InvestPane

Privacy Policy

Last updated: September 6, 2026

This Privacy Policy explains how InvestAI ("InvestAI", "we", "us") collects, uses, and protects your data when you use the InvestAI portfolio-tracking application (the "Service"). InvestAI is operated from Romania and this policy is written with the EU General Data Protection Regulation (GDPR) in mind.

1. Who we are

InvestAI is operated by an individual data controller. For any privacy question, request, or complaint, contact: vlad.paunescu@gmail.com.

2. What data we collect

  • Account data: your email address and authentication credentials (passwords are stored hashed, never in plain text).
  • Broker & bank connection data: API keys or tokens you provide for brokers (Trading212, IBKR, Binance, Tradeville) and, where you connect a bank via Enable Banking, read-only access to account balances and transaction history. Broker/bank credentials are encrypted at rest.
  • Financial data: holdings, positions, transactions, and cash balances either uploaded by you (broker statement files) or synced from broker/bank APIs you explicitly connect.
  • Uploaded documents: statement files, screenshots, or other documents you upload for import, stored in encrypted object storage.
  • Usage data: basic technical logs (e.g. request timestamps, error logs) needed to operate and secure the Service. We do not use third-party analytics or advertising trackers.

3. How we use your data

We use your data solely to provide the Service: authenticating you, importing and normalizing your broker/bank data, matching instruments across brokers, and displaying your consolidated portfolio, holdings, and analytics back to you. Where you use AI-assisted import features, extracted document data may be sent to Google Gemini for processing; it is not used to train third-party models.

4. Open banking access (Enable Banking)

If you choose to connect a bank account, InvestAI uses Enable Banking as an Account Information Service (AIS) provider under PSD2. This access is read-only (account information and transactions), is initiated only with your explicit consent through your bank's own authentication flow, and can be revoked by you at any time, either in your bank's own consent management or by disconnecting the account inside InvestAI.

5. Data sharing

We do not sell your data. We share data only with the infrastructure and service providers necessary to run InvestAI, each acting as a data processor under contract or their own applicable terms:

  • Hosting and edge infrastructure (Vercel)
  • Database hosting (Neon, PostgreSQL)
  • Encrypted file storage (Cloudflare R2)
  • AI-assisted document processing (Google Gemini), only for documents you actively submit for import
  • Broker and open-banking APIs you explicitly connect (Trading212, IBKR, Binance, Tradeville, Enable Banking)

6. Data security

Broker and bank credentials are encrypted at rest. Passwords are hashed. Access to production data is restricted to the operator. No method of transmission or storage is 100% secure, but we take reasonable technical measures to protect your data.

7. Data retention

We retain your data for as long as your account is active. You may request deletion of your account and associated data at any time by contacting us; some data may be retained where required by law.

8. Your rights (GDPR)

If you are located in the EU/EEA, you have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact vlad.paunescu@gmail.com.

9. Cookies

InvestAI uses only essential cookies required for authentication. See our Cookie Policy for details.

10. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.

11. Contact

Questions about this policy: vlad.paunescu@gmail.com.