TrackAUM

Privacy Policy

Effective July 12, 2026. This policy explains what data TrackAUM collects, why, who processes it, and the controls you have.

What TrackAUM is

TrackAUM is a portfolio tracker: you record or connect investments and the app values them in your chosen currencies. It is read-only by design — it can never move money, place trades, or withdraw funds anywhere.

Data we collect

  • Account: your email address, provided through our sign-in provider (Privy) when you log in with a one-time code. We never see or store a password.
  • Portfolio data you enter: holdings, transactions, liabilities, watchlists, alerts, rebalancing targets and preferences (currencies, display options). This is the product — it exists so the app can show it back to you.
  • Connected accounts: exchange API keys you add are required to be read-only and are encrypted at rest (AES-256-GCM); they are decrypted only momentarily on the server to fetch balances and trades, and are never included in exports, API responses, or logs. Wallet addresses you add are public blockchain identifiers.
  • Sessions: per-device session records (browser user-agent string, sign-in and last-seen timestamps) so you can review and revoke devices in Settings → Security.
  • App PIN: if you enable the privacy lock, the PIN is stored only as a salted scrypt hash — we cannot recover it.

Data we do not collect

  • No bank or brokerage logins, ever.
  • No wallet private keys or seed phrases, ever.
  • No advertising trackers, analytics pixels, or data brokers.
  • We do not sell or share your data for advertising. Period.

How your data is used

Solely to operate the product: valuing your portfolio, refreshing prices and FX rates, syncing connected accounts on a schedule, sending the price-alert emails you configure, and securing your account. There is no secondary use.

Processors we rely on

A small set of infrastructure providers process data on our behalf, each only what its job requires:

  • Privy — email sign-in (your email address).
  • Vercel — application hosting (request logs).
  • Neon — the encrypted database where your data lives.
  • Resend — delivery of the alert emails you set up (your email address, the alert text).
  • Market-data providers — price and FX lookups. Only asset symbols are sent; never your identity, balances, or holdings.

Security

  • All traffic is encrypted in transit (TLS, HSTS enforced).
  • Exchange API keys are encrypted at rest with AES-256-GCM; database storage is encrypted by our provider.
  • Sessions are first-party, HTTP-only cookies; you can revoke any device from Settings, and state-changing requests are same-origin enforced.
  • Error messages and logs never include credentials or secret material.

Retention & deletion

Your data is kept while your account exists. Deleting your account (Settings → Delete account) immediately and permanently removes your portfolios, holdings, transactions, liabilities, connections (including encrypted keys), alerts, watchlists, and sessions. There is no soft-delete copy.

Your rights (GDPR / CCPA)

Wherever you are, you get the same controls — self-service, no request form needed:

  • Access & portability: export everything anytime (Settings → Export) as JSON or CSV.
  • Rectification: every record you enter can be edited or removed in the app.
  • Erasure: delete your account in Settings; it takes effect immediately.
  • No sale, no ads: there is nothing to opt out of — we don't sell or share personal information as defined by the CCPA.

Cookies

TrackAUM sets only strictly-necessary cookies: a session cookie and a sign-in token, both HTTP-only. Your theme preference lives in your browser's local storage. There are no advertising or cross-site tracking cookies, so there is no cookie banner to click.

Changes & contact

If this policy changes materially, the effective date above will change and the app will point it out. Questions or requests: privacy@trackaum.app.