Back to home

Privacy Policy

Last updated August 20, 2026

This document was drafted for Portfolio Eyes and describes how the Service actually works. It is not legal advice, and it is pending review by qualified counsel — if you rely on it for your own purposes, have it reviewed first.

LOONIELODGE INC. (“we”, “us”, “our”) operates Portfolio Eyes. This Policy explains, in specific terms, what personal information we collect, why we collect it, how it is stored and encrypted, who can access it, how long we keep it, what we do if something goes wrong, and the rights you have over it. It is written to meet Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and Quebec’s Law 25, and it applies to the website, the application and the emails we send.

1. Accountability — who is responsible

LOONIELODGE INC. is responsible for the personal information under its control, including information we transfer to a service provider for processing. We have designated a Privacy Officer who is accountable for our compliance with this Policy and with applicable privacy law.

Privacy Officer, LOONIELODGE INC. — privacy@portfeyes.com, or by mail at the postal address shown in the site footer. You can also raise a privacy question through the in-app support desk.

Our practices are implemented through this Policy, our internal security measures, our written confidentiality-incident response procedure, and contractual commitments from every service provider that handles personal information on our behalf.

2. Your consent, and how to withdraw it

We collect, use and disclose your personal information with your knowledge and consent, except where the law permits or requires otherwise — for example to investigate a breach of an agreement, or to comply with a lawful demand.

How we obtain consent:

  • Express consent at sign-up. Before you can finish onboarding you must tick a box confirming that you accept the Terms of Service and this Privacy Policy. We record the moment you accepted and the version you accepted, so both of us know what was agreed.
  • Separate express consent for marketing email. Product announcements are sent only if you opt in through a distinct, unticked box at onboarding, which you can change at any time in Settings. This is express consent under Canada’s Anti-Spam Legislation (CASL): no opt-in means no announcement email, ever.
  • Implied consent for operating the Service. When you enter a holding, connect a broker or turn on an alert, you are asking us to process that information for that purpose — and we do only that with it.
  • Fresh consent for anything new. If we ever want to use your information for a purpose not described in this Policy, we will ask you first.

Withdrawing consent. You may withdraw consent at any time: turn a feature off, disconnect a broker, switch marketing email off in Settings or use the unsubscribe link in any announcement, or delete your account. Withdrawal takes effect going forward and is subject to legal and contractual limits — we may be unable to keep providing a feature that depends on the information you have withdrawn, and we will tell you if that is the case.

Consent is never demanded beyond what a feature needs: we do not make your use of the Service conditional on consenting to a collection that is not necessary to provide it.

3. Why we collect your information

We identify the purpose of a collection before or at the time we collect. We use personal information only for these purposes:

  • to create and secure your account, sign you in, and confirm your eligibility;
  • to operate the features you use — showing your holdings and transactions, computing allocation, performance, cost basis, realized gain/loss and contribution room, and generating watchlists, valuations, reports and analyzer output;
  • to send the notifications you enable — alerts, digests and scheduled reviews — and the transactional email the Service requires, such as billing receipts and security or account notices;
  • to take payment, manage your subscription, apply any discount, and meet tax and accounting obligations;
  • to answer your support requests;
  • to keep the Service secure, reliable and available — diagnosing errors, preventing abuse and fraud, enforcing plan limits, and maintaining backups;
  • to send product announcements, if and only if you have opted in;
  • to comply with the law, and to establish, exercise or defend legal claims.

We do not use your personal or financial information for advertising, for profiling you for anyone else, or for training any artificial-intelligence model. We do not sell, rent or trade it — ever.

4. Exactly what we collect

We limit collection to what is necessary for the purposes above. This is the full inventory of what we hold:

  • Account and identity: your email address, an authentication identifier from our sign-in provider, your interface language, the date you confirmed you are a resident of Canada, your display currency, your plan and role, and account timestamps.
  • Consent records: when you accepted the Terms and this Policy and which version; when you attested to being of the age of majority; and when you gave or withdrew marketing consent.
  • Portfolio data: the investment accounts you create or connect (name or alias, account type such as TFSA, RRSP or RESP, currency, and whether you exclude it from totals); your holdings (security, quantity, book cost); your transactions (type, date, quantity, price, fees, currency); your allocation targets; your watchlists; and daily snapshots of your portfolio’s value so charts can show history.
  • Contribution-room figures you enter: the TFSA room and RRSP deduction limit you copy from the CRA, and the dates they apply to. We only ever show back the official numbers you gave us — we do not estimate them.
  • Preferences and in-app activity: alert rules and the alerts that fired, notification preferences including quiet hours and digest settings, your notifications and whether you have read them, scheduled reviews, analyzer reports, and any valuation assumptions you set.
  • Household data, if you use it: the household you own or belong to, invitations you send or receive, and the shared view those permissions produce.
  • Support content: the subject and body of tickets you open, the messages in the thread, and the automated classification and draft reply our support tooling prepares for an administrator to review.
  • Billing data: your customer and subscription identifiers at our payment processor, your plan, billing interval, renewal date, cancellation state, and any discount granted to you. Card numbers, bank details and billing addresses are collected and held by Stripe, not by us — they never reach our servers.
  • Email records: unsubscribe and suppression entries, and the delivery state of any announcement sent to you, so that we can honour your choices and never send the same message twice.
  • Technical and security data: server and application logs, error diagnostics, background-job records, and abuse-prevention counters. Where a counter is tied to an IP address, we store only a keyed cryptographic digest of that address — never the address itself.

Connected brokerages: when you link a broker we receive the account, position and transaction data described above, plus a read-only access credential issued by the aggregation provider. We never receive your brokerage username or password.

5. What we deliberately do not collect

We audit our own collection and remove anything a feature does not actually need. We do not ask for, and do not store:

  • your date of birth or birth year — you attest to being of the age of majority instead;
  • your Social Insurance Number, Social Security Number, or any government identification number;
  • your residency or immigration status;
  • your home address or telephone number (Stripe collects only what a payment legally requires);
  • your income, employment, net worth or credit information;
  • your brokerage username, password, or any trading credential;
  • your precise location, GPS data or device fingerprints;
  • advertising, cross-site or social-media tracking identifiers;
  • biometric information, or any sensitive information about your health, beliefs or background.

When a feature stops needing a piece of information, we delete the column rather than keep it — we have done this before and we intend to keep doing it.

6. Connected brokerage accounts

Brokerage links run through SnapTrade, a specialist aggregation provider. You authorize the connection in the provider’s own secure flow, at your broker, and your credentials go to your broker — not to us, and not into our database.

What comes back to us is read-only account, position and transaction information, plus a credential that permits only reading. Neither we nor the provider can place a trade, move cash, or change anything at your broker through this connection.

You can disconnect a broker at any time from the Accounts screen. Disconnecting stops further syncing and deletes the stored credential; data already imported stays in your portfolio until you delete the account or your profile.

7. How and where your data is stored

Your data lives in a managed PostgreSQL database operated by Supabase, hosted on Amazon Web Services infrastructure in Canada (the AWS ca-central-1 region, in Montréal). The application itself runs on Vercel’s platform. Backups and point-in-time recovery are provided by the database platform and are held on the same encrypted storage.

Because these providers are located in the United States, your personal information is stored and processed outside Canada and, while it is there, may be accessible to United States courts, law enforcement and national-security authorities under the law of that country. Section 10 describes our providers, and the full list is on our sub-processors page.

Every record we hold is scoped to your user account. Queries are filtered by your identity in the data layer, and a signed-in session can reach only its own rows. There is no view of one user’s portfolio available to another, apart from the household feature that you explicitly opt into and can revoke.

8. How your data is encrypted

In transit. Every connection to the Service uses HTTPS with TLS. We send a Strict-Transport-Security header so that browsers refuse to fall back to an unencrypted connection. We also send a content-security policy, currently in report-only mode: browsers evaluate it and report violations to us without blocking anything, which is the stage before we enforce it. Connections between the application and the database, and between the application and every provider, are TLS-encrypted as well.

At rest. The database and its backups are encrypted at rest by the database platform using AES-256. Application logs and error diagnostics are held encrypted by their respective providers.

Application-layer encryption for the most sensitive secret. The read-only brokerage credential is not merely covered by the platform’s disk encryption. Before it is written to the database we seal it with AES-256-GCM authenticated encryption, using a fresh 96-bit nonce for every value and a key that exists only in the server’s environment configuration — never in the database, never in the source code, and never in a backup of the data. It is decrypted only in the server-side code path that calls the brokerage provider. The practical effect is that a copy of the database on its own yields no usable brokerage credential.

Credentials we never hold. We never store your Portfolio Eyes password itself — only a salted argon2id hash of it, which cannot be reversed to recover the password. We never see your brokerage password. We never see your card number.

Other cryptographic protections. IP addresses used for abuse-prevention counters are stored only as a keyed HMAC-SHA-256 digest, so the stored value cannot be turned back into an address. Unsubscribe and similar one-click links carry signed, tamper-evident tokens rather than raw identifiers.

9. Who has access to your data

You. Your account is the only place your complete portfolio can be seen. You can view, export and delete it at any time.

LOONIELODGE INC. personnel. Portfolio Eyes is operated by a very small team. The administrative screens in the app are restricted to accounts holding the administrator role, and they deliberately expose only what running the business requires: your email address, your plan and billing status, your account status, and the names, types and currencies of your investment accounts. They do not display your holdings, your transactions, your positions or your portfolio values.

Support. When you open a ticket, an administrator reads what you wrote in it — and the draft reply prepared for that ticket — in order to answer you. Please do not include information that a ticket does not need.

Database administration. Direct database access is limited to the person responsible for operating and maintaining the Service, is protected by credentials held outside the application, and is used only for operating, debugging, migrating and backing up the Service — not for browsing user portfolios. Administrative capability inside the app is gated behind the administrator role and can be revoked.

Service providers. Each provider listed in section 10 receives only the information its own function requires, under a contract limiting it to that use.

No one else. We do not sell, rent, trade or share your personal information for anyone else’s marketing. We disclose it beyond the cases above only where the law compels us — a warrant, subpoena, court order or other lawful demand — or where it is necessary to protect someone’s safety, or to establish or defend a legal claim. We satisfy ourselves that a demand is valid, disclose no more than it requires, and tell you about it unless we are prohibited from doing so.

10. Service providers and transfers outside Canada

We use these categories of provider to run the Service: hosting (Vercel), database (Supabase), payments (Stripe), brokerage aggregation (SnapTrade), market data and news (Finnhub), transactional email (Resend), announcement email (Mailgun), error monitoring (Sentry), and artificial-intelligence text generation (OpenAI). Authentication is handled by us, not by a third party. The current named list is on our sub-processors page and is updated when it changes.

Each provider processes personal information only on our instructions and only as its service requires, under a contract that limits how it may use and disclose that information and requires it to protect it.

Most of these providers are located in the United States, so your personal information is transferred there. Under PIPEDA a transfer for processing is a use, not a disclosure: we remain accountable for your information while a provider holds it, and we use contractual means to give it a comparable level of protection. While outside Canada it is subject to the law of that country and may be accessible to its authorities. If you are not comfortable with that, please do not use the Service.

11. How long we keep your data

We keep personal information only as long as it serves the purpose it was collected for, or as long as the law requires. Our schedule:

  • Account, portfolio, watchlist, alert and preference data — for as long as your account is open. When you delete your account these records are deleted with it.
  • Support tickets — deleted 365 days after the ticket is resolved or closed. If you delete your account while a ticket exists, the ticket is de-identified: the link to you is removed and the support record remains without pointing to you.
  • Notifications — read notifications are removed automatically after 90 days by a nightly job; unread notifications are never removed by that job.
  • AI-usage records (which feature, which model, how many tokens — no content of yours) — 400 days, so that we can review cost and reliability.
  • Abuse-prevention counters (the keyed IP digests) — 48 hours.
  • Unsubscribe and email-suppression records — kept indefinitely, and deliberately surviving account deletion. This is the only way to guarantee that we never email you again after you have asked us not to.
  • Billing records — held by Stripe under its own retention rules; we keep the minimum needed to meet tax and accounting obligations.
  • Confidentiality-incident records — at least 24 months from the day we determine that a breach occurred, as PIPEDA requires, and in the incident register Law 25 requires.
  • Backups — data deleted from the live database persists in routine encrypted backups until those age out on the platform’s own cycle, after which it is gone.

Deleting your account permanently removes your profile and every record that depends on it — accounts, holdings, transactions, contribution-room figures, watchlists, alerts, notification preferences and the stored brokerage credential — cancels any live subscription, and removes your sign-in identity so the account cannot be reopened. It cannot be undone; export first if you want a copy.

12. Safeguards — how we protect your information

We protect personal information with safeguards proportionate to its sensitivity, and financial information is sensitive. Beyond the encryption described in section 8:

  • Access control. Every request is authenticated and every query is scoped to the signed-in user. A single server-side check governs whether an account is active and permitted to act, so a suspended account cannot perform an action even mid-session; disabling an account also revokes its sessions at the identity provider.
  • Least privilege. Administrative capability is tied to an explicit role, is held by as few people as possible, and exposes only the fields listed in section 9. Secrets live in environment configuration — not in the code and not in the repository — and the application refuses to start in production without the encryption key it needs.
  • Transport and browser hardening. Strict-Transport-Security; a content-security policy; X-Frame-Options: DENY to prevent clickjacking of the billing and settings forms; X-Content-Type-Options: nosniff; a restrictive permissions policy; and a referrer policy that stops identifiers in URLs from leaking to other sites.
  • Abuse resistance. Rate limiting on the endpoints that matter, enforcement of plan limits, and signed tokens on one-click email actions.
  • Data minimization by design. We periodically audit what we store and remove anything a feature does not use, so that a breach can expose only what we genuinely needed (see section 5).
  • Monitoring and integrity. Errors are reported to a monitoring provider with personal-information reporting switched off and message content redacted before it is sent. Background jobs are heartbeat-monitored so that a silent failure is detected rather than assumed away. Authenticated encryption on stored secrets makes tampering detectable.
  • Deletion in practice. Deletion is enforced by database-level cascades rather than by remembering to clean up, and retention windows are enforced by scheduled jobs rather than by good intentions.

No system is perfectly secure and we do not claim otherwise. If you believe you have found a vulnerability, please tell the Privacy Officer at privacy@portfeyes.com before disclosing it elsewhere. We will investigate, and we will not pursue good-faith research that respects our users’ privacy.

13. Breach response and notification

A confidentiality incident — a privacy breach — is any unauthorized access to, use, disclosure or loss of personal information we hold. We maintain a written response procedure and follow it every time.

Contain and assess. We first stop the exposure: rotating the affected credential or key, invalidating sessions, disabling the affected account or endpoint, and taking a surface offline if necessary. We preserve logs and build a timeline. We then assess the risk, considering how sensitive the information is, how many people are affected, whether the data was encrypted, how likely misuse is, and whether the data can be recovered.

Notify you. If an incident creates a real risk of significant harm to you — PIPEDA’s standard, and Law 25’s risk of serious injury — we will notify you directly, as soon as feasible, at your account email address, in plain English or French. The notice will say what happened and when, what information was involved, what we have done, what we recommend you do (for example re-link your brokerage, or watch for phishing), and how to reach the Privacy Officer. We will not delay telling you in order to complete a perfect root-cause analysis: we notify on reasonable belief and update you as we learn more.

Notify regulators. Where the same threshold is met we report the incident to the Office of the Privacy Commissioner of Canada as soon as feasible, as PIPEDA requires, and to the Commission d’accès à l’information du Québec where Quebec residents are affected. Where a service provider caused the incident, the duty to notify you remains ours.

Record. We keep a record of every confidentiality incident — whether or not notification was required — including the date, a description, the information involved, the cause, the number of people affected, our risk assessment, who was notified and when, and what we changed afterwards. We retain that record for at least 24 months from the day we determine the incident occurred, as PIPEDA requires, and we will provide it to the Commissioner on request.

Fix. Every incident ends with a root-cause fix and, wherever possible, a permanent guardrail — a test, a check, or a design change — so that the same failure cannot recur, followed by a review of the response itself.

14. Your rights, and how to exercise them

You have the following rights over your personal information. Most are available immediately in the app, without asking us:

  • Access. See what we hold. Settings → Export your data produces a complete JSON file of your profile, accounts, holdings, transactions, watchlists, alerts, preferences, support tickets and consent records.
  • Correction. Fix anything inaccurate. Your profile, accounts, holdings, transactions, targets and contribution-room figures are all editable in the app; if you cannot correct something yourself, ask the Privacy Officer.
  • Deletion. Settings → Delete your account removes your account and all data that depends on it, as described in section 11.
  • Withdrawal of consent. Turn features off, disconnect brokers, or switch marketing email off in Settings or through any unsubscribe link.
  • Portability. The export is machine-readable JSON that you can take elsewhere.
  • Explanation. Ask how a figure is computed, or what we hold about you and why — we will answer.

You may also make a request in writing to the Privacy Officer at privacy@portfeyes.com. We may ask you to confirm your identity so that we do not disclose your information to someone else. We respond within 30 days of receiving a request, as PIPEDA requires, or tell you within that time why we need an extension and how long it will take. Access is free; if a request is unusual enough to carry a cost we will tell you in advance and you may withdraw it.

In limited cases the law permits or requires us to refuse access — for example where releasing information would reveal personal information about another person, or would compromise an investigation. If we refuse, we will tell you why, tell you which provision we rely on, and tell you how to complain.

15. Accuracy

We keep personal information as accurate, complete and up to date as the purposes require. Most of it comes straight from you, or from your broker’s own records, so the fastest way to keep it accurate is to keep your accounts synced and your entries current. We do not independently verify contribution-room figures or manually entered holdings — you are the source for those. If you tell us something is wrong we will correct it, and where the inaccuracy matters we will pass the correction on to any provider that received it.

16. AI features and automated processing

Higher plans include educational AI features. When you use one, we send a compact, bounded summary of the relevant tracked data — for example ticker symbols, account types, quantities, values, gain/loss figures and sector labels — to our AI provider, which generates the narrative text you see. We do not send your name, your email address, your account identifiers or your billing information.

Our contract with the provider prohibits it from using what we send to train its models. The AI-usage records we keep hold only which feature, which model and how many tokens — never the content of a prompt or a response.

These features make no automated decision about you and produce no legal or similarly significant effect. The figures and signals the text describes are computed by us from your own data; the model only puts them into words. The output is informational only, may be wrong, and is not advice — see section 7 of the Terms of Service.

17. Cookies and telemetry

We use only the cookies the Service needs in order to work: a session cookie that keeps you signed in, and a preference cookie that remembers your language. We do not use advertising cookies, cross-site trackers, social-media pixels, or third-party analytics that profile you across the web.

To keep the Service reliable we use an error-monitoring provider that receives technical diagnostics when something fails — the error, where in the code it happened, and the surrounding technical context. It is configured not to send personal information by default, and message content is redacted before it leaves our server, so a diagnostic does not include what you typed.

18. Age

The Service is intended for adults. You must confirm at onboarding that you are at least the age of majority where you live, and we do not knowingly collect personal information from anyone below it. If you believe a minor has given us personal information, contact the Privacy Officer and we will delete the account and its data.

19. Quebec residents (Law 25)

If you live in Quebec, Law 25 — the Act respecting the protection of personal information in the private sector, as amended — gives you rights in addition to those above:

  • to be informed of the personal information we hold about you, and to receive a copy of it;
  • to have inaccurate, incomplete or ambiguous information corrected;
  • to withdraw your consent to a use or a disclosure;
  • to portability — to receive the computerized personal information you provided to us in a structured, commonly used technological format;
  • to de-indexing, or to cessation of dissemination, in the circumstances the Act provides;
  • to be informed when personal information is used to render a decision based exclusively on automated processing — we make no such decisions, as section 16 explains.

The Privacy Officer named in section 1 is the person in charge of the protection of personal information for the purposes of the Act. We assess the privacy implications of a project before it involves personal information outside Quebec, we notify the Commission d’accès à l’information and affected individuals of any confidentiality incident presenting a risk of serious injury, and we keep the register of incidents the Act requires (see section 13).

20. Changes to this Policy

We will update this Policy as the Service, our providers or the law change. The current version and the date it took effect are always posted here, and each version carries a stamp we record against your acceptance. For a material change — a new purpose, a new category of information, or a new category of provider — we will notify you by email or in the app before it takes effect and, where the law requires consent for that change, we will ask you for it. Continuing to use the Service after the effective date means you accept the updated Policy.

21. Questions and complaints

Ask us first. Contact the Privacy Officer at privacy@portfeyes.com, through the in-app support desk, or by mail at the postal address in the site footer. We will acknowledge your question, investigate it, tell you the outcome, and — if we agree that something went wrong — correct our practices.

If you are not satisfied, you can complain to a regulator: the Office of the Privacy Commissioner of Canada (priv.gc.ca, 1-800-282-1376), or the Commission d’accès à l’information du Québec (cai.gouv.qc.ca) if you live in Quebec. If you live in the United States, you may also have rights under your state’s privacy law — contact the Privacy Officer and we will tell you how they apply.