Privacy Policy
Last updated
This policy describes what we collect, why we collect it, and who else touches it. It is specific: where a third party processes your data, it is named, along with what it receives and why.
1. Who is responsible
The data controller is Federico Pérez Fernández, pending: registered address. For any privacy question or to exercise a right below, write to [email protected].
We have not appointed a Data Protection Officer, as we are not required to. pending: confirm this remains true for your entity
2. What we collect
| Data | Why we have it |
|---|---|
| Email address and password hash | To create your account, verify it, sign you in and reset your password. Passwords are stored hashed and are never readable by us. |
| Broker API credentials | To read your positions and transaction history. Encrypted at rest; used only when a sync runs. |
| Bitcoin addresses you add | To read public balances for those addresses. Encrypted at rest. |
| Portfolio data: holdings, transactions, dividends, valuations | The substance of the product. Retrieved from the sources you connect and stored so history and analytics exist. |
| Content you create: notes, knowledge entries, agent settings, advisor conversations | To provide the features that store them, and to give the advisor context. |
| Subscription status and billing period | To decide whether your account has access. We do not store card details. |
| Technical logs: IP address, user agent, timestamps, error traces | Security, abuse prevention and debugging. Retained for a limited period, see section 5. |
| Usage metering: token counts for advisor and agent activity | To enforce fair-use allowances. Counts, not content. |
3. Why we are allowed to (legal bases)
- Performance of a contract — everything needed to provide the Service you have subscribed to: your account, your portfolio data, the advisor and the agents.
- Legal obligation — retaining invoices and transaction records for the period tax law requires.
- Legitimate interests — keeping the Service secure, preventing abuse, and debugging faults. We balance this against your interests and keep the data involved to the minimum and for the shortest period that works.
- Consent — only where we ask for it explicitly, and you can withdraw it at any time. We do not send marketing email without it.
4. Who else processes your data
We use the following processors. Each one receives only what it needs for its function, and each is bound by a data processing agreement.
| Processor | What it receives | Purpose |
|---|---|---|
| Stripe | Email, billing details you enter with them, subscription state | Payment processing and subscription billing |
| xAI (Grok) | The portion of your portfolio and conversation relevant to a request | Powering the advisor and the research agents |
| Cloudflare | IP address, request metadata | CDN, DDoS protection and bot filtering in front of the origin |
| Brevo | Email address and message content | Transactional email: verification, password reset, service notices |
| Hetzner | All stored data, as the hosting provider | Server and database hosting |
We do not sell your data, we do not share it with advertisers, and we do not use it to train any machine learning model.
5. How long we keep it
- Account and portfolio data: for as long as your account exists. Cancelling a subscription does not delete it — so that resubscribing restores your history rather than starting over.
- After you delete your account: erased from live systems promptly, and from encrypted backups as those backups age out of the retention window.
- Technical logs: a short rolling window, kept only as long as they are useful for security and debugging.
- Invoices and payment records: for the period tax and accounting law requires, which is longer than the rest and is not something we can shorten on request.
6. Where your data is
The application and its database run on servers in the European Union. Some processors named above operate outside the EU; where they do, transfers rely on the European Commission’s Standard Contractual Clauses or an adequacy decision.
7. Your rights
Under the GDPR you have the right to access your data, to correct it, to have it erased, to restrict or object to processing, to receive it in a portable format, and to withdraw consent where processing is based on it.
To exercise any of these, write to the address in section 1. We will respond within one month. If you are not satisfied with our response you may complain to your national data protection authority — in Spain, the Agencia Española de Protección de Datos (aepd.es).
8. Cookies and local storage
This marketing site sets no cookies and runs no analytics or advertising trackers. It stores one item in your browser’s local storage — your light or dark theme preference — which never leaves your device and is not a cookie.
The application at app.vest101.com stores your session token and interface preferences in local storage. These are strictly necessary to keep you signed in. Cloudflare may set a security cookie in front of both sites to distinguish humans from automated traffic.
9. Security
Broker credentials and Bitcoin addresses are encrypted at rest. Data is scoped per user at the database access layer. The origin server accepts connections only from Cloudflare. The Security page describes this in detail, including what we do not claim.
If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours and tell you directly where the risk is high.
10. Children
The Service is not for anyone under 18 and we do not knowingly collect data from children. If you believe a child has created an account, tell us and we will delete it.
11. Changes
If we change this policy materially — a new processor, a new purpose, a longer retention period — we will email account holders before the change takes effect. The date at the top always reflects the current version.
Terms of Service →