← Back to App
Portfolio Analytics Lab icon

Trust center

Privacy

Plain-language information for the hosted Portfolio Analytics Lab beta.

Controller and contact

Portfolio Analytics Lab is operated by its project owner in Greece. For privacy and data-rights requests, email portfolioanalyticslab@gmail.com.

Data categories

Signed-in accounts can store account identifiers, private dashboard snapshots, settings, normalized manual inputs and encrypted read-only broker credentials. Password handling is delegated to the authentication service. Original broker tax-statement files used for reconciliation are not retained by PAL.

Purposes and legal bases

Account and portfolio data is processed to provide the dashboard and requested account features. Security, abuse prevention and reliability diagnostics are processed for the operator's legitimate interests in protecting and operating the service. PAL does not sell broker credentials or private portfolio data.

Guest diagnostics

Guest/demo use may record the event type, time, app path, basic non-portfolio context and a one-way hash derived from network and browser information. Raw IP addresses and raw browser identifiers are not stored in this diagnostic table. These events are retained for up to 90 days.

Public-site analytics

The public information site can use Google Analytics only after the visitor chooses Allow analytics. It may measure pages viewed, approximate location, device context and engagement time. Portfolio rows, broker credentials, account data and uploaded files are not sent to Google Analytics. Visitors can refuse analytics or reopen Analytics preferences from the public-site footer.

Recipients and transfers

Infrastructure providers process only the information needed for hosting, authentication, storage, background tasks, security and delivery. Processing may occur outside the European Economic Area under the provider's applicable transfer safeguards. Operational and security logs may follow each provider's own retention terms.

Retention

Saved account data remains until it is replaced or deleted by the account holder. Completed routine operational records are normally removed after 90 days; active and unresolved failure records may be kept longer while needed to resolve a problem. Account deletion removes PAL-controlled account data, subject to limited provider logs and legal obligations.

Your rights

Depending on applicable law, you may request access, correction, deletion, restriction, portability or object to processing, and may lodge a complaint with your data-protection authority. Focused table and workbook exports, together with deletion controls, are available in the app; use the contact above for other requests.

Security choices

Use read-only broker access, protect your login, remove connections you no longer need and never send credentials through chat, community channels or support messages. No internet service can promise absolute security.