Privacy
Privacy Policy
This policy describes the information Fillfolio collects and how it is used to provide portfolio tracking, brokerage sync, analytics, and billing.
Information we collect
Fillfolio may collect account details such as your email address, authentication identifiers, portfolio names, saved assets, transactions, cash ledger entries, import preferences, settings, and billing status. Payment card details are handled by Stripe and are not stored by Fillfolio.
How we use information
We use information to provide the app, protect account access, save portfolio records, process subscriptions, enable read-only brokerage sync, respond to support requests, improve reliability, prevent abuse, and comply with legal, tax, security, and payment obligations.
SnapTrade brokerage data
If you connect a brokerage through SnapTrade, Fillfolio may process connection identifiers, brokerage/institution names, account labels, account identifiers, balances, cash balances, positions, securities, quantities, prices, activity history, sync timestamps, and encrypted SnapTrade user secrets or related sync credentials. This data is used to display synced holdings and activity in a read-only portfolio experience.
Blockchain wallet data
If you add a blockchain wallet, Fillfolio may process wallet labels, public addresses or xpubs, chain identifiers, token symbols, quantities, prices, balances, net worth summaries, sync timestamps, and provider responses needed to display read-only wallet holdings. Wallet addresses and xpubs are treated as privacy-sensitive account data.
Connected bank data and consent
If you connect a bank, Fillfolio may process institution names, account labels, account types and subtypes, currencies, one normalized balance and its current-or-available source, keyed duplicate-detection fingerprints, connection status, provider-authorized product and data-scope labels, consent records, and sync timestamps needed to show cash, cash-management balances, credit-card debt, and net worth. Before opening the bank connection flow, Fillfolio records your explicit consent, its version, purpose, requested products, timestamp, and the policy links shown to you. Fillfolio also requires recent first-factor identity reverification and a separate authenticator-app or single-use recovery-code verification before opening the connection flow. This bank-action step-up is operated by Fillfolio and does not change the authentication provider's session-factor state. The bank connection service handles institution credentials; Fillfolio does not receive or store bank usernames, passwords, or one-time authentication codes.
Authenticator and account security data
Fillfolio may process an encrypted authenticator seed, keyed hashes of single-use recovery codes, hashed assurances bound to your authenticated Clerk session and security-policy version, short-lived assurances bound to an intended bank action, replay counters, lockout and rate-limit state, reset timestamps, and pseudonymized security audit events. Account MFA is optional on every plan, while bank connection actions always require the shared factor. Authenticator and recovery codes are never intentionally logged. Recovery codes are shown once, and only protected hashes are retained. Security audit events are retained for up to 12 months.
Bank-data minimization
The connection is configured read-only. Fillfolio uses the minimum 30-day Transactions initializer because Balance cannot initialize a connection by itself and the recurring product allows the provider to maintain updated account data. Plaid or an institution may request broader permissions to establish and maintain that connection. Fillfolio limits its provider API calls to connection and institution metadata, account metadata and balances, connection updates, and revocation. It does not call transaction-history, Auth, Identity, account-number, or Signal endpoints. It stores an encrypted connection token and minimized normalized institution, account, balance, consent, product-audit, and sync fields only. It does not initiate transfers or payments.
Stripe billing data
Stripe processes card details and may provide Fillfolio with customer identifiers, subscription status, invoices, payment status, billing email, and limited payment metadata. Fillfolio uses that information to activate plans, show billing status, and support payment questions.
Hosting and operational data
Hosting, security, and infrastructure services may process request metadata such as IP address, user agent, URLs, timing, security events, and operational logs needed to run and protect the service.
Google Search Console and GA4
Google Search Console may process site ownership, indexing, query, click, impression, and technical search-performance information for fillfolio.com. If Google Analytics 4 is enabled and you grant analytics consent, GA4 may process page views, events, device/browser details, approximate location, and analytics cookie identifiers to help us understand product usage.
Google Sheets™ add-on data
The Fillfolio Google Sheets™ add-on may locally read, create, format, and update Fillfolio-managed ranges in the active spreadsheet. It does not scan other Google Drive™ files, request Google Drive™-wide access, or send spreadsheet cell contents back to Fillfolio. Portfolio reports move one way from Fillfolio into the spreadsheet you selected. Fillfolio may receive a pseudonymous spreadsheet identifier hash, the selected export scope, masked-value setting, row counts, sync status and timestamps, the add-on's declared permissions, and the signed-in Fillfolio account used to authorize the connection. The spreadsheet name is not sent or stored.
Google API Limited Use
Fillfolio's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Fillfolio does not sell Google Workspace™ data or use it for advertising, lending or eligibility decisions, data-broker services, or artificial-intelligence and machine-learning model training. Google Workspace™ data is not transferred to third-party AI services.
Service providers and sharing
Fillfolio relies on service providers including Clerk for authentication, Stripe for billing, read-only brokerage and bank connection services, infrastructure and security services, Google services for search diagnostics and consent-based analytics, and market-data services needed to operate the product. We do not sell personal information, and providers process information as needed to support Fillfolio.
Processing locations
Fillfolio data is primarily processed using infrastructure in Europe and may be accessed by authorized personnel in the United States for security, support, and service operations. Service providers may process data in other jurisdictions under their contractual and legal safeguards. Fillfolio does not sell or license connected financial data.
Local storage, cookies, and consent
The app uses browser storage for preferences such as theme, selected portfolio, sidebar state, privacy mode, and table density. Authentication and payment providers may use cookies or similar technologies to keep sessions secure. GA4 analytics scripts are loaded only when a measurement ID is configured and analytics consent is granted in the browser.
Retention and deletion
We keep account and portfolio information while your account is active or as needed for security, billing, dispute handling, and legal obligations. When you disconnect a bank or delete your account, Fillfolio requests provider revocation and removes connected account, balance, and token data within 24 hours in the normal course. If revocation is temporarily unavailable, derived balance data is removed and the encrypted token may be retained solely for retry for up to seven days before local deletion. Minimized bank webhook metadata is retained for 30 days, sync and error logs for 90 days, and consent and security audit records for up to 12 months. If you use destructive account-security reset, Fillfolio immediately invalidates the authenticator factor, recovery codes, and outstanding assurances; removes or schedules revocation of connected banks; removes visible bank data; revokes active Fillfolio sessions; and applies a one-hour re-enrollment hold. No email or SMS notification is sent for that self-service reset. To request deletion or export help, contact [email protected]. For Google Sheets™, expired pending connection records are deleted within 24 hours, active minimized connection metadata is retained while connected, and add-on access tokens expire after 90 days unless rotated. Disconnecting immediately invalidates access and scrubs spreadsheet identifiers and token material; the minimized revocation record is deleted after 30 days. Google Sheets™ sync logs are deleted after 90 days. Account deletion removes all remaining Google Sheets™ connections and sync logs.
Security
Fillfolio uses HTTPS, protected routes, server-side access checks, encrypted sync secrets where applicable, and trusted providers for authentication, brokerage sync, infrastructure, and payments. No internet service can be guaranteed perfectly secure, but we design around reasonable safeguards.
Contact
Questions, deletion requests, export requests, or privacy concerns can be sent to [email protected].
Mailing address
Mailing address: 99 WALL ST #884, NEW YORK, NY 10005, USA. This address is for business correspondence. Customer support is fastest by email.