Legal

Privacy Policy

Your portfolio is yours. This page explains exactly what FortuneOK collects, why we collect it, and the choices you have over your data.

Effective
Last updated

No selling, ever

We do not sell, rent or trade your personal data or portfolio data to anyone.

Encrypted in transit & at rest

All traffic uses TLS. Data lives in encrypted Supabase databases.

You control your data

Export your whole portfolio to Excel or PDF, and delete your account yourself, at any time.

FortuneOK ("we", "us", "our") operates FortuneOK (the "Service"). This Privacy Policy describes how we collect and process information when you visit our website or use the Service.

1. The short version

  • We collect the minimum needed to run a portfolio tracker: your email, the assets and goals you record, and standard service logs.
  • Payments are handled by Lemon Squeezy. We never see your full card number.
  • Broker connections are optional and read-only. Your brokerage credentials go to SnapTrade, never to us, and we can never trade or move money.
  • We do not sell your data, do not run third-party advertising trackers, and do not share your portfolio with anyone.
  • You can export your data from the dashboard at any time, and delete your account yourself, in a couple of clicks, without contacting us.

2. Scope

This policy covers data we process about visitors to fortuneok.com and registered users of FortuneOK. It does not cover the privacy practices of third-party sites or services you may connect to from within the Service - their own policies apply.

Our public demo at fortuneok.com/demo needs no account. It runs entirely on sample data, nothing you enter there is saved, and if you happen to be signed in your own portfolio is never loaded or shown on that page.

3. Information we collect

We collect only what we need to operate the Service. The categories below summarize everything we touch.

Account information
Your name and email address, captured when you sign up with Google or via a magic link. We never ask for or store a password.
Portfolio & asset data
The assets, portfolios, transactions, currencies and notes you record, plus the value snapshots we compute from them to draw your performance history. We treat this as private and never sell or share it, for advertising or anything else.
Financial goal settings
The targets you configure for financial independence, your emergency fund, your annual return and your desired allocation, including the monthly expense and contribution figures behind them.
Payment information
Handled directly by Lemon Squeezy, our merchant of record. We store your subscription status, renewal dates and their customer reference, never your card number.
Imported files
If you import a CSV or Excel file, it is read in your browser and only the transactions shown in the preview are sent to us. The file itself is never uploaded to our servers and we never store it.
Connected broker data
If you choose to connect a broker, we receive read-only holdings and activity from the brokerage aggregator (SnapTrade) so we can sync your portfolio. Your brokerage credentials are entered in SnapTrade's portal and never reach us.
Usage & device data
The date of your last sign-in, plus the country, device type, operating system and browser derived from that request. Used for security, support and understanding who the product serves. The same categories are recorded on each page view, under Product analytics below.
Diagnostic logs
When something breaks we record the error message, the page or API route involved, and your account reference, so we can fix it. We deliberately exclude request bodies, API keys and broker secrets.
Feature suggestions
If you post a suggestion or bug report, vote or comment on the public suggestions board, we store the text, any image you attach, your vote and the date. Your first name is shown next to what you post; your email address and last name are not.
Product analytics
Which pages you visit and which buttons you press, recorded on our own servers so we can see where people get stuck. Counts and yes/no flags, plus for a page view the country, region and city the request came from and the browser, operating system and device type it came on, each as a category: never a holding, a symbol, a balance, a name, an email address, your IP address or the raw browser string. No third-party analytics script.
Cookies & local storage
A session cookie to keep you logged in, one functional cookie for layout, and one analytics cookie of our own that counts a visit once. Display preferences such as base currency live in your browser's local storage, not on our servers. No advertising cookies.

Some things we deliberately do not collect: passwords (sign-in is by Google or magic link), card numbers, brokerage credentials, and government identifiers. Market data lookups are made by symbol, so our data provider learns which tickers the app is pricing, never who owns them.

4. How we use your data

We use the information described above to:

  • Provide, operate and maintain the Service (calculate allocations, fetch prices, convert currencies, render charts, track progress against the goals you set).
  • Sync holdings and activity from a broker you have chosen to connect, and suspend that connection if your subscription lapses.
  • Authenticate you, secure your account and prevent fraud or abuse.
  • Process subscription payments and send transactional emails (receipts, magic links, account notices).
  • Diagnose bugs and improve performance using aggregate logs and error traces.
  • Communicate with you about product changes, security alerts and important policy updates.
  • Show the suggestions, votes and comments you post on the public suggestions board, under your first name, and use them to decide what to build.

We rely on the following legal bases under GDPR where it applies: performance of a contract (running the Service you signed up for), legitimate interest (security, debugging) and consent (optional broker connections, optional marketing emails).

5. How we share data

We do not sell your personal data. We share information only in the following limited cases:

  • With service providers who help us run the Service (see section 6), under data-processing terms.
  • When required by law, court order or to protect the rights, property or safety of users.
  • In connection with a merger, acquisition or sale of assets, in which case we will notify you before your data is transferred and becomes subject to a different policy.

6. Service providers

The following third parties process limited data on our behalf so we can deliver the Service:

ProviderPurposeRegion
SupabaseDatabase hosting & authenticationUSA / EU
Lemon SqueezyPayments & subscription billing (merchant of record)USA
ResendTransactional email (magic links, account emails)USA
GoogleOAuth sign-in (optional)USA
Financial Modeling PrepMarket & symbol data (queried by symbol, never with your identity)USA
SnapTradeBroker connections & holdings sync (optional)USA / Canada
VercelApplication hosting & CDNGlobal
UpstashShort-lived caching of market data, exchange rates & chart seriesUSA / EU

7. Cookies & local storage

We use a small, focused set of cookies, and none of them follow you to other websites:

  • Session cookie - keeps you logged in across pages. Strictly necessary.
  • One functional cookie - records whether your device is touch-based so the dashboard renders the right layout on first paint.
  • One analytics cookie - our own, a random identifier that lasts thirty days, lets us count the same visit across pages, so that reading three pages counts as one person rather than three. It is set only on this site, is not readable anywhere else, and is sent to no one but us.
  • No advertising cookies - we do not run third-party ad trackers or behavioral profiling, and we do not build advertising profiles.

On the analytics, we would rather be specific than reassuring. We record, on our own servers, page views and a short, fixed list of actions: starting a sign-in, opening the add-asset form, starting a broker connection, opening checkout, and the matching outcomes recorded on our side (an account created, an asset added, a broker connected, a file imported, a subscription started, a feature suggestion posted or voted on). Each one carries counts and yes/no flags. A page view also records where the request came from (country, region and city, read from the geolocation header of our hosting provider) and what it came on (browser, operating system, and phone, tablet or desktop), each reduced to a category; the IP address and the identification string of the browser are read to derive those and are not stored. No holding, symbol, balance, valuation, currency, name or email address is ever sent, and the list of what each event may carry is fixed in our code rather than left to whatever a page happens to pass. We have turned off the two features that would break this promise: automatic click capture, which would ship the text of whatever you clicked (on your dashboard, that text is your net worth), and session recording. If you are signed in, events are labelled with your account reference so we can count one person once; never with your name or email.

Display preferences such as your base currency, language and chart selections are kept in your browser's local storage rather than sent to us. Your financial goal settings are the exception: they are saved to your account so they follow you between devices. Clearing your browser data signs you out and resets the local preferences; it does not touch your portfolio.

8. Data retention

We keep your account and portfolio data for as long as your account exists, including after a trial or subscription ends. Lapsing does not delete anything: the account becomes read-only and your records stay intact so you can pick up where you left off.

Two categories age out automatically. Historical value snapshots are downsampled over time (daily points are kept for 90 days, weekly points for 2 years, monthly points indefinitely), and cached market and exchange-rate data expires within hours.

Feature suggestions and bug reports follow their own rule, and the board says so. An open post that has found no support after 60 days (no net upvote and no comment, or more downvotes than upvotes) is deleted, together with its votes and comments. Posts we have marked planned, shipped or declined are kept. You can delete your own posts and comments at any time, whether or not your subscription is active, and deleting your account deletes your posts, the images you attached to them, your votes and your comments, including other members' votes and comments on your posts.

You can delete your account yourself at any time from the account menu in the dashboard. Doing so erases your personal data and portfolio entries immediately rather than on a schedule: your account record, portfolios, holdings, transactions, performance history, goals and sign-in details are removed, and any linked broker is disconnected. Error logs we keep for diagnosing faults are stripped of anything that identifies you (your name, email and account reference are erased from them) rather than deleted outright, because once those identifiers are gone the remaining record is no longer personal data. Records we are required to keep for legal, tax or accounting reasons are retained (typically up to 7 years for invoice records held by Lemon Squeezy). If you email us to delete an account instead, we action it within 30 days.

Two things sit outside that immediate deletion, and we would rather name them than let “immediately” imply more than it does. Product analytics records are kept as counts. Your usage events (page views and a fixed list of actions with counts and yes/no flags, never a holding, a balance, a name or an email address) are stored on our own servers labelled with your account reference. Deleting your account removes that reference from every one of them at the same moment, so what remains is an anonymous count, with the country, city and device type of the visit and nothing that leads back to you. The second is backups: deleted records can persist in encrypted database backups for up to 30 days before those rotate out.

9. Security

We use industry-standard safeguards: TLS in transit, encrypted storage at rest, least-privilege access for staff, and audit logging on production systems. No system is perfectly secure, so please use a strong, unique sign-in email and notify us immediately if you suspect unauthorized access.

10. Your privacy rights

Depending on where you live (e.g. EU/UK under GDPR, California under CCPA/CPRA, Brazil under LGPD), you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Delete your data (the "right to be forgotten").
  • Export your data in a portable format.
  • Object to or restrict certain processing.
  • Withdraw consent for optional processing at any time.

You can act on most of these yourself, at any time and whether or not your subscription is active: export your full portfolio to Excel or PDF from the dashboard, correct any entry by editing it, delete individual assets, transactions and portfolios, disconnect a broker, and delete your account outright from the account menu. For any other request, email support@fortuneok.com and we will respond within 30 days.

11. International transfers

FortuneOK is a small, independent operation, and the service providers listed in section 6 process data in the United States, the European Union and other jurisdictions. Your data will therefore cross borders. Where a transfer leaves the jurisdiction you are in, we rely on Standard Contractual Clauses or an equivalent safeguard to protect it.

12. Children's privacy

The Service is not directed to children under 13 (or the relevant age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us and we will delete it.

13. Changes to this policy

We may update this Privacy Policy from time to time. If a change is material we will notify you by email and update the "Last updated" date at the top of this page. Your continued use of the Service after the update takes effect constitutes acceptance of the revised policy.

14. Contact us

Questions, requests or complaints about your privacy? Email support@fortuneok.com. We read every message and take privacy concerns seriously.

Questions about this Privacy Policy?Contact us