Privacy Policy
Last updated: September 2026
Valence is a personal portfolio tracking application. This policy explains what data we collect, why we collect it, and what rights you have over it. We collect only what is necessary to operate the service and never sell your data to third parties.
Data We Collect
- Account data: your email address and an Argon2-hashed password, or, if you sign in with Google or GitHub, your email address and the account ID of that provider. We never store your password in plain text. We also store your plan and trial status, time zone and preferred base currency.
- Billing data: if you subscribe to a paid plan, a Stripe customer ID and subscription status. Card details are entered directly with Stripe and never reach our servers.
- Portfolio data: transactions, cash balances, brokers, TER values, asset details and watchlists that you enter manually or import via CSV.
- Session tokens: short-lived access tokens and longer-lived refresh tokens stored in HttpOnly cookies. These expire automatically and are pruned from the database when they do.
- IP addresses: used transiently by the rate-limiter to prevent brute-force attacks. Your full IP address is also recorded with each sign-in attempt in the security audit log. Server access logs keep only a shortened address (the last part is removed).
- Audit log: timestamps and actions for security-relevant events (e.g. sign-in, password change, subscription changes, account deletion) and for changes you make to your portfolio data (e.g. adding a transaction or importing a file). For changes we record which record was changed, never its contents.
- Feedback: if you send feedback or a bug report from the app, your message, the optional reply address you give, and the email address of your account. These are emailed to our support mailbox; we keep a copy in the security audit log only if the email could not be sent.
What We Do Not Collect
- Analytics or behavioural tracking cookies
- Device fingerprints or advertising identifiers
- Financial account credentials or broker login details
How We Use Your Data
- To authenticate you and maintain your session
- To display and calculate your portfolio analytics
- To send service emails about your account and subscription via Resend: email verification, password reset, welcome, trial start, payment receipts, failed payments, cancellation, and account deletion confirmation. We do not send marketing emails.
- To process subscription payments via Stripe, if you sign up for a paid plan
- To read and answer feedback you send us
- To enforce rate limits and protect against abuse
Third-Party Services
Valence uses the following sub-processors. Apart from Cloudflare, which carries all traffic between your browser and our server, none of them receive your portfolio data (transactions, cash balances, brokers, TER values, or watchlists).
- Cloudflare: all traffic to Valence passes through Cloudflare's network, which protects the site against attacks and handles the encrypted connection. Cloudflare therefore processes your IP address and the content of requests in transit. Our database backups are stored in Cloudflare R2, encrypted before upload with a key Cloudflare does not hold. Cloudflare Privacy Policy.
- Yahoo Finance (yfinance): live and historical market prices and asset searches are fetched using ticker symbols and the search terms you type. No account data is sent.
- OpenFIGI: when you import a CSV that identifies assets by ISIN, those ISINs are sent to OpenFIGI to find the matching ticker symbols. No account data or other transaction details are sent.
- Resend: email delivery. Your email address is transmitted to Resend when we send you a service email, and feedback you send is forwarded to our support mailbox through Resend. Resend Privacy Policy.
- Proton Mail: hosts our support mailbox, which receives the emails you send us and the feedback you submit in the app. Proton Privacy Policy.
- Stripe: payment processing for paid subscriptions. If you subscribe, your email address and payment details are handled by Stripe; card data is entered on Stripe's hosted checkout and never reaches our servers. We store only a Stripe customer ID and your subscription status. Stripe Privacy Policy.
- Sentry (optional): if configured, application errors are reported without request bodies or personally identifiable information (
send_default_pii=False,max_request_body_size="never"). Sentry Privacy Policy. - Hosting provider: the server and database are hosted on a VPS. The provider has access to the physical host but not to application-level data.
Cookies
Valence sets two session cookies, both HttpOnly and SameSite=Strict:
- access_token: short-lived session token (default: 30 minutes)
- refresh_token: longer-lived token used to renew the session without re-login (default: 7 days of inactivity, path restricted to
/auth/refresh)
However often a session is renewed, you are asked to sign in again after 30 days.
If you sign in with Google or GitHub, a short-lived oauth_state cookie (10 minutes,
SameSite=Lax) is set during the sign-in redirect to prevent CSRF, and is
cleared once sign-in completes. No tracking, analytics, or advertising cookies are set.
Browser Storage
Valence keeps a few display preferences in your browser's local storage: your theme, whether amounts are hidden, rebalance targets, forecast inputs, table sorting and the broker you last used when adding a transaction. These stay on your device, are never sent to our server, and are removed when you clear your browser's site data.
Data Retention
Your data is retained for as long as your account exists. Expired session tokens are automatically pruned from the database. When you delete your account, all associated data (transactions, cash balances, brokers, TER values, watchlists, session tokens, and your email address) is removed immediately from the live database and cannot be recovered. Copies that remain in routine encrypted database backups are deleted within 30 days.
If you register but never confirm your email address, and add no portfolio data, watchlists or other content, your account is deleted automatically after 30 days.
Audit log records are kept for up to 90 days and then automatically deleted. When you delete your account, the records of changes to your portfolio data and any feedback you sent are deleted immediately. Security records (such as sign-ins, password changes and the deletion itself) are anonymised instead: your email address, IP address and other personal identifiers are stripped and the link to your account is removed, so the security event remains for integrity purposes but no longer identifies you.
Feedback emails in our support mailbox are kept only as long as needed to handle your message. You can ask us to delete them at any time.
Our web server keeps access logs for troubleshooting and abuse prevention. They record a shortened IP address (the last part is removed, so it no longer identifies you), the page requested and the response status. Error entries, such as a request refused by the rate limiter, can contain the full IP address. These logs are capped in size and the oldest entries are overwritten automatically.
Legal Basis for Processing
We process your personal data on the following legal bases (GDPR Art. 6):
- Contract (Art. 6(1)(b)): processing your email address and portfolio data, and sending service emails, is necessary to provide the Service you signed up for.
- Legitimate interest (Art. 6(1)(f)): rate limiting, audit logging and server logs are necessary to protect the security and integrity of the Service, and handling the feedback you choose to send helps us support you and improve the Service.
- Legal obligation (Art. 6(1)(c)): we may retain certain records where required by applicable law.
We do not rely on consent as a legal basis because we do not send marketing emails or use tracking technologies that require it.
Your Rights (GDPR)
If you are located in the European Economic Area, you have the right to:
- Access and portability: download all your transactions as CSV via Account Settings → Download transactions.csv (or
GET /auth/me/export). Other personal data we hold (brokers, TER values, watchlists, and account details) is available on request via the contact address below. - Erasure: delete your account and all associated data via Account Settings → Delete Account (or
DELETE /auth/me). - Rectification: edit or delete individual transactions at any time within the app.
- Objection / restriction: contact us at the address below to request restriction of processing.
- Complaint: you have the right to lodge a complaint with your national data protection authority (e.g. the Dutch Autoriteit Persoonsgegevens at autoriteitpersoonsgegevens.nl, or the authority in your country of residence).
Data Transfers
Your data is stored on a server in the EU. Some sub-processors (e.g. Cloudflare, Resend, Stripe, Sentry) are based in the United States or transfer data outside the EEA. They do so under the EU-US Data Privacy Framework, Standard Contractual Clauses, or an equivalent adequacy mechanism, as described in their respective privacy policies.
Security
Passwords are hashed with Argon2 before storage. All communication is encrypted via HTTPS/TLS. Auth cookies are HttpOnly (not accessible to JavaScript), SameSite=Strict (CSRF protection), and Secure (HTTPS only). A Content-Security-Policy header is enforced on every response. Database backups are encrypted before they leave our server.
Children's Data
Valence is intended for users aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, contact us and we will delete it.
Contact
For privacy-related requests or questions, email [email protected]. We will respond within 30 days.
Changes to This Policy
If we make material changes, we will update the "Last updated" date above. Continued use of the service after changes constitutes acceptance of the updated policy.