PortfolioFit Objective alignment
Home MCP docs Privacy Terms Support Log in

Privacy

Privacy Policy

How PortfolioFit collects, uses, shares, retains, and protects information across the website, MCP server, and plugin.

Last updated: July 31, 2026

On this page Scope Information we collect How we use information Service providers Retention Your controls Security Contact

1. Scope

This Privacy Policy describes how PortfolioFit handles information when you use the PortfolioFit website, portfolio workspace, remote MCP server, or PortfolioFit plugin. It also covers information received when an agent acts on your behalf through an authorized PortfolioFit connection.

PortfolioFit is designed for portfolio mandate and constraint analysis. Please do not submit personal or confidential information that is not needed for that purpose.

2. Information we collect

Account and identity information

We collect your name, email address, and password credentials when you create an account. Passwords are stored as one-way hashes, not in plain text. If you sign in with Google, we receive the Google account identifier, name, email address, and email-verification status needed to create or connect your PortfolioFit account. We do not retain long-lived Google access or refresh tokens for website sign-in.

Portfolio and analysis information

We process portfolio names, mandates or objectives, holdings, security attributes, constraints, source references, warnings, questions, and analysis results that you or your agent submit. We also store generated rules, model and response identifiers, confidence metadata, and evaluation history used to explain and audit results.

Files and drafts

CSV, XLSX, and PDF uploads are read to extract relevant text and tables. PortfolioFit does not intentionally retain the original upload as a stored application file. It may retain the original filename, extracted or normalized content, warnings, and resulting analysis. A draft entered on the public start page is held in your browser session until it is used to create an account workspace or the session expires.

Agent, usage, and technical information

For MCP and plugin requests, we process the connected account, capability, idempotency key, a hash of the input, structured output, model and provider response identifiers, token counts, status, errors, and timestamps. We also receive standard web request and security information such as IP address, browser or client type, requested URL, and session or CSRF cookie data through our infrastructure.

Billing information

When you purchase a plan, we store subscription status and Stripe customer, subscription, and checkout-session identifiers. Payment card details are collected and processed by Stripe and are not stored by PortfolioFit.

3. How we use information

We use the information described above to:

  • create, authenticate, connect, and protect accounts;
  • extract and normalize portfolio information and provide requested analyses;
  • produce evidence-aware results, deterministic calculations, and remediation guidance;
  • maintain evaluation history, enforce plan limits, prevent duplicate charges, and investigate errors;
  • process subscriptions, send transactional email, and provide support;
  • monitor reliability, security, abuse, and public-site usage; and
  • comply with legal obligations and enforce our Terms of Service.

We do not use Google account data for advertising. PortfolioFit's handling of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

4. Service providers and disclosures

We disclose information only as needed to operate the service, including to these categories of recipients:

  • OpenAI: relevant mandate, holdings, extracted document text, questions, and context for model-assisted extraction and analysis. Deterministic calculations may run without an OpenAI model call.
  • Google: authentication requests when you choose Google sign-in.
  • Stripe: account, email, plan, checkout, and subscription information for payments.
  • AWS SES and email infrastructure: recipient and transactional message information.
  • SiteHits: public and product-page usage events and standard request information for analytics.
  • Hosting and security providers: information required to host, back up, monitor, and protect the service.

We may also disclose information when required by law, to protect rights and safety, or as part of a business reorganization subject to appropriate safeguards. Providers may process information in countries other than your own under their applicable terms and safeguards.

5. Cookies and similar technologies

PortfolioFit uses essential session and CSRF cookies to keep you signed in, preserve a public draft, and protect forms and OAuth flows. SiteHits may use browser storage or similar technologies for analytics. Blocking essential cookies may prevent account, draft, and authorization features from working.

6. Retention

  • Account, portfolio, mandate, holdings, rules, and website evaluation data are retained while your account is active or until they are deleted, subject to operational, security, and legal needs. Moving a portfolio to Trash does not erase it; permanent deletion removes the portfolio and its related rules and evaluation records from the active database.
  • MCP structured result payloads are normally cleared after 90 days. Invocation audit and usage metadata, including hashes, idempotency keys, provider identifiers, token counts, status, and timestamps, may be retained longer for security, billing, limit enforcement, and service integrity.
  • OAuth access tokens are short-lived. Refresh authorization is normally limited to 30 days, unused dynamically registered clients are normally removed after 30 days, and pending identity links expire after a short period.
  • Backups, security logs, provider records, and records required for legal or fraud-prevention purposes may remain for their applicable operational or legal retention periods.

7. Your choices and controls

You can update portfolio data, move portfolios to Trash, and permanently delete portfolios in the product.

You may disconnect an agent integration in the agent client and revoke Google access from your Google account. To request access, correction, export, restriction, objection, or deletion of account-level information, email support@portfolio.fit. We may need to verify your identity before acting on a request. Some audit, billing, security, backup, or legally required records may be retained after a request.

8. Security and data quality

We use access controls, secure cookies in production, scoped OAuth tokens, input limits, and structured output validation to protect the service. No security measure is perfect. Keep credentials and agent authorization links private, and report suspected unauthorized access promptly.

PortfolioFit analyses depend on the data supplied and may be incomplete or incorrect. Review important results and source evidence before relying on them.

9. Changes to this policy

We may update this policy as the service or legal requirements change. We will publish the revised policy here and update the date above. Material changes may also be communicated through the service or by email.

10. Contact

For privacy questions or requests, contact PortfolioFit at support@portfolio.fit or visit the Support page.

PortfolioFit Analytical support for reviewing portfolio mandates and constraints. PortfolioFit does not provide investment, legal, tax, or regulatory advice and does not place trades.

Home MCP docs Privacy Terms Support