timevest
Sign up

Privacy Policy

Last updated: May 19, 2026

1. Data Controller

Timevest ("we", "us", "our") is the data controller responsible for your personal data. For any privacy-related questions, contact us at [email protected].

2. Information We Collect

When you use Timevest, we collect the following categories of data:

  • Account data: Email address and display name, provided during registration.
  • Portfolio data: Assets, transactions, balances, strategy settings, fund allocations, and other financial information you voluntarily enter.
  • Chat data: Messages you send to the AI assistant and the AI responses generated.
  • Usage data: Pages visited, features used, session duration, device type, browser type, operating system, and approximate location (country level) — collected via analytics tools.
  • Technical data: IP address, browser user agent, and cookies necessary for authentication and service operation.

3. Legal Basis for Processing (GDPR)

We process your personal data under the following legal bases as defined by the EU General Data Protection Regulation (GDPR):

  • Contract performance (Art. 6(1)(b)): Account data, portfolio data, and chat data are processed to provide the Service you signed up for.
  • Legitimate interest (Art. 6(1)(f)): Usage and technical data are processed to improve the Service, ensure security, and prevent abuse.
  • Consent (Art. 6(1)(a)): Analytics cookies are placed based on your consent, which you can withdraw at any time.

4. How We Use Your Data

  • To provide, operate, and maintain the portfolio tracking service.
  • To power AI-driven portfolio analysis and chat features.
  • To process payments and manage subscriptions.
  • To improve the application based on aggregated usage patterns.
  • To send important service-related communications (security alerts, account changes, Terms updates).
  • To detect, prevent, and address fraud, abuse, and technical issues.

We do not use your data for profiling, automated decision-making, or targeted advertising.

5. Third-Party Services

We use the following third-party services to operate Timevest. Each may process limited data as described:

  • Supabase (database & authentication) — stores your account and portfolio data. Servers located in the EU/EEA.
  • Cloudflare (hosting & CDN) — serves the application and may process IP addresses for security and performance.
  • Anthropic (AI chat) — your chat messages are sent to Anthropic's Claude API to generate responses. Messages are not used by Anthropic to train models. See Anthropic's privacy policy for details.
  • PostHog (analytics) — collects anonymized usage data to help us improve the product. PostHog EU instance is used.
  • Binance & CoinGecko (market data) — price data is fetched from these APIs. No personal data is shared with them.

We do not sell, rent, or share your personal data with third parties for their marketing purposes.

6. International Data Transfers

Some of our third-party service providers may process data outside the European Economic Area (EEA). Where this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, or the service provider's participation in recognized data protection frameworks.

7. Data Retention

  • Account & portfolio data: Retained for as long as your account is active. Deleted within 30 days of account deletion.
  • Chat data: Retained for as long as your account is active. You can delete individual chat sessions at any time.
  • Usage & analytics data: Retained in anonymized form for up to 12 months.
  • Payment data: Retained as required by tax and accounting laws (typically 7 years for transaction records).

8. Data Storage & Security

Your data is encrypted in transit (TLS) and at rest. Access is controlled through row-level security policies, ensuring your data is visible only to you. We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction.

9. Your Rights Under GDPR

If you are located in the EU/EEA, you have the following rights regarding your personal data:

  • Right of access (Art. 15): Request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16): Request correction of inaccurate or incomplete data.
  • Right to erasure (Art. 17): Request deletion of your personal data. You can delete your account and all associated data from Settings, or contact us.
  • Right to data portability (Art. 20): Request your data in a structured, machine-readable format. Export is available from Settings.
  • Right to restrict processing (Art. 18): Request that we limit the processing of your data in certain circumstances.
  • Right to object (Art. 21): Object to processing based on legitimate interest.
  • Right to withdraw consent (Art. 7(3)): Withdraw consent for analytics cookies at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, email [email protected]. We will respond within 30 days.

You also have the right to lodge a complaint with your local data protection supervisory authority if you believe your data is being processed unlawfully.

10. Cookies

We use the following types of cookies:

  • Essential cookies: Required for authentication and core functionality. These cannot be disabled.
  • Analytics cookies: Used by PostHog to understand usage patterns and improve the Service. These are set based on your consent.

We do not use advertising or third-party tracking cookies.

11. Children's Privacy

Timevest is not intended for use by anyone under the age of 18. We do not knowingly collect personal data from children. If you believe a child under 18 has provided us with personal data, please contact us and we will promptly delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via the application or email at least 30 days before they take effect. The "Last updated" date at the top reflects the most recent revision. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.

13. Contact

For any questions, requests, or concerns about this Privacy Policy or your personal data, contact us at [email protected].

← Back to home
timevest

A modern portfolio tracker for crypto, gold, stocks and cash. Real prices, real averages, real strategy.

Sign up — free → Email us
Product
  • Sign up
  • How it works
  • FAQ
Company
  • Founder note
  • Email
Trust
  • Privacy
  • Terms
© 2026 Timevest. Track every buy. Beat every average.v1.0 · made with patience