Portfolio Observatory
Privacy Policy
Portfolio Observatory is a private, manual portfolio tracker for listed stocks and ETFs. This policy explains what data we hold, why we hold it, and the choices you have. We designed the product to hold as little personal data as possible.
Data we collect
- Account identity. Authentication is handled by Clerk. We receive a user identifier and the email address you sign up with so we can secure your account and associate your portfolio with you.
- Portfolio ledger. The purchases, sales, dividends, fees, notes, alerts, and watchlist entries you record yourself. This is stored against your authenticated account and is never shared with other users.
- Operational data. Minimal technical logs needed to keep the service running and secure. We do not log your portfolio values or transaction contents.
Data we do not collect
- We never collect brokerage credentials or connect to brokerage accounts.
- We never collect wallet keys or seed phrases.
- We never have authority to place orders, move money, or trade.
Market data
Quotes, foreign-exchange rates, and market-session status are retrieved from third-party market-data providers (currently Twelve Data for quotes and instrument search, and Frankfurter for foreign-exchange reference rates). We send only the instrument symbols and currency pairs required to fetch prices — never your holdings, quantities, or personal information. Quote freshness and timing are shown alongside every value. Market data is informational and may be delayed.
Alerts and push notifications
Alerts are optional and informational. You choose the rules you want to track, and they are stored against your authenticated account. By default, alert rules are evaluated only while the app is open.
- Server monitoring opt-in.If you turn on “Monitor alerts on the server (push)” in the iOS app, we evaluate your enabled rules on a schedule using market data and may send you a push notification when a rule’s condition is met. You can turn this off at any time, which stops server evaluation for your account and removes this device’s push registration.
- Device tokens. To deliver push notifications we store an Apple Push Notification service (APNs) device token for the devices you opt in with. Tokens are removed when you opt out, delete the app registration, or when Apple reports them as no longer valid.
- Notification content. Notifications describe the rule you set in neutral terms. They never contain trading instructions, recommendations, or advice, and we keep monetary detail in notification copy to the minimum needed to be useful.
- Delivery records. We keep a minimal delivery log (which rule triggered, when, delivery status) to make alerts reliable and auditable. This log is tied to your account and is removed with your account data on deletion.
How we use data
We use your data only to operate the service: to authenticate you, store and calculate your portfolio, and display market-dependent values. We do not sell your data and we do not use it for advertising.
Analytics and product telemetry
We use PostHog to understand how the app is used and to detect errors so we can keep it reliable. For signed-in users this telemetry is linked to your Clerk user identifier. PostHog records page views, feature interactions, and error diagnostics. We do not use it for advertising and we do not sell this data.
- What is masked. Captured text and input fields are masked, and we scrub sensitive properties — including email, portfolio names and values, holdings, quantities, prices, notes, and tokens — before events leave your browser, so your portfolio figures are not sent to analytics.
- Session replay. Where session replay is enabled, recordings apply the same text and input masking. You can turn product analytics off from the in-app data settings.
Storage and security
Portfolio data is stored in a managed PostgreSQL database hosted on Supabase and is accessible only to your authenticated account. Data is encrypted in transit. Access to production systems is restricted and audited.
Your choices
- Export. You can export your full portfolio data at any time from the in-app account data screen.
- Deletion. You can request deletion of your account and confirm deletion of app-managed portfolio data after export/review safeguards. The app retains only minimal deletion proof for replay and audit safety. Authentication records held by Clerk are handled through the identity provider or account support process.
Third parties
We rely on Clerk for authentication, Supabase for managed database storage, Vercel for hosting and delivery, market-data providers (including Twelve Data for quotes and Frankfurter for foreign-exchange reference rates) for prices, PostHog for product analytics and error tracking, and Apple’s Push Notification service to deliver alerts you opt into. Each processes data only to provide their part of the service.
Children
Portfolio Observatory is not directed at children and is intended for adults managing their own records.
Changes
We may update this policy as the product evolves. Material changes will be reflected by the “last updated” date above.
Contact
For privacy questions or data requests, contact blake@cliquemediagroup.com.au.