Privacy Policy
Last updated: September 2, 2026
At Prismfolio ("we," "our," or "us"), operated by Vault and Compass, LLC, we are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our browser extension and website. Please read this policy carefully. If you do not agree with the terms of this policy, please do not access the site.
Short version
- Without signing in, the extension extracts holdings on your device and keeps a local copy in Chrome storage.
- When you sign in (Free or Plus), holdings you analyze are sent to our servers and stored so you can use the web app across devices. Free includes up to 1 Plaid auto-sync connection; Plus raises account and Plaid limits.
- We use Plaid for read-only brokerage linking. We never receive your brokerage login credentials.
- One analytics tool, PostHog, served from our own domain. Before you choose, and if you decline, it counts page visits without cookies and without identifying anyone. Full product analytics start only if you accept.
- You can delete your account and request data removal at any time.
Who we are
Prismfolio is a software product from Vault and Compass, LLC. We build tools that help you understand your portfolio; we are not a registered investment advisor, broker-dealer, or bank. This policy covers the Prismfolio Chrome extension, prismfolio.io, and related services we operate for Prismfolio only.
For company-wide practices across Vault & Compass products (including how we describe Sheetful and the corporate site), see the Vault & Compass privacy policy.
1Information We Collect
Portfolio Data
The Prismfolio browser extension extracts portfolio data from brokerage websites when you choose to analyze your holdings. This includes:
- Stock symbols and quantities
- Current market values
- Asset allocation data
- Sector and industry classifications
Analytics Data
We use a single analytics tool, PostHog, served from our own domain. Until you make a cookie choice, and whenever you decline (or your browser sends a Global Privacy Control signal, which we honor), PostHog runs in cookieless mode: it counts page visits in memory only, stores nothing on your device, sets no cookies, and identifies no one. Only after you click Accept do we enable full product analytics.
We do not use Google Analytics. The Prismfolio browser extension sends no analytics of any kind: no PostHog, no Google Analytics, and no usage or behavioral telemetry. The only thing the extension transmits on its own initiative is a crash report when it hits an error, through Sentry, described in section 4.
Global Privacy Control is honored as an opt-out: when your browser sends the signal we record your choice as declined and confirm on screen that we saw it. If you then deliberately turn analytics on using the cookie preferences control below, that later choice stands, and the on-screen note says so.
On this site, cookieless mode collects only:
- A count of page visits, held in memory for the life of the page
- No cookies, no browser storage, no profile, and no cross-visit identifier
After you accept, we may also collect:
- Page views and session duration on the marketing site and web app
- Feature usage events (no portfolio holdings in analytics payloads)
- Clicks and other interactions on the page, collected automatically rather than event by event
- Browser type and anonymised referrer information
- Masked session recordings on marketing pages (inputs hidden before transmission)
You can change your choice on the web at any time via cookie preferences or the site consent banner. Sentry error reporting runs separately for service stability (see section 4a).
2How We Use Your Data
We use your data for the following purposes:
- Portfolio Analysis: To provide insights into your investment portfolio's diversification, risk, and performance
- Service Improvement: Cookieless visit counts, and full web analytics once you accept, help us understand how prismfolio.io is used; signed-in product usage may also inform reliability and capacity planning without putting holdings in analytics payloads
- Account Services: To provide cloud sync and multi-device access for web app users
- Error Reporting: To detect and diagnose technical issues using Sentry error tracking
- Security: To protect against fraud and ensure the security of our service
3Data Storage & Processing
Browser Extension (Extract vs Analyze)
The Prismfolio browser extension extracts portfolio data from brokerage websites on your device. What happens next depends on whether you are signed in:
- What the extension reads: Prismfolio doesn't have its own connection to your broker. It works by reading your broker's page in your browser. The extension reads the pages you open at your broker while you are signed in there. Those pages sometimes carry account-holder details such as name, postal address or phone number alongside your holdings, because your broker includes them in the same response. Prismfolio uses only your holdings, account names and masked account numbers. Anything else is discarded on your device and is never sent to our servers.
- Extract (on device): Reading holdings from the broker page happens in your browser. We never see your brokerage login credentials.
- Anonymous use: A local copy may be kept in Chrome's storage API. Uninstalling the extension removes that local data.
- Signed-in analyze / sync: When you sign in and run analysis (or sync), holdings are sent to our API and stored in our database so the web app and multi-device features work. This applies on Free and Plus, cloud storage is not limited to Plus.
Web App with Plaid Integration
If you use the web app to link investment accounts via Plaid:
- Plaid's secure infrastructure routes data through Plaid's servers (the same system used by Robinhood, Venmo, and Betterment)
- Read-only access: We can view your holdings but cannot trade or move your money
- OAuth security: Your brokerage credentials are never stored or visible to us; Plaid handles authentication
- Account-holder identity and contact information: Connected-account data delivered by your financial institution may include identity and contact details for the account holder, such as name, postal address, email address, and phone number on file with that institution. Financial institutions may share this category with connected-account data regardless of which data a product requests. We request investment account data only, and do not ask your institution for identity or contact information.
- Encrypted tokens: Plaid access tokens are encrypted with AES-256-GCM before storage in our database. Portfolio holdings are stored as application data in our database and protected by our host provider's encryption at rest and access controls, not the same app-level AES wrap used for tokens.
- No sale of data: We do not sell your portfolio data. We share data only with processors listed in section 4 as needed to operate the service (for example Plaid, Stripe, Neon, hosting, and error monitoring), under contract.
Your broker relationship
Brokers generally treat use of a third-party tool, including Prismfolio, as authorized by you, and that can affect the broker's own fraud protection guarantee. This is true of any portfolio tool, including bank connection services, and is not specific to Prismfolio.
Your relationship with your brokerage is between you and the brokerage. We take no responsibility for your broker's site, or for anything that happens there.
Privacy commitment: Whether you use the browser extension or web app, we do not sell your personal information. Investment data is used to provide portfolio analysis and related product features, and is shared with service providers only as described in this policy.
Account Data (Optional)
If you choose to create an account, we store your email address and portfolio data from analyses and syncs you run while signed in (subject to your plan limits). Signing in is optional for basic extension extract; signed-in Free and Plus both use our cloud for web features.
4Third-Party Services
We use the following third-party services:
Plaid (Account Linking)
For web app users who link investment accounts, we use Plaid to securely connect to your brokerage. Plaid is SOC 2 Type II certified and used by major financial apps like Robinhood, Venmo, and Betterment. Plaid never shares your brokerage credentials with us.
PostHog
PostHog is our only analytics tool. We use PostHog Cloud for product analytics on prismfolio.io (feature usage and friction signals). PostHog does not sell data to advertisers. Session recordings are fully masked (all inputs and marked sensitive fields are hidden before transmission), and they run only after you accept.
Analytics requests are sent to prismfolio.io and forwarded to PostHog by our own servers, so your browser never contacts PostHog directly.
Before you make a cookie choice, and if you decline, PostHog runs in cookieless mode: page visits are counted in memory, nothing is written to your device, and no profile is created. Session recording, autocapture, and feature-usage events are off in that mode.
Sentry
We use Sentry for error monitoring and crash reporting. Sentry collects error logs and stack traces to help us diagnose and fix technical issues. When an error occurs, Sentry may also record a replay of that session. Replays are configured to mask all on-screen text and to block media before transmission, so a replay is meant to show the layout and the actions taken rather than the figures on your screen. This app draws its charts as SVG, and we are still verifying that chart labels are masked by that setting; until we have confirmed it, we do not claim that a replay can never contain a figure from your portfolio. Sessions without an error are not recorded. Our code strips request headers from error reports before sending them, and we do not attach your name or email to them; that stripping applies to error reports, while replays travel on a separate channel and are governed by the masking settings described above. Because your browser sends these reports to Sentry directly, Sentry can see the IP address the report comes from, in the same way any service you connect to can; that is a property of the connection rather than something we put in the report.
Stripe (Billing)
Plus subscriptions are processed by Stripe. Stripe receives payment and billing contact information you provide at checkout. We do not store full payment card numbers on our servers.
Google (Sign-in)
If you sign in with Google, Google provides basic profile information (such as name and email) under OAuth. We use it only to authenticate your Prismfolio account.
Resend (Email)
We use Resend to send operational email from contact and feedback forms (notifications to our team, and related transactional messages). Sign-in is Google-only, we do not send password-reset email. Plus billing receipts and invoices are sent by Stripe, not Resend. Resend processes recipient addresses and message content on our behalf.
Neon (Database)
Signed-in Free and Plus account and portfolio sync data is stored in Neon Postgres. Data is encrypted in transit and protected by Neon/host encryption at rest and access controls in production.
Vercel (Web hosting)
Our marketing site and Next.js web application are hosted on Vercel. Vercel may process request metadata (such as IP address and user agent) as part of delivering pages.
AWS App Runner (API hosting)
Our API server runs on AWS App Runner at api.prismfolio.io. Request metadata needed to serve authenticated API calls may transit AWS infrastructure; portfolio and account data is stored in Neon Postgres, not on App Runner hosts beyond processing in memory.
Upstash (Rate limiting)
We use Upstash Redis for API rate limiting. Upstash may process request identifiers needed to enforce limits; it does not receive portfolio holdings.
4a. Cookies & Analytics
We use cookies and similar technologies for essential service operation and, with your consent, full product analytics. Essential cookies and technologies (for example auth session cookies, the small cookie that remembers your analytics choice, and Sentry error reporting) run without an Accept click. PostHog runs in cookieless mode until you accept, and in full mode after. The table below lists analytics and error tools, what they collect, and when they activate.
| Service | Purpose | What it collects | Activated |
|---|---|---|---|
| PostHog (cookieless mode) | Page-visit counting | A page-visit count held in memory. Each page view carries the page address, the page you came from, and basic browser and device information. It travels through our own server, which like any web server sees the IP address the request comes from; we do not pass your IP address on to PostHog, so the analytics service never sees it. No cookies, no browser storage, no profile, no cross-visit identifier. | Before you choose, and on Decline |
| PostHog (full mode) | Product analytics | Feature usage events, masked session recordings. No financial data. | On Accept only |
| Sentry | Error reporting | Stack traces and error context, plus a text-masked, media-blocked session replay captured only when an error occurs, and the IP address the report is sent from. Essential for service stability. | Always (essential) |
What Decline means: Declining stops all analytics storage and all identification. PostHog keeps counting page visits in memory so we know how many people visited, but it sets no analytics cookies, builds no profile, and records no session. If you had accepted before, the identifiers and stored properties from that earlier visit are erased the moment you decline, not at some later point. Two things described elsewhere in this section are still kept: the record of your analytics choice itself, and the tab-scoped record of the campaign that brought you here, which disappears when you close the tab. That stays true on later visits unless you change your choice on this page.
Global Privacy Control
We honor Global Privacy Control as an opt-out, and it applies to the browser that sends it. See Analytics Data in section 1 for how the signal is recorded, how we confirm it on screen, and when a later choice of your own overrides it.
How you found us
When you arrive from an advertisement or a campaign link, the link carries campaign parameters (for example a click identifier and the campaign name). We record those, the referring site, and the page you landed on, so we can tell which campaigns bring people here. These are campaign details, not personal information, and we never put anything you type into this record.
Consistent with the rest of this section, we hold that record only for the current browser session unless you accept analytics. If you accept, it is stored in a first-party cookie named pf_first_touch for up to 180 days. If you decline, or never choose, no such cookie is ever written and the record disappears when you close the tab.
4b. Data retention
We retain data while your account is active, and as needed to provide the service:
- Active account history: Portfolio snapshots in our database are kept to power trend charts and history views (typically up to about 90 days of snapshot history for signed-in users).
- After you delete your account: We delete or anonymize associated cloud data from active systems within 30 days, except where retention is required by law or needed to resolve disputes.
- Disaster-recovery backups: Encrypted database backups / point-in-time recovery windows are short-lived (on the order of days, not months) and are overwritten on rotation; they are not used for other purposes.
- Extension-only (anonymous): Clear extension storage or uninstall to remove local data.
Contact and support messages are retained long enough to respond and maintain service quality, then archived or deleted according to operational needs.
4c. Security
We use industry-standard safeguards for data in transit and at rest, including HTTPS, encrypted tokens where applicable, and access controls for production systems. No method of storage or transmission is perfectly secure; if you discover a vulnerability, please email security@prismfolio.io. For a deeper overview, read our Security page.
5Your Rights
You have the following rights regarding your data:
- Access: You can view all data stored locally in the extension at any time
- Deletion: You can delete your local data by clearing the extension data or uninstalling it. For cloud-stored data, contact us or use your account settings
- Opt-Out (web analytics): You can turn full web analytics off anytime via cookie preferences or the site consent banner, and we honor Global Privacy Control. The Chrome extension needs no analytics opt-out because it runs no analytics; extension error reporting (Sentry) is limited to crash/diagnostic data for stability.
- Data Portability: You can export your portfolio data from the extension
- Correction: You can update or correct your data at any time through the extension interface
Disconnecting a linked account
Removing a linked account in Prismfolio stops our syncing and removes the stored holdings for that account. You can also revoke the connection at your financial institution, using the connected-apps controls in its online banking settings. At Citi, for example, the path is Citi Online, then Profile, then More settings, then Connected Apps; other institutions place the equivalent controls elsewhere in their online banking settings. Changing your bank password does not revoke access previously granted to a data aggregator, so use the revocation control at your institution, remove the account here, or both.
California (CCPA)
California residents may request access, deletion, and information about our data practices. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. To exercise these rights, email privacy@prismfolio.io or use account settings (including account deletion). For optional web analytics opt-out, use cookie preferences.
Other jurisdictions
Where GDPR or similar laws apply, you may have rights to access, portability, erasure, restriction, and objection. Contact privacy@prismfolio.io to exercise these rights. We respond within 30 days where required.
6Children's Privacy
Our service is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately, and we will take steps to delete such information.
7Policy Updates
We may update this Privacy Policy from time to time. When we do, we will:
- Post the updated policy on this page
- Update the "Last updated" date at the top
Your continued use of the service after any changes constitutes acceptance of the updated policy.
8Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Vault and Compass, LLC1111B South Governors Avenue STE 7017Dover, Delaware 19904United StatesEffective Date
This Privacy Policy is effective as of September 2, 2026, and will remain in effect except as otherwise stated in any future revisions to this policy.