Privacy Policy
PortRisk provides portfolio risk analytics. We keep the data we collect to the minimum needed to run the service, and we never sell it.
Who operates PortRisk
PortRisk is the data controller for information processed through this service. The public product domain is portrisk.tech. Privacy requests are handled at privacy@portrisk.tech.
Data we collect
- Account data: Auth0 user ID, email address, display name and profile image supplied when you authenticate.
- Portfolio data: assets, transaction dates, amounts, prices, watchlists, public wallet addresses and calculated risk history.
- Connected exchange data: read-only API credentials. Exchange secrets are encrypted before storage; private wallet keys are never requested or stored.
- Billing data: Stripe customer, subscription and price identifiers. PortRisk does not receive or store full payment-card details.
- Operational data: security and activity events, feedback, rate-limit counters, session records and basic request metadata such as IP address and user agent.
How we use your data
We use this information to authenticate you, calculate risk scores, VaR, concentration, correlations and stress scenarios, maintain account security, provide support, deliver requested reports and administer Pro subscriptions. We do not sell personal or portfolio data and do not use it for advertising.
Service providers
- Auth0: authentication and identity management.
- Vercel and our managed PostgreSQL provider: application hosting, request processing, database storage and operational backups.
- Stripe: subscription checkout, billing and legally required payment records.
- Anthropic: AI risk explanations when you explicitly use the assistant.
- Resend: delivery of service and risk-report emails when email delivery is enabled.
- CoinGecko, Binance, Alpha Vantage, Frankfurter and Alternative.me: market prices, price history, exchange balances, foreign-exchange rates and market sentiment.
- GoldRush, Alchemy, mempool.space and Solana public RPC providers: balances for public wallet addresses that you choose to connect.
These providers process data only for the stated service purpose and may process it in countries outside your own under their applicable contractual safeguards.
AI portfolio context
When you ask the AI assistant a question, PortRisk sends Anthropic your question together with a limited portfolio context: asset symbols and names, portfolio weights, selected risk metrics and relevant market context. We do not send exchange credentials, wallet secrets, payment details or your Auth0 credentials. PortRisk stores only a daily usage counter, not the prompt or AI response; Anthropic may retain request data according to its own service terms.
Market and public-wallet requests
To retrieve financial data, PortRisk sends only the asset identifiers needed for a request to the relevant market provider. When you connect a public wallet address, that address and its chain are sent to the applicable public blockchain data provider. Public addresses and blockchain activity are public by design; private keys and seed phrases are never requested.
Cookies
We use only strictly necessary authentication and security cookies. Production cookies are HttpOnly, Secure and SameSite protected. We do not use advertising or third-party tracking cookies.
Retention
- Account, portfolio, risk-history and billing-link records are retained while the account is active and deleted when account deletion completes, except records Stripe or another provider must retain by law.
- Sessions remain until logout or expiry. Rate-limit and password-reset records remain only for their security window.
- Feedback and account-linked operational activity are retained for up to 12 months or until account deletion, whichever comes first.
- Deletion removes data from the active database immediately after external account cancellation succeeds. Encrypted provider backups may persist temporarily for the backup-retention period before automatic expiry.
Your choices and deletion
You may export your portfolio from the product and request correction, access or deletion at privacy@portrisk.tech. Account deletion first cancels an active Stripe subscription and removes the Auth0 profile, then deletes PortRisk account data. The operation is designed to be safe to retry.
Changes
We may update this policy as the service evolves. Material changes will be reflected by the date above.