Privacy Policy

Last updated: 28 April 2026 · Version 1.0

In short: Portfolio Manager is designed to collect no data. Portfolios, positions and goals stay on your device. There is no app server. Calls to external services (Gemini, EODHD, FMP) only happen if you activate the respective optional features, with your own API key.

1. Overview

This privacy notice describes how PluriFin (Filippo Salemi, a private individual based in Italy) processes personal data in connection with the Portfolio Manager application and the related website.

The data controller is Filippo Salemi, reachable at [email protected]. For GDPR-specific requests: [email protected].

2. Data collected

2.1 App data (local)

All data you enter in the app -- portfolios, positions, goals, settings, API keys -- is stored exclusively on your device, in encrypted storage (AES-256 + HMAC-SHA256). The encryption key is kept in the operating system keystore.

2.2 Website data

  • Pre-launch newsletter sign-up: email + preferred language (handled by Formspree, USA, Standard Contractual Clauses).
  • Contact form: name, email, subject, message (handled by Formspree).
  • GitHub Pages static server logs: IP address, user-agent (max 14-day retention, handled by GitHub).

3. Processing purposes

  • Newsletter: send a launch notification. Legal basis: consent (Art. 6.1.a GDPR).
  • Contact form: respond to support requests. Legal basis: consent and legitimate interest (Art. 6.1.f).
  • GitHub Pages logs: security and abuse prevention. Legal basis: legitimate interest.

4. Third parties

The app may send data to external services only if you enable the relevant optional features:

  • Google Gemini -- AI analysis (user API key).
  • EODHD / FMP -- market prices (user API key).
  • Formspree -- form handling (USA, SCC).
  • GitHub Pages -- static hosting (USA, SCC).

5. User rights

You may at any time exercise the rights under Articles 15-22 GDPR: access, rectification, erasure, restriction, portability, objection. Write to [email protected].

For local data, you can wipe everything from Settings at any time.

6. Contact

General: [email protected]

GDPR requests: [email protected]

7. Changes

Material changes will be communicated on the site and, where required, by email to newsletter subscribers.


The full Privacy Policy will be produced by a legal professional in Wave W3 of the development plan. This text is a preliminary informational version.