accept the revised policy.


Contact

Questions about this policy or your data? Reach us at support@syncwealth.app.

SyncWealth is a tool for informational purposes only and does not provide financial advice.