Privacy Policy
Last updated August 2026
Short version: we store what you type in so the app can work, we don't sell your data, and you can export or delete it any time from My account. The long version is below.
1. What we collect
- From Google sign-in: your email, name, and profile photo, used to create your account and identify you to co-owners/community members you choose to interact with.
- What you enter: holdings, cash balances, notes, targets, forecast overrides, and anything you send Assistant Margus in chat.
- Usage & performance: basic, privacy-respecting analytics and performance metrics via Vercel Analytics / Speed Insights (page views, load times), no cross-site tracking or ad identifiers.
2. How we use it
To run the app: show your sheets, compute your numbers, remember your preferences, let AI features read your portfolio when you explicitly ask them to, and (only if you opt into a community) show a leaderboard summary of your performance to people in that community. We don't use your data to train third-party AI models, and we don't sell or rent your data to anyone.
3. Who sees it: third parties
A few categories of processor see limited data, only as needed to run the feature:
- Supabase (EU-hosted), our database and authentication provider. Everything you enter lives there.
- AI model providers (OpenRouter and fallback providers). When you use Margus, ask for a forecast, or run Pulse, the relevant portfolio context and your message are sent to whichever provider answers that request. We don't control their retention policies beyond what they publish.
- Market data providers (Yahoo Finance and fallback quote providers). We send ticker symbols to fetch prices; we don't send your holdings or identity to these.
- Vercel: hosting, plus the anonymized analytics mentioned above.
4. Sharing between users
If you invite a co-owner to a sheet, they get full edit access to that sheet's data. If you join a community/leaderboard, other members see a read-only performance summary (returns, notable holdings) for the sheet(s) you've linked to that community, not your raw cash balance or full transaction history unless the community view is explicitly designed to show it. You control which sheets, if any, are linked to a community.
5. Cookies
We use one essential cookie set (via Supabase Auth) to keep you signed in. No third-party advertising or cross-site tracking cookies.
6. Data retention
We keep your data while your account is active. Nightly snapshots of book data are kept for backup/recovery and restricted to admin-only access. You can permanently delete your profile and solely-owned sheets yourself at any time (see below); this removes them from active use immediately.
7. Your rights (export & deletion)
From My account you can download a complete export of your data as JSON, or permanently delete your account: your profile, any sheet you solely own, and your sign-in credential itself (sheets you share with a co-owner stay with them). If for any reason the sign-in credential can't be removed at the same time, your Upside Lab data is still fully wiped immediately. You'd just want to also revoke Upside Lab's access from your Google account if you want that connection severed too. EU/EEA residents have rights under GDPR (access, rectification, erasure, portability, objection); the export/delete tools cover most of these directly; email us for anything else.
8. Security
Data is encrypted in transit (TLS) and access is scoped per-user at the database level (row-level security), so one user's sheets aren't readable by another unless explicitly shared via invite or community. No system is perfectly secure; if we discover a breach affecting your data we'll notify affected users.
9. Children
Upside Lab isn't directed at children and isn't intended for use by anyone below the age required to hold a brokerage account or enter a binding agreement in their jurisdiction.
10. Changes
We may update this policy as the product evolves. Material changes will be reflected here with a new “last updated” date.
11. Contact
Questions, data requests, or concerns: privacy@upsidelab.app.
See also our Terms of service.