Stockfolio

Privacy Policy

Last updated: May 24, 2026

1. Information we collect

Email and hashed password (or Google profile if you use Google sign-in). Server-side: IP, timestamps, browser info, cookies. Application data: account names, trade entries, investment logs, goal amounts. Account numbers and other sensitive identifiers are not stored.

If you opt in to notifications: browser push subscription (endpoint URL, public key) used solely to deliver alerts. A daily snapshot of your total portfolio value (in KRW) is stored to compute day-over-day changes.

2. Purpose

Authentication, password reset, computing returns/statistics from your trade entries, sending opt-in notifications about asset changes, fraud prevention, legal compliance.

3. Retention

Until you delete your account or withdraw consent, after which your data is removed promptly.

4. Subprocessors

Supabase (auth + database, US/SG), Vercel (hosting, US), Cloudflare (DNS, US). Yahoo Finance is queried for market data without sending personal information. Browser push services (Google FCM, Apple APNs, Mozilla autopush, etc.) relay opt-in notifications only.

5. Your rights

You may access, correct, delete your data, or stop processing at any time. Account deletion is permanent.

6. Security

Passwords are stored as bcrypt hashes. All traffic is HTTPS-encrypted. Row Level Security ensures you can only access your own data.

7. Contact

Privacy contact: euiyeol97@gmail.com

개인정보처리방침 · Stockfolio