Privacy Policy

Vantage Portfolio · Version 1.0 · Effective 7 July 2026

1. Data Controller

The data controller for Vantage Portfolio ("the app", "the service") is Thibault Van Renne, Noorwegenstraat 51, 9940 Evergem, Belgium. Contact: tvr@thibaultvanrenne.com.

2. Data We Collect

Account data. When you sign in with Apple or Google, we receive a unique identifier from that provider and, if you choose to share them, your email address and name. We never see your Apple or Google password.

Portfolio data. The holdings you enter or import: ticker symbols, quantities, purchase prices, and broker labels you assign. Price alerts you create (symbol, direction, threshold).

Community data. If you use the forum: your chosen display name, and the posts, replies, and reports you submit. Posts and replies are visible to other users under your display name.

Device data. If you enable notifications, the push token needed to deliver them (Apple Push Notification service or Firebase Cloud Messaging). We do not collect device fingerprints, advertising identifiers, or location data.

Technical logs. Our servers keep short-lived technical logs (IP address, endpoint, timestamp) for security, rate limiting, and abuse prevention.

3. What Never Leaves Your Device

AI API keys. If you connect a Google Gemini, Anthropic Claude, or OpenAI API key, it is stored exclusively in your device's secure storage (iOS Keychain / Android encrypted preferences). AI requests are sent directly from your device to your chosen provider. Your key is never transmitted to, stored on, or readable by our servers.

Portfolio screenshots. Screenshot import uses on-device text recognition (Apple Vision / Google ML Kit). The image itself is never uploaded to our servers. If you have connected an AI key, the recognized text is sent from your device directly to your AI provider to structure it — under that provider's privacy terms.

4. How We Use Your Data

We do not use your data for advertising, we do not sell or rent it, we do not profile you, and we use no third-party analytics or tracking SDKs.

5. Legal Basis (GDPR)

ProcessingLegal basis
Account, portfolio, alerts, forumPerformance of a contract — Art. 6(1)(b) GDPR
Security logs, rate limiting, moderationLegitimate interest in a secure, lawful service — Art. 6(1)(f)
Push notificationsYour consent (system permission) — Art. 6(1)(a), revocable in device settings

6. Third Parties

PartyRole
Apple / GoogleSign-in (we receive only the identifier and, optionally, email/name) and push-notification delivery
Market-data and news providers (e.g. Finnhub, Financial Modeling Prep, SEC EDGAR, news feeds)Our servers fetch market data from them; none of your personal data is sent to them
Anthropic (Claude API)Automated moderation screening of forum posts (post text only, no account identity) and generation of shared market summaries
Your AI provider (Google / Anthropic / OpenAI)Only if you connect your own key; your device communicates with them directly under your own agreement with that provider
Hetzner Online GmbH (Germany)Server hosting, European Union

We share personal data with no other parties, except where required by law.

7. International Transfers

Your data is stored and processed on servers in the European Union. Forum-moderation text sent to Anthropic and, where you connect a key, your own AI requests may be processed in the United States under those providers' GDPR transfer safeguards (Standard Contractual Clauses / EU–US Data Privacy Framework).

8. Data Retention

9. Cookies

The app uses no cookies and no trackers. Authentication uses a session token stored in your device's secure storage.

10. Your Rights (GDPR)

You have the right of access, rectification, erasure, restriction, portability, and objection. The two most important are built into the app: Settings → Export my data (complete machine-readable copy) and Settings → Delete account (immediate, permanent). For the others, email us — we respond within 30 days. You also have the right to lodge a complaint with your supervisory authority; in Belgium that is the Gegevensbeschermingsautoriteit (gegevensbeschermingsautoriteit.be).

11. California Users (CCPA)

We do not sell or share personal information as defined by the CCPA. You may exercise access and deletion rights via the in-app tools above or by email.

12. Children

The service is not directed at children and may not be used by anyone under 16. We do not knowingly collect data from children; if you believe a child has created an account, contact us and we will delete it.

13. Security

Transport encryption (TLS) on all connections, tokens and keys in platform secure storage, server hardening, rate limiting, and least-access principles. No system is perfectly secure; we will notify affected users and authorities of any breach as required by Art. 33–34 GDPR.

14. Changes

We may update this policy; material changes will be announced in the app before taking effect. The current version is always at this address.

15. Contact

Thibault Van Renne · Noorwegenstraat 51, 9940 Evergem, Belgium · tvr@thibaultvanrenne.com