Privacy Policy

Last updated: April 2026

1. Information We Collect

When you use VestorLab, we may collect:

  • Account information — email address, name, and profile photo from Google OAuth or email sign-in.
  • Portfolio data — positions, trades, and watchlist symbols you add or import from brokers.
  • Usage data — pages visited, features used, and analysis requests.
  • Risk profile — responses to the risk tolerance questionnaire.

2. How We Use Your Information

  • To provide and personalize the Service (portfolio tracking, AI analysis, news feed).
  • To authenticate your identity and secure your account.
  • To generate AI-powered analysis tailored to your holdings and risk profile.
  • To send transactional emails (magic link sign-in). We do not send marketing emails.

3. Data Sharing

We do not sell your personal information. We may share data with:

  • AI providers — portfolio context is sent to LLM providers (Anthropic, Google, OpenAI) to generate analysis. This data is not stored by these providers beyond processing the request.
  • Email service — your email address is shared with Resend for magic link delivery.
  • Authentication — Google OAuth tokens are verified with Google servers.

4. Brokerage Data

If you import data from a brokerage (e.g., Interactive Brokers Flex reports), the imported positions and trade history are stored in our database to provide portfolio tracking and analysis. We do not store your brokerage credentials. Flex report tokens are used once for import and not retained.

5. Data Security

We use industry-standard security measures to protect your data, including encrypted connections (HTTPS), hashed tokens, and secure database access. However, no method of transmission over the Internet is 100% secure.

6. Data Retention

Your account data is retained as long as your account is active. You may request deletion of your account and associated data at any time by contacting us.

7. Cookies

We use JSON Web Tokens (JWT) stored in browser localStorage for authentication. We do not use third-party tracking cookies or analytics services.

8. Changes to This Policy

We may update this policy from time to time. Changes will be posted on this page with an updated date.

9. Contact

Questions about your privacy? Contact us at support@vestorlab.com.