Privacy Policy
Last updated: March 2026
1. What data we collect
We collect only the data necessary to provide FinLore's services:
- Email address — collected when you sign in via Google or GitHub OAuth, or when you subscribe to our newsletter.
- Name and profile picture — provided by your OAuth provider (Google or GitHub) and used only to display your identity within the app.
- Portfolio holdings — tickers, share quantities, and average buy prices that you manually enter in the portfolio tracker. We do not connect to any brokerage or financial institution on your behalf.
We do not collect payment information, browsing history beyond standard server logs, or any data from third-party tracking cookies.
2. Where your data is stored
All user data is stored in Supabase, a secure PostgreSQL database hosted on AWS infrastructure. Your portfolio data is protected by Row Level Security (RLS), meaning database queries are enforced at the database level to ensure that each user can only access their own data — even if application-level code were to malfunction.
Newsletter subscriptions are managed by Resend, a transactional email provider. Your email address is stored in Resend's secure infrastructure solely for the purpose of sending FinLore newsletters.
3. Who can access your data
Only you can view and modify your portfolio holdings. FinLore staff have administrative access to the database for operational purposes, but we only view anonymized or aggregate data (e.g., total number of users or most-tracked tickers). We do not inspect individual portfolios.
Your email address is accessible to FinLore administrators solely for the purpose of delivering newsletters and responding to support requests.
4. We never sell or share your data
FinLore does not sell, rent, license, or otherwise share your personal data with any third party for marketing, advertising, or any commercial purpose. Your data is used exclusively to provide FinLore's features to you.
We do not use any third-party advertising networks or behavioral tracking technologies.
5. Cookies and analytics
FinLore uses Vercel Analytics to collect anonymized, aggregated page-view statistics. No personally identifiable information is collected by analytics. We use session cookies managed by Supabase Auth to keep you signed in — these are essential to the app's functionality and are not used for tracking.
6. How to delete your account and data
To delete your account and all associated portfolio data, send an email to hello@finlore.io with the subject line "Delete my account" from the email address associated with your account. We will permanently delete all your data within 7 business days and confirm by email.
To unsubscribe from the newsletter, click the unsubscribe link in any newsletter email, or include "unsubscribe" in the subject line of a reply.
7. Changes to this policy
We may update this privacy policy from time to time. When we do, we will update the "last updated" date at the top of this page. Continued use of FinLore after changes are posted constitutes acceptance of the updated policy.
8. Contact
If you have any questions about this privacy policy or how we handle your data, please contact us at hello@finlore.io.