← Back to HaboFi

Privacy Policy

Last updated: August 2026

HaboFi ("we", "our", or "the app") is a personal stock portfolio tracker available at habofi.eu. This policy explains what data we collect, how we use it, and your rights.

1. Data We Collect

  • Account data — your email address and hashed password when you register, or your Google account name and email if you use Google Sign-In.
  • Portfolio data — holdings, transaction history, pies, and AutoInvest plans you add or import (via CSV upload or a connected Trading 212 API key), stored in our database so your portfolio is available across devices.
  • Trading 212 API key — if you connect your Trading 212 account, your API key is encrypted before storage (see section 3) and used only to fetch your portfolio positions on your request.
  • Transaction log — buy/sell records you manually log inside the app, stored in your browser's localStorage (never sent to our servers).
  • Usage data — anonymous page-view events collected via Google Analytics (see section 4).

2. How We Use Your Data

  • To authenticate you and load your portfolio on any device.
  • To display real-time prices, news, and AI-generated analysis relevant to your holdings.
  • To improve the app based on aggregate, anonymised usage patterns.
  • We do not sell your data, use it for advertising, or share it with third parties for their own purposes.

3. Data Storage & Security

Your account and portfolio data is stored in Supabase (PostgreSQL), hosted in the EU. Supabase encrypts data at rest and in transit using TLS. Access is restricted by row-level security policies so each user can only read their own records.

If you connect a Trading 212 account, your API key is encrypted with AES-256-GCM before it is stored — the key needed to decrypt it is held only in our server environment, never in the database, and is never sent to your browser.

Transaction history you log by hand, and certain preferences (theme, hidden values), are stored only in your browser's localStorage — this data never leaves your device. Portfolio data you import or sync is stored in the database described above.

To keep the app fast we cache some results in Upstash Redis for short periods. Most of what is cached is market data that has nothing to do with you — prices, charts, company profiles. The one exception is your portfolio value history, which is cached against your account ID for at most one hour so the dashboard chart does not have to be rebuilt on every visit. Deleting your account clears it immediately rather than waiting for it to expire.

4. Third-Party Services

ServicePurposeData shared
SupabaseDatabase & authenticationEmail, hashed password, portfolio rows
VercelHosting — every request to the site is served by themIP address and request logs
Upstash (Redis)Short-lived cache & rate limiting, so pages load without re-querying on every visitYour account ID with a cached copy of your portfolio value history (max 1 hour); IP addresses for rate limiting
Google OAuthSign-in optionGoogle account name & email
Google AnalyticsAnonymous usage stats — only if you accept cookiesPage views (no PII)
Yahoo Finance / FinnhubReal-time stock prices & company newsTicker symbols only
Publisher news feedsHeadlines from Yahoo Finance, CNBC, MarketWatch, Nasdaq, Seeking Alpha and Google NewsNone — our server fetches public feeds; nothing about you is sent
Image CDNsCompany logos & article thumbnails, loaded straight into your browserYour IP address and browser user-agent, as with any image on the web
Anthropic (Claude)AI stock analysis, when you request itTicker name and public financial figures — no account or portfolio data
Trading 212Optional portfolio sync you initiateYour encrypted API key, read-only, only when you trigger a sync
ResendSending contact-form emails & alertsName, email, and message you submit

5. Cookies

HaboFi uses session cookies set by Supabase to keep you signed in. We do not use advertising or tracking cookies. Google Analytics uses its own cookies (_ga, _gid) to count anonymous visits — you can opt out via the Google Analytics opt-out browser add-on.

6. Data Retention

Your account and portfolio data is kept for as long as your account is active. Deleting your account from the Account page permanently erases all associated data immediately — every stored row, your login itself, and any cached copy of your portfolio history. There is no waiting period. localStorage data is stored on your device indefinitely until you clear it manually, and clearing your browser data removes it.

7. Your Rights

Under the GDPR (if you are in the EU/EEA) you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data (edit any imported transaction from the Transactions page).
  • Request deletion of your account and data — self-serve from the Account page, effective immediately.
  • Export your portfolio data — self-serve as a JSON download from the Account page.

You don't need to contact us for any of the above — they're available directly in your account. For anything else, reach us at the email below.

8. Children's Privacy

HaboFi is not intended for anyone under the age of 16. We do not knowingly collect personal data from children.

9. Changes to This Policy

We may update this policy occasionally. When we do, we'll update the "Last updated" date at the top. Continued use of HaboFi after changes constitutes acceptance of the updated policy.

10. Contact

Questions about this policy? contact@habofi.eu