Last updated: January 26, 2025
Portfolio Flow ("we," "us," or "our") operates the portfolioflow.ai website and related services (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. Please read this policy carefully. By accessing or using the Service, you agree to this Privacy Policy.
When you create an account, we collect:
When you connect brokerage or bank accounts through Plaid, we access:
Important: We request read-only access only. We cannot execute trades, transfer funds, or make any changes to your accounts. Your brokerage login credentials are never transmitted to or stored on our servers—Plaid handles authentication directly with your financial institution.
We automatically collect:
When you use the AI chat feature, we process your questions along with your portfolio data to generate responses. Chat history may be retained to improve the Service and provide context for follow-up questions within a session.
We use collected information to:
We do not sell, rent, or trade your personal information to third parties. We share information only in the following circumstances:
We use trusted third-party services to operate the Service:
We may disclose your information if required by law, regulation, legal process, or governmental request, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have.
We implement industry-standard security measures to protect your information:
However, no method of transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
We retain your personal and financial information for as long as your account is active or as needed to provide the Service. Historical portfolio snapshots are retained to enable performance tracking. If you delete your account, we will delete or anonymize your information within 30 days, except where retention is required for legal, accounting, or legitimate business purposes.
You have the following rights regarding your data:
We use essential cookies to maintain your session and authentication state. We may use analytics tools to understand how the Service is used. You can control cookies through your browser settings, though disabling essential cookies may prevent the Service from functioning properly.
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child under 18, we will delete it promptly.
Your information may be transferred to and processed in countries other than your country of residence, including the United States. These countries may have different data protection laws. By using the Service, you consent to such transfers.
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, request deletion, and opt out of sales (though we do not sell personal information). To exercise these rights, contact us using the information below.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy or our data practices, please contact us at: