Foliotron Privacy Policy

Version 1.40 — 23 September 2026

Foliotron lets you track your investment portfolio, transactions, research notes, images, reminders and alerts. This policy covers the application at app.foliotron.com and the website foliotron.com, including the early-access signup form.

Everything privacy-sensitive is readable by you alone. Your amounts and quantities, and all the text you write yourself (notes, research, investment cases and portfolio strategies), are encrypted under a data key only you can open. Foliotron cannot read any of it. The shape of your portfolio does stay readable: dates, transaction types, instruments, platforms and names, including those of positions you no longer hold. Exactly what is and is not encrypted is stated per category in section 2 and summarised in section 5. One consequence comes with that, and you should know it before creating an account: if you lose both your password and your recovery code, without a device you are still logged in on and without the optional server copy of your key, nobody can open your encrypted data any more.

Foliotron processes only the personal data needed to run the application, secure accounts, store your preferences and resolve technical issues. Foliotron does not sell your data, and never uses your financial or portfolio data for advertising or for third-party marketing profiles.

Foliotron may hold financial information you consider sensitive. Access to data is therefore kept limited, and technical and organisational security measures apply. Foliotron does not use your portfolio data or research notes to give you personal investment advice, assess your creditworthiness, or make automated decisions with legal or similarly significant effects.

Your portfolio is yours alone. Foliotron has no administrator view of your portfolio and no way to log in as another user: your quantities, amounts, transactions, returns and research notes are visible only inside your own account.

As with any self-hosted application, the administrator of Foliotron has technical access to the servers and the database. Your amounts and the text you write are not readable there: they sit behind a data key only you can open (section 5). The shape of your portfolio does stay readable: dates, transaction types, instruments, platforms and names. That access exists solely for system administration, meaning maintenance, backups, security and resolving faults. The administrator does not use it to look at users' portfolios or research notes.

What the administrator can and cannot see, and what leaves the server, is set out in plain language on the page Transparency: what only you can read.

1. Who is responsible?

The controller responsible for your personal data is:

Dyon Beaart (sole proprietorship / eenmanszaak, trading as Foliotron)
Chamber of Commerce (KvK): 22049671
Email: hello@foliotron.com

This address is available for any privacy questions, requests, or complaints.

2. What data does Foliotron process and why?

2a. Account data

What
Email address, first name, last name (optional), profile picture (optional), subscription tier. Your password itself is neither transmitted nor stored: your browser derives a login value from it, and only a bcrypt hash of that value is kept (irreversible). Foliotron additionally stores two encrypted copies of your personal data key, one locked with your password and one with your recovery code; see section 5.
Why
To create your account, authenticate you, and provide access to the application.
Legal basis
Performance of a contract (Art. 6(1)(b) GDPR).
Retention
For the duration of your account. Erased within 30 days of account deletion.

2b. Portfolio data

What
Platforms (broker names, currencies, notes), positions (instrument names, ISIN codes, quantities, purchase prices, strategy labels, conviction level, notes), the investment case per instrument (core idea, assumptions, invalidation criteria, risks, catalysts, expected outcome, open questions, and per saved version an optional short note, the source of the change and the date; for a review also your verdict and note), transactions (purchases, sales, transfers in and out, dividends, fees, coupons, staking rewards, airdrops — with date, amount, currency, and optional notes), cash accounts (name, currency, optional account label, balances, transactions).
Why
To record, track, and analyse your investment portfolio. This is the core functionality of Foliotron.
Legal basis
Performance of a contract (Art. 6(1)(b) GDPR).
Retention
For the duration of your account. Every saved version of the investment case, the note on an instrument, a portfolio's strategy and description and the note on a platform is kept, so you can read back and restore earlier versions; older versions are not deleted automatically. After account deletion, portfolio data, including all kept versions, is erased within 30 days.

Encryption. Quantities, prices, fees and amounts, cash movements and balances, the notes on a transaction, a cash movement or a platform, the investment case including every saved version, and a portfolio’s strategy and description are stored encrypted under your personal data key (section 5). What stays readable: the date and type of a transaction, which instrument and which platform it concerns, and the names of your portfolios, platforms and accounts. Foliotron can therefore see what you hold or have held and when you traded, not how much.

Importing transactions

When you import transactions from a broker or exchange file, that file is parsed in your browser and is never uploaded or stored. Only the resulting transactions are saved. To make a later import automatic, Foliotron remembers, per account, how a line in your file maps to an instrument (its ISIN, the product label as your broker names it, and the exchange code) and which import format that account uses.

If an import fails, you can optionally share your file with a support report. Only then is the file uploaded — the entire file, including any worksheets the import does not read. It is visible only to the administrator and deleted after at most 30 days (see 2p).

If Foliotron does not recognise the file format, you can map the columns yourself. You may then optionally share that column mapping to improve importing for other users. In that case only the column mapping and format settings (column headers and parsing hints) are submitted — never the data from your rows.

Connecting a crypto exchange

You can optionally connect a platform to a crypto exchange or platform (Kraken, Bitstamp, Bitfinex, Iconomi, eToro or Bitvavo) using a read-only API key that you create at that exchange yourself. That key and its secret are stored on the server encrypted under your personal data key (section 5), like your amounts; the server can only use them while you are using the app. Connecting verifies the key by making a read request to the exchange on your behalf; where the exchange makes this verifiable, a key that can withdraw funds or place orders is refused. You can disconnect at any time, which deletes the stored credentials immediately.

Foliotron uses that key to read your trade history, incoming and outgoing crypto transfers and balances from the exchange, and stores them as transactions in your portfolio — the same data you would otherwise enter manually or through a file. This happens on the server: when the app is opened and the last synchronisation is more than an hour old, and whenever you press sync yourself. Alongside the transactions, the exchange's original data is kept (trade id, market, amounts, fees, timestamp and, for on-chain transfers, the transaction hash and destination address) so that an import stays repeatable and auditable. The last balance read per coin is kept so differences with your portfolio can be shown. This is separate from the file import above, which continues to be parsed entirely in your browser.

2c. Research items and notes

What
Titles, freeform notes (text), links to external sources, tags, information about which user created or modified the item, archived items, favorite markings, and (on import) the original publication date of the source.
Why
To help you track and organise investment research.
Legal basis
Performance of a contract (Art. 6(1)(b) GDPR).
Retention
For the duration of your account. Every saved version of a research note's text is kept, so you can read back and restore earlier versions; older versions are not deleted automatically. Erased within 30 days of account deletion, including all kept versions.

Encryption. The text of a research note and of a saved article is encrypted under your personal data key (section 5), including every saved version. The title, link, source, author, dates and tags stay readable: the title sits in the note’s URL. An article Foliotron fetches for you waits readable on the server until you first open the note; after that its text is encrypted too.

2d. Reminders and alerts

What
Reminder titles, notes, due dates, price alert thresholds, links to instruments or research items, per-reminder notification preferences (email and push).
Why
To notify you of relevant dates or price events.
Legal basis
Performance of a contract (Art. 6(1)(b) GDPR).
Retention
For the duration of your account. Erased within 30 days of account deletion.

2e. Settings

What
Display currency, language and locale preference, notification preferences (push and email for dividends and earnings), default dividend tax rate.
Why
To personalise the application to your preferences.
Legal basis
Performance of a contract (Art. 6(1)(b) GDPR).
Retention
For the duration of your account. Erased within 30 days of account deletion.

2f. Optional third-party integrations

What
Username and encrypted password, or API key and encrypted secret, for optional external integrations (such as Beleggers Belangen) — only if you choose to set them up. Credentials are encrypted using AES-256-GCM (256-bit key) under your personal data key (section 5), and can therefore only be opened while you are in the application yourself. Keys for exchange connections (including Iconomi) are covered by the exchange connection above.
Why
To retrieve data from the relevant external service on your behalf.
Legal basis
Consent (Art. 6(1)(a) GDPR). You grant consent by configuring the integration yourself. You can delete these credentials at any time via your account settings.
Retention
Until you delete the integration or close your account.

2g. Uploaded images

What
Image files you upload (e.g. screenshots), including file name, format, and SHA256 hash.
Why
To display images within your research notes.
Legal basis
Performance of a contract (Art. 6(1)(b) GDPR).
Retention
For the duration of your account, or until you delete the image.

Encryption. Uploaded images are not encrypted under your personal data key. A screenshot of a statement or a portfolio overview is therefore readable on the server, even when the note around it is not.

2h. Push notification subscriptions

What
Browser-generated endpoint URL and cryptographic keys for web push notifications, if you enable push notifications.
Why
To send push alerts for reminders and price events.
Legal basis
Consent (Art. 6(1)(a) GDPR). You grant consent by enabling push notifications in your browser. You can withdraw consent at any time via your browser or account settings.
Retention
Until you withdraw consent or delete your account.

2i. Login events and security logs

What
Timestamp of login attempts, success or failure, browser and device information (user agent), and failure reason. IP addresses are used temporarily for rate limiting (to prevent brute-force attacks) but are not stored permanently in the database.
Why
To monitor account security and detect and prevent abuse.
Legal basis
Legitimate interest (Art. 6(1)(f) GDPR). The interest is the security of the application and your account.
Retention
90 days, after which records are automatically deleted.

2j. Usage events (product analytics)

What
Records of general usage actions such as viewing the dashboard, viewing an instrument or research item, or creating a transaction or research item. No page URLs or detailed session data are stored.
Why
To understand how the application is used so Foliotron can be improved.
Legal basis
Legitimate interest (Art. 6(1)(f) GDPR). Data minimisation is applied: Foliotron records only broad usage actions and does not collect detailed click paths, heatmaps, or advertising profiles.
Retention
90 days, after which records are automatically deleted.

2k. Technical error logs

What
Server errors including API route, HTTP method, user ID, browser and device information, and error details. Additionally, errors during file imports: the error code and technical characteristics such as column headers, row count, file size and file type — never cell values or file names. Personal data is minimised in these logs.
Why
To identify and resolve technical issues.
Legal basis
Legitimate interest (Art. 6(1)(f) GDPR).
Retention
30 days.

2l. Transactional emails

What
Email address, name, language preference, and content of transactional messages such as account notifications, security alerts, reminders, price alerts, or system updates. In addition, delivery information is recorded per message sent (subject, delivery status and, on a failed delivery, the reason such as a bounce or block) to detect deliverability problems. This delivery information is linked to your account so deliverability problems can be traced per user. Emails are sent via Mailjet (EU). Tracking techniques are disabled per message: emails contain no tracking pixel and links are not rewritten — whether you open an email or click its links is not recorded.
Why
To send necessary or user-configured messages about your account and use of Foliotron, and to monitor their delivery.
Legal basis
Performance of a contract (Art. 6(1)(b) GDPR) for necessary account and service emails. Consent or user preferences for optional notifications. Recording delivery status relies on legitimate interest (Art. 6(1)(f) GDPR): monitoring the deliverability of sent emails.
Retention
For the duration of your account, or as long as needed for delivery, security, and error handling.

2m. AI integration (optional)

AI features are entirely optional and only active if you supply your own API key from a third-party provider (Anthropic, OpenAI, or Google). When AI features are enabled:

What
Instrument names, position sizes, tags, vision fields (strategy, conviction, horizon, portfolio role), notes, research items, transactions, dividends, and, if you have cash accounts enabled, cash positions (platform names, account labels, currencies, and current balances; this option is on by default for new accounts and can be switched off under Settings → AI) — as selected by your context permissions in Settings → AI.
Why
To answer questions and generate proposals in the portfolio chat. Data is sent only when you actively use the chat and only for the categories you have enabled.
Legal basis
Explicit consent (Art. 6(1)(a) GDPR). You provide consent by entering your API key and accepting the AI consent modal. Consent can be withdrawn at any time by disabling AI or deleting your API key in Settings → AI.
Retention
Foliotron does not log or store prompts or responses. Interaction metadata (provider, model, token counts, duration, success) is stored in AiInteractionLog for the lifetime of your account if the audit log is enabled. Conversation messages are stored only if you enable conversation retention, and only for the lifetime of your account.

Your API key is stored encrypted (AES-256-GCM) under your personal data key (section 5). Your AI documents and, if you enable conversation retention, the content of your conversation messages are encrypted the same way. To answer a question, Foliotron opens the data involved with your key at the moment of your request, and sends only the categories you enabled to the provider you chose. Foliotron never shares your API key with any party other than the AI provider you select. Switching provider clears your prior consent and requires a new acknowledgement before AI features re-enable.

AI web and financial news search (optional)

When the administrator has enabled web search, the AI assistant can perform searches via Brave Search and fetch public web pages. Search queries may contain instrument names or research topics. These queries are processed by Brave Search (Brave Software, Inc., United States). This only occurs when you explicitly ask the AI to search the web during a chat session. No directly identifying personal data such as your name or email address is included in search queries.

In addition, the AI assistant can fetch financial news and live quotes from Yahoo Finance to answer questions about market movements (for example "why is crypto up today?"). Requests may contain tickers, instrument names, or market topics, and are only sent when you ask a relevant question in the AI chat. No directly identifying personal data is included.

Voice input (dictation, optional)

When the voice input (dictation) feature is used, the browser captures a short audio recording and sends it to the Foliotron server. The server forwards it to OpenAI for transcription. The audio is processed entirely in memory and is never written to disk or stored in any database. OpenAI's data processing terms apply to this audio data.

Text extraction from images (optional)

When you explicitly run text extraction on an image, the Foliotron server sends that image to the AI provider you selected in Settings → AI (Anthropic, OpenAI, or Google) so the text in it can be read. This happens only on that explicit request and is covered by the same per-provider consent as the other AI features. The image is processed entirely in memory: for this feature Foliotron does not store the image separately, and the extracted text is not logged. An image you insert into a note is of course kept as an upload (see section 2g). The data processing terms of the selected provider apply to the transmitted image.

2n. Cookies and local storage

What
Session cookie (foliotron_session): contains a JWT with user ID and role (no email address). Local storage: UI preferences (including chart range, ‘hide amounts’, panel width, feedback-button visibility, the language chosen on the login page), per-instrument UI hints, local-cache timestamps, and temporary share state (cleared immediately after use). Session storage (cleared when you close the tab): the ongoing AI chat — your messages and the replies — and a few UI states. Local cache (IndexedDB): downloaded prices and exchange rates, and a local copy of your portfolio, transaction and balance data so pages load instantly; plus your user ID to keep the cache isolated per user.
Why
The session cookie is strictly necessary for authentication. Local storage retains functional preferences so the application behaves as expected. The local cache speeds up loading and is always re-fetchable from the server.
Legal basis
The session cookie is strictly necessary to provide the service. For functional local storage and cache, Foliotron relies on legitimate interest (Art. 6(1)(f) GDPR): remembering user preferences, speeding up the application, and keeping data isolated per user.
Retention
Session cookie: until 90 days after your last visit (every visit extends it), deleted on logout. Local storage and cache: until browser storage is cleared or the user deletes the data. Session storage: until you close the tab. Your account-specific cache (portfolio, transactions, balances) and your user ID are cleared on logout; they can also be cleared manually via Settings.

Foliotron does not place tracking cookies, advertising cookies, or third-party analytics cookies.

The website foliotron.com sets one functional cookie (foliotron_lang) that remembers the language you chose, and keeps your light or dark display choice in your browser's local storage. Both are functional and require no consent.

2o. Waitlist and invitation data

What
If you sign up for early access (or are invited manually): name, email address, language preference, the interests you select (such as testing, an interview, or staying informed), and optionally which tool you currently use to track your portfolio. For an invitation, the invitation status and an encrypted (hashed) invitation token with an expiry date are also stored. This signup does not create an account yet. In addition, an existing user can sign you up via the ‘invite a friend’ feature: in that case your name (optional) and email address are placed on the waitlist, together with a reference to the user who signed you up, and you receive a single email about this. If you do not want this, you can reply to that email and your details will be removed immediately.
Why
To manage interested testers, send early-access invitations, and follow up on signups.
Legal basis
Taking steps at your request prior to entering into a contract (Art. 6(1)(b) GDPR), and legitimate interest (Art. 6(1)(f) GDPR) in managing beta access.
Retention
Until you create an account, or until the signup is declined or deleted. Signups that are not followed up are periodically purged.

The signup form on foliotron.com forwards what you enter straight to this waitlist in the application; the website itself keeps no copy.

2p. Feedback messages (beta testers)

What
When you submit a feedback message via the feedback button: the content of your message (free text, up to 5,000 characters), an optional screenshot of the page at the time of submission (stored as an image on the server), the page URL, the application route, your viewport dimensions, browser and device information (user agent), language setting, theme, app version, the coordinates of your click on the screenshot, and — where available — the component context at the clicked location. When this screenshot is captured, the ‘hide amounts’ feature is applied automatically so monetary amounts, portfolio values, and similar financial figures are not visible in the image. When reporting an import problem, you can additionally attach your import file; that file is then stored on the server in its entirety — including any worksheets the import does not read — and is visible only to the administrator. You can read back your own feedback messages and the administrator's replies under ‘My feedback’ and reply there yourself; those replies are stored with the message. When the administrator replies to your feedback or marks it done or closed, you receive an email about it at your account address; the reply text is included in that email. Optionally, you can include a summary of your local browser data when sending (off by default, ticked per message): counts and date ranges of the locally stored price, exchange-rate and transaction data, the identifiers of the instruments the page is showing, your time zone, screen density and the version of the local storage. Amounts, prices, exchange rates and transaction rows are never sent.
Why
To receive, prioritise, and act on bug reports, UX issues, and feature requests from beta testers, and to let you know what happened with them.
Legal basis
Legitimate interest (Art. 6(1)(f) GDPR): improving the application based on active user feedback. You submit feedback entirely at your own initiative. The feedback feature is enabled for all users and can be disabled per account by the administrator.
Retention
Feedback messages and associated screenshots are retained for the duration of your account or until they are no longer needed for product development. Screenshots are deleted when your account is deleted. Attached import files are automatically deleted after at most 30 days, and immediately when your account is deleted. An included local data summary is kept together with the feedback message.

2q. Connected external apps (MCP connections)

What
When you connect an external app to your account (for example an AI assistant): the name the app states for itself, the address it sends you back to, the permissions you approve, your setting per kind of data of what a connected app may read and write, and the access keys issued as a result. Keys are stored only as a hash, never in readable form. While the connection is active the app can request your portfolio data — value and price moves, positions, strategy/goals document, benchmark, transactions, dividends, cash accounts, per-instrument notes and reviews, research notes, watchlist, upcoming events, and reminders — and, only where you switch it on per kind of data under Settings → AI, write as well: your investment case and a review on it, a research note, the note on an instrument, a portfolio's strategy document, and create, snooze or complete a reminder. Writing is off by default. Every change made by an app is kept as a new version, with the app as its source, next to the versions you save yourself (section 2), and you can restore an earlier version. A day allows at most 100 changes and 20 emails; that count keeps only a number per day, no content, and expires after two days. The app can also, if you approve that permission, email you at your own account address. The app cannot delete anything, cannot add or change transactions, and cannot email anyone else. Foliotron does not record which data the app requests or what it does with it; what the app does with your data afterwards is governed by that provider's own privacy policy.
Why
To let you use your own data in an external app of your choosing, and to let you withdraw that access.
Legal basis
Consent (Art. 6(1)(a) GDPR): a connection is only established after you explicitly approve it on the consent screen, with each permission named. What an app may read and write you set per kind of data under Settings → AI as well; the consent screen shows that setting at that moment. You can withdraw the connection.
Retention
Access keys expire after one hour, refresh keys after at most 90 days of disuse. Revoked or expired keys are deleted after 30 days; registrations for apps that were never connected after 30 days of disuse.

Encryption. A connected app does not hold your data key and therefore cannot read the encrypted fields, not even while you are in the application yourself; if the app asks for them, it gets them back marked as encrypted. What stays readable to the app is what stays readable per section 2: which instruments you traded and when, names, dates and reminders. If you want the app to read your amounts and texts too, you can have a server copy of your data key kept; see section 5. That option is off by default.

3. Who has access to your data?

Administrator: Dyon Beaart has the only direct access to the production database. That access reaches the data that stays readable per section 2. It cannot open the encrypted fields: the administrator does not hold your data key (section 5), unless you have switched on the optional server copy of it yourself.

Apps you connect yourself: if you connect an external app to your account (section 2q), that app can request your portfolio data for as long as the connection is active. Such an app is not engaged by Foliotron and is therefore not a Foliotron processor: you grant the access yourself and can withdraw it yourself.

A full overview of external service providers and processors is included in section 10.

Your data is not sold to third parties or used for advertising.

4. How long is your data retained?

See the retention periods per category in section 2. As a general rule: active personal data in the application database is deleted within 30 days after you close your account or after a deletion request is processed.

Backups: deleted data may temporarily remain in secure backups. These backups are not actively used to restore deleted accounts, except where necessary for security, error recovery, or legal obligations. The database is backed up every night to AWS storage within the EU; in addition, a snapshot of the full server is taken daily. Every backup and every snapshot is deleted automatically after at most 30 days. Deleted data is therefore gone from all backups at most 30 days after it is removed from the active database. What is stored encrypted is encrypted in the backup too.

Loss of your data key: if you recover your password without a recovery code, without a device you are still logged in on and without the optional server copy of your key (section 5), the encrypted data that has thereby become unrecoverable is deleted immediately, ahead of the periods stated in section 2. See section 5.

5. Security

Encryption under your own data key

When your account is created, your browser generates a random 256-bit data key, which is used to encrypt your data with AES-256-GCM. That key is stored nowhere in unencrypted form. The server keeps two encrypted copies of it: one locked with a key derived from your password (PBKDF2-SHA256, at least 600,000 iterations) and one with a key derived from a 32-character recovery code, shown to you once when your account is created. Devices you are logged in on keep a third encrypted copy locally. Your password and your recovery code are themselves stored nowhere.

The server does not receive your password. Your browser derives a login value from it, and a bcrypt hash of that value is stored on the server (irreversible). While you use the app, your browser sends your data key with every request over the secure connection. The server uses it only for as long as that request runs, or for as long as an exchange synchronisation that request started runs (a few minutes, even if you close the tab), and does not hold it in a session. It is not stored on the server, unless you switch on the optional server copy below yourself. If you change your password, only the encrypted copy of the key is re-locked, and your data is not re-encrypted.

Which data is encrypted and which stays readable is stated per category in section 2. In summary: amounts, quantities, prices and fees, and the free text you write (notes, investment cases and their versions, portfolio strategies, AI documents and conversation messages) are encrypted. What stays readable: dates, transaction types, instruments, platforms, the names of portfolios, platforms and accounts, tags, the titles and links of research notes, reminders, the composition of your benchmark, your settings, and uploaded images.

Consequence. If you lose your password and your recovery code while no longer logged in on any device, nobody can open your encrypted data any more, Foliotron included. A password recovery then creates a new data key and deletes the data that can no longer be opened. That is confirmed three separate times beforehand. If you still have your recovery code, are still logged in on a device, or have switched on the optional server copy below, your data remains intact.

Optional server copy of your data key

If you want an external app you connected (section 2q) to be able to read your encrypted data as well, you can have an additional encrypted copy of your data key kept, locked with a key managed in AWS Key Management Service (eu-central-1) that the server unlocks only at start-up. That copy has a second consequence: if you lose your password and your recovery code, the password recovery through your email address returns your data key from this copy and your data is preserved. This option is off by default, is enabled only at your own request, and can be withdrawn at any time; the copy is then deleted immediately. While the option is on, anyone with full access to the running server can technically open your encrypted data, and anyone with access to your email address can replace your password through the password recovery and keep your data. The server's key is not stored readably in a backup; a backup on its own cannot open the copy.

Other measures

  • Sessions expire 90 days after your last visit (every visit extends them) and are managed via a secure session cookie with the HttpOnly, Secure (in production), and SameSite=Lax flags.
  • Access to the server and database is restricted to the administrator, and reaches no further than the readable data listed in section 2.
  • Backups contain the same encrypted fields as the database: a backup holds no readable amounts and no readable notes.
  • The application is hosted on AWS infrastructure within the EU.
  • All connections use HTTPS.
  • Rate limiting is applied to login attempts to prevent brute-force attacks.
  • The password policy (at least 8 characters, with an uppercase letter and a number or symbol) is enforced at registration, invitation, password change and password recovery.

6. Your rights under the GDPR

  • Access — you can request an overview of the data held about you.
  • Rectification — you can ask for inaccurate or incomplete data to be corrected.
  • Erasure — you can ask for all your data to be deleted.
  • Restriction of processing — in certain cases, you can ask for processing to be restricted.
  • Data portability — you can request an export of the data you have entered yourself.
  • Object — you can object to processing based on legitimate interest.
  • Withdrawal of consent — for processing based on consent (push notifications, external integrations), you can withdraw consent at any time without affecting the lawfulness of prior processing.

7. Complaints

If you believe your personal data is not being handled correctly, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens):

Website: autoriteitpersoonsgegevens.nl
Phone: +31 88 - 1805 250

Reaching out first at hello@foliotron.com to resolve the concern before escalating is appreciated.

8. How to exercise your rights

Send an email to hello@foliotron.com with the subject "GDPR request" and a description of your request. A response will be provided within 30 days.

Identity verification may be requested before processing your request.

9. Data breaches

When a security incident involving personal data occurs, Foliotron assesses whether a data breach has taken place under the GDPR. Where notification to the Autoriteit Persoonsgegevens (Dutch DPA) is required, this will be done without undue delay and, where feasible, within 72 hours after Foliotron becomes aware of the breach. Affected individuals are notified when the breach is likely to result in a high risk to their rights and freedoms.

10. Current processors and external services

Foliotron maintains an up-to-date overview of external service providers that process or may process personal data. When a new service provider relevant to personal data is added, this policy will be updated.

Market data is fetched server-side by Foliotron. External market data providers do not receive directly identifying user data such as name or email address and do not know which user tracks which instrument. Foliotron only uses the public ticker symbols or instrument IDs required for the market data request.

Service provider Role Personal data Location
Amazon Web Services (AWS)Hosting & infrastructureYes — processorFrankfurt, DE (EU)
Yahoo Finance Public financial data and, when you use AI, quotes and financial news on request No — server-side requests contain tickers or market topics; no identifying user data —
CoinGeckoPublic crypto data No — server-side system requests; no identifying user data —
Mailjet (Sinch) Sending and delivery of transactional emails Yes — processor. Email address, name, language preference, message subject and content, and delivery status. Open and click tracking is disabled per message EU
Anthropic, OpenAI or Google (optional) AI language model (portfolio chat, when enabled) Yes — investment data you choose to share via the AI chat (see section 2m). Only processed when you actively use AI features with your own API key. Which provider is used depends on your choice in Settings → AI. And, when voice input is used, short audio recordings for transcription; when text is extracted from an image, that image. United States
Brave Search (optional) Web search from AI chat (when enabled by administrator) Search queries may contain instrument names or research topics. No name or email address is included. Only when you explicitly ask the AI to search the web. United States
Bitstamp Ltd (optional) Exchange data source (only if you connect it yourself) Requests are signed with your own API key. No Foliotron account data is shared United Kingdom / Luxembourg
Payward Inc. (Kraken) (optional) Exchange data source (only if you connect it yourself) Requests are signed with your own API key. No Foliotron account data is shared United States
iFinex Inc. (Bitfinex) (optional) Exchange data source (only if you connect it yourself) Requests are signed with your own API key. No Foliotron account data is shared British Virgin Islands
Bitvavo B.V. (optional) Exchange data source (only if you connect it yourself) Requests are signed with your own API key. No Foliotron account data is shared Netherlands
ICONOMI Limited (optional) Strategy data source (prices are public; your balance and activity only if you connect it yourself) Requests for your data are signed with your own API key. No Foliotron account data is shared United Kingdom
eToro (Europe) Ltd (optional) Broker data source: your positions, trade history and copy relationships (only if you connect it yourself) Requests are signed with your own API key. No Foliotron account data is shared Cyprus
Payment provider (planned)Payments & subscriptionsYes — processorTBD

11. Data transfers outside the European Economic Area

Foliotron strives to process personal data within the European Economic Area. The application is hosted on AWS in Frankfurt, Germany. When a service provider processes personal data outside the European Economic Area, this will only occur where a valid legal basis exists, such as appropriate contractual safeguards.

12. Changes to this policy

This policy will be updated when the application or its data processing changes. The version number and date at the top of this document indicate when it was last revised. For significant changes, you will be notified via the application or by email.