1. Who is responsible
Investor Twin is operated from Denmark. For questions about this policy or to exercise privacy rights, email privacy@investortwin.app.
2. Data we process
Account and contact data
When account features become available, this may include your email address, internal user identifier, authentication information supplied by our identity provider, support messages, and consent records.
Brokerage and portfolio data
If you connect a brokerage, we may process connection status, brokerage name, account metadata, balances, positions, holdings, allocation values, currencies, and transaction or activity history. Investor Twin does not ask you to provide brokerage login credentials directly; the brokerage connection is completed through the connection provider's hosted flow.
Imported portfolio data
If you use screenshot or manual import, we process the images and holding information you submit, including security names, tickers, quantities, values, and weights. Avoid uploading screenshots containing information that is not needed for portfolio import.
Device, usage, and diagnostic data
We may process app version, operating system, device identifiers used for service security, request times, IP address in server logs, connection errors, and crash diagnostics. Investor Twin does not use advertising trackers or sell personal data.
Public filing data
Institutional portfolio information comes from public sources such as SEC filings. This information generally concerns institutions and securities rather than Investor Twin users.
3. Why we use data
- Provide portfolio import, normalization, comparison, and explanation features.
- Create and maintain secure user and brokerage connections.
- Detect errors, fraud, misuse, and security incidents.
- Respond to support, access, correction, export, and deletion requests.
- Comply with legal obligations and enforce the service terms.
- Improve reliability using aggregated or de-identified product information where practical.
Under the GDPR, the relevant legal bases may include performance of a contract, legitimate interests in operating and securing the service, consent where requested, and compliance with legal obligations.
4. Providers and disclosures
Depending on the feature and environment, Investor Twin may use the following categories of service provider:
- SnapTrade for supported brokerage connectivity and normalized account data.
- Your brokerage or financial institution when you authorize a connection.
- Supabase for intended account authentication and database services.
- Railway for intended backend application hosting.
- OpenAI when screenshot analysis is used to extract portfolio holdings.
- Sentry for intended crash and reliability monitoring configured to minimize personal data.
- Expo/EAS and Apple for app build, distribution, and platform services.
We may also disclose information where required by law, to protect users or the service, or as part of a business transfer subject to appropriate safeguards. We do not sell personal data.
5. International transfers
Some providers may process data outside Denmark or the European Economic Area. Where required, transfers rely on adequacy decisions, Standard Contractual Clauses, or another lawful transfer mechanism, together with appropriate contractual and technical safeguards.
6. Retention and deletion
We keep personal data only for as long as needed for the purposes described above. Portfolio and connection records are intended to remain while your account or connection is active. Support, security, billing, and legal records may be retained longer where necessary. Backups and logs may take additional time to expire.
You can request deletion at investortwin.app/delete-account. A verified deletion request is intended to remove or de-identify account, portfolio, connection, order-draft, follow, and notification data, subject to legal and security retention requirements.
7. Your choices and rights
Depending on applicable law, you may have rights to access, correct, export, restrict, object to, or delete personal data, and to withdraw consent. You may also complain to the Danish Data Protection Agency or your local supervisory authority.
You may disconnect a brokerage connection without deleting your entire Investor Twin account. Contact privacy@investortwin.app if the in-app control is unavailable.
8. Security
Investor Twin is designed to keep provider credentials on secure backend systems, use encrypted network connections, restrict access, and separate user records. No system can guarantee absolute security. If you believe your account or brokerage connection may be compromised, contact your brokerage and security@investortwin.app promptly.
9. Children
Investor Twin is intended for adults and is not directed to children under 18. We do not knowingly collect personal data from children.
10. Changes and contact
We may update this policy as the service develops. Material changes will be communicated where required. Questions can be sent to privacy@investortwin.app.