Cookie Policy

Last updated: August 5, 2026

1. What Are Cookies?

Cookies are small text files stored on your device when you visit a website. They help websites remember your preferences and improve your experience.

2. How We Use Cookies

MyInvestFolio — across both Continuity System and Portfolio Clarity — uses a minimal, security-focused approach to cookies. Your authentication token is stored locally on your device (not as a browser cookie), with a small session cookie kept only as a fallback.

3. Types of Cookies We Use

3.1 Essential Cookies (Required)

Purpose: Authentication and security

Cookies Used:

  • session_token - User authentication (fallback)
  • admin_session_token - Admin authentication (fallback)

Duration: 7 days

Can be disabled? No - Required for the service to function

3.2 JWT Tokens (Primary Authentication)

Storage Method: localStorage (not cookies)

Token Name: auth_token

Purpose: Primary authentication mechanism

Duration: 7 days

3.3 Optional Analytics & Monitoring (Consent-Gated)

Purpose: Product analytics and error monitoring

Status: Disabled by default. These services only load if you explicitly opt in via the Cookie Consent Banner or the Cookie Preferences panel in Settings.

Services: PostHog (product analytics & session replay) and Sentry (error monitoring). See Section 5 for full details.

Can be disabled? Yes — at any time, with no impact on core functionality.

3.4 What We DON'T Use

MyInvestFolio does NOT use:

  • ❌ Advertising or retargeting cookies
  • ❌ Google Analytics or similar third-party ad-tech trackers
  • ❌ Social media cookies
  • ❌ Marketing or behavioural-profiling cookies
  • ❌ Any tracker that loads before you give consent

4. Cookie Management

4.1 Browser Settings

You can control cookies through your browser settings:

  • Chrome: Settings → Privacy and security → Cookies and other site data
  • Firefox: Settings → Privacy & Security → Cookies and Site Data
  • Safari: Preferences → Privacy → Manage Website Data
  • Edge: Settings → Cookies and site permissions

4.2 Impact of Blocking Cookies

⚠️ Warning: Blocking essential cookies will prevent you from logging in and using MyInvestFolio. Our authentication system requires either JWT tokens (localStorage) or session cookies to function.

5. Third-Party Services

We use the following third-party services. Analytics and monitoring services are strictly consent-gated — they do not load or send any data until you opt in.

Stripe (Payment Processing)

Used for secure payment processing. Stripe may set cookies to prevent fraud and ensure secure transactions.

Stripe Privacy Policy →

Resend (Email Services)

Used for sending transactional emails (account verification, password resets, billing receipts). No cookies are set on your browser.

PostHog (Product Analytics & Session Replay) Consent required

What it collects (only if you opt in): anonymised page views, button clicks, navigation paths, device/browser type, approximate region, and optional session replays (mouse movements, clicks, scrolls). Sensitive form fields, passwords, and financial values are masked by default.

Why we'd like to use it: to understand which features our users use, identify confusing flows, and improve the product.

Default state: Off. The PostHog script is not injected into the page until you grant consent.

How to opt out / withdraw consent: Click "Reject" in the Cookie Consent Banner, or open Settings → Cookie Preferences at any time and toggle Analytics off. Withdrawing consent immediately stops further data collection and clears the PostHog session.

PostHog Privacy Policy →

Sentry (Error Monitoring) Consent required

What it collects (only if you opt in): JavaScript error stack traces, the URL where the error occurred, browser/OS version, and a breadcrumb trail of recent UI actions. Personally identifiable information and request bodies are scrubbed before transmission.

Why we'd like to use it: to detect and fix crashes, broken pages, and performance regressions before they affect more users.

Default state: Off. The Sentry SDK is not initialised until you grant consent.

How to opt out / withdraw consent: Use the Cookie Consent Banner or Settings → Cookie Preferences and toggle Error Monitoring off. Existing buffered events are discarded.

Sentry Privacy Policy →

Manage your preferences anytime: visit Settings → Cookie Preferences. Your choices are stored locally on your device and are honoured on every visit.

6. Data Retention

Session cookies are automatically deleted when you log out or after 7 days of inactivity. JWT tokens in localStorage remain until you explicitly log out or they expire (7 days).

7. Updates to This Policy

We may update this Cookie Policy to reflect changes in our practices or legal requirements. The "Last updated" date at the top indicates when changes were made.

8. Contact Us

If you have questions about our use of cookies, contact us at:

Email: privacy@myinvestfolio.io

Primary Office: Nigeria

Note: We serve users globally across multiple countries

9. Related Policies