Privacy Policy

Last updated: August 5, 2026

Our Privacy Promise

  • Your investment data is encrypted the moment we receive it.
  • We never sell it, share it for advertising, or train AI on it.
  • Only you decide who else ever sees it.

1. Introduction

MyInvestFolio (“we”, “our”, or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use MyInvestFolio — our two-tier portfolio infrastructure (Continuity System and Portfolio Clarity).

2. Information We Collect

2.1 Personal Information

We collect information that you provide directly to us, including:

  • Name and email address
  • Country and billing information
  • Password and authentication credentials
  • Investment portfolio data (amounts, types, currencies) — stored encrypted at rest so that even our own engineers cannot read the amounts.
  • Communication preferences
  • Continuity System data you choose to add — the names and contact details of Trusted Contacts you appoint, plain-language notes about each asset, and any documents you upload (statements, agreements, custody letters).
  • Verification information from your Trusted Contacts — government-issued ID images and a live selfie check — collected only if and when a Continuity release is triggered.

When you add a Trusted Contact, you are asked to confirm you have their permission to record their name and contact details. We do not contact them unless the Continuity release process begins.

2.2 Automatically Collected Information

When you access our platform, we automatically collect:

  • Device information (browser type, operating system)
  • IP address and location data
  • Login history and security logs
  • Usage data and analytics

IP addresses and device information are used only to detect suspicious sign-ins and are automatically deleted after 90 days unless part of an active security investigation.

3. How We Use Your Information

Your investment data belongs to you. We use the information you give us for five narrow purposes — and nothing else.

What we use your data for:

  1. To run your account. Log you in, keep your portfolio visible to you, and let you edit or export it at any time.
  2. To keep you secure. Send you security alerts, detect suspicious sign-ins, and block brute-force attacks on your account. We look at login patterns, never at your investment amounts.
  3. To bill you. Process your subscription payment through Stripe. We never see or store your card number.
  4. To let you reach us. Reply to your support emails and account questions.
  5. To run the Continuity System check-in cycleonly if you have activated it. Every 90 days we send a brief “I’m well” email you can dismiss with one click. If you stop responding for an extended period, the verified two-administrator release process described in Section 5 is triggered — and nothing releases automatically.

On rare occasions, when we receive a court order naming a specific account, we minimise our response to the narrowest possible scope, formally challenge any request that is vague or overbroad, notify the affected account holder unless a court prohibits us from doing so, never volunteer data, and publish an annual transparency report showing the number of requests received and how many we complied with.

What we will NEVER do with your data — full stop:

  • We will never sell, rent, licence, share, or monetise your investment data. Not in aggregate, not anonymised, not “for research”, not ever.
  • We will never train AI or machine-learning models on your investment data, and we do not use any third-party AI service that would.
  • We will never look at your portfolio values to profile you or infer your net worth for marketing.
  • We will never send you promotional emails about products from other companies. Your inbox from us contains only: security alerts, service updates, and (if opted in) our own product news.
  • We will never use tracking pixels, ad-network cookies, or behavioural analytics that follow you around the internet.
  • We will never grant our own staff access to decrypted investment values except through a strictly logged, Owner-only pathway or the verified two-administrator Continuity release described in Section 5.

Every field containing an amount, valuation, holding or personal identifier is stored encrypted at rest (see Section 4). Even if someone stole our database tomorrow, your numbers would look like random text.

4. Data Security

We implement industry-standard security measures to protect your data, including:

  • Field-level encryption at rest (AES-128 / Fernet): sensitive personal data (email, full name, username) and all financial data (investment amounts, valuations, prices, mortgages, interest rates and other monetary fields) are encrypted in our database. Even with raw database access, these values are unreadable without our encryption key.
  • Password hashing (Argon2id): passwords are stored as one-way Argon2id hashes (OWASP-recommended, 2023). We can never recover or read your password — not even our engineers.
  • TLS in transit: all traffic between your device and our servers is encrypted end-to-end over HTTPS/TLS.
  • JWT token-based authentication: stateless auth with short-lived tokens; no third-party tracking cookies are required for login.
  • Two-factor authentication (2FA): optional TOTP-based second factor via your authenticator app.
  • Login anomaly detection & alerts: we monitor for new-device logins, unusual locations, and brute-force attempts, and email you when something looks off.
  • Audit logging: sensitive operations (admin views, password changes, account deletion) are recorded for compliance traceability.
  • Regular security reviews: periodic code-health scans and penetration-style testing as we approach security certification.

5. Data Sharing and Disclosure

🛡️We do not sell, rent, or share your personal investment data with any third party — full stop. Only you decide who else ever sees your portfolio.

Continuity System — a controlled exception. If, and only if, you have set up Continuity System and the check-in cycle completes without response, the specific items you nominated may be released to the specific Trusted Contacts you chose. Nothing happens automatically.

We use a limited number of third-party services (sub-processors) to operate the platform. These services process data strictly on our behalf and under our instructions:

Sentry — Error Monitoring

Collects anonymized error reports (stack traces, browser info) to help us identify and fix bugs. Does not access your investment data. If you reject cookies, Sentry data is fully anonymized with no user identifiers.

Resend — Transactional Emails

Processes your email address solely to deliver security alerts, verification emails, and account notifications. No investment data is shared.

MongoDB Atlas — Data Storage

Cloud database hosting for all platform data. Data is encrypted at rest and in transit. Access is restricted to our application only.

Stripe — Payment Processing (when active)

Processes subscription payments securely. We never store your full card details. Stripe is PCI DSS Level 1 certified.

We may also disclose information when required by law or to protect our legal rights.

6. Your Rights

You have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate information
  • Erasure: Request deletion of your data
  • Portability: Export your data in a machine-readable format
  • Restrict Processing: Limit how we use your data
  • Object: Opt-out of certain data processing

To exercise these rights, contact us at privacy@myinvestfolio.io

7. Data Retention

We retain your personal data for as long as your account is active or as needed to provide services. Continuity System records — including Trusted Contact details and uploaded documents — are retained under your control while your account is active and released only under the verified trigger described above. After account deletion, we may retain certain information for legal compliance and audit purposes.

8. Cookies and Tracking

We use minimal cookies for authentication and security. See our Cookie Policy for details.

9. Children’s Privacy

Our service is not intended for users under 18 years of age. We do not knowingly collect data from children.

10. International Data Transfers & Multi-Country Operations

Our Global Service: MyInvestFolio operates as a multi-country, multi-currency investment platform. We serve users worldwide and support investments in various currencies (USD, EUR, GBP, NGN, and more).

Data Location: Your data may be transferred to and processed in countries outside your residence, including the United States (our primary jurisdiction) and other locations where our service providers operate. We ensure appropriate safeguards are in place for all international transfers.

Legal Compliance: We comply with:

  • US federal and state privacy laws (primary)
  • GDPR (for EU residents)
  • Nigerian Data Protection Regulation (NDPR)
  • Other applicable data protection laws in your jurisdiction

Highest-standard-applied principle: Regardless of where you live, we apply the strictest of the applicable privacy regimes — typically GDPR — to your data by default.

Your Rights: Regardless of your location, you have the rights outlined in Section 6 of this policy, including data access, portability, and deletion.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or platform notification.

12. Contact Us

For privacy-related questions or concerns, contact us at:

Email: privacy@myinvestfolio.io

Data Protection Officer: dpo@myinvestfolio.io

Primary Jurisdiction: United States of America

Global Service: Serving users in multiple countries