Last updated: 9 July 2026 · applies from version v3.6.0+
PulseMyPortfolio ("PMP", "the application") is a personal portfolio- and wealth-tracking application with AI analyses. This policy describes what the application does (and, above all, does not do) with your data.
In short
- Your data lives on your device, not on PMP's servers.
- No telemetry, no analytics, no tracking cookies.
- Your API keys stay local (never stored on a PMP backend).
- The AI providers you configure (Anthropic, OpenAI, Gemini, Mistral, Groq, Cerebras, DeepSeek, Grok, Perplexity, OpenRouter, or Ollama, 100% local) only receive the data for the analysis being run, not your entire portfolio. Some process the data outside the European Union.
- No user account: PMP works without sign-up.
1. Data stored locally (on your device)
All of this data is kept in the application's local storage (the browser's localStorage, or its native Capacitor equivalent):
- Your positions: tickers, quantities, cost basis, accounts, currencies
- Your wealth: current accounts, savings accounts, real estate, loans/liabilities entered manually
- Your settings: display preferences, custom sectors, expert options
- Your analyses: AI-analysis results, kept so they can be reopened without a new call
- Your API keys: for each configured AI provider
- Your API-usage tracking (for cost-estimation purposes)
This data never leaves your device, except when you: explicitly export a backup (Settings → Data), use the encrypted transfer (QR / PIN code) to another device, run an AI analysis (section 2), or send a bug report (section 4).
2. Data sent to AI providers
When you run an AI analysis, PMP sends the provider that you configured only the information needed for the requested analysis:
| Type of analysis | Data sent |
|---|---|
| Sector analysis | Sector name, public news (Yahoo Finance) |
| In-depth stock analysis | Ticker, name, sector, news, Yahoo metrics |
| Import from screenshots | The image you upload, as is. This is the only feature where PMP transmits a raw file rather than selected fields. A broker screenshot may show your name, address or account number: crop or mask those areas before importing. The app reminds you of this at upload time. |
Requests go through the PMP backend, which acts as a proxy (without storage). Your API key is passed in the x-api-key header, used immediately for the call to the provider, and never logged server-side.
Each provider has its own processing terms:
- Anthropic (Claude), United States
- OpenAI, United States
- Google AI Studio (Gemini), United States
- Mistral, European Union (France)
- Groq, United States
- Cerebras, United States
- DeepSeek, China
- xAI (Grok), United States
- Perplexity, United States
- OpenRouter, United States (multi-model relay)
- Ollama, local, on your machine: no data sent to a third party
Most of these providers process your requests outside the European Union (mainly in the United States, DeepSeek in China). Mistral is established in the EU. The choice is yours: if the processing location matters to you, favour an EU provider or Ollama (100% local).
3. Market data fetched from third parties
To show prices, filed accounts and market context, PMP queries four public sources, always through the PMP proxy and without storage:
- Yahoo Finance: prices, histories and fundamental metrics of the tickers you follow, exchange rates, and recent news by sector (used to feed the AI analyses).
- SEC EDGAR (the US regulator): annual financial statements of US-listed companies (up to 19 years), and quarterly portfolio filings of the managers covered in Markets → Leading managers.
- OpenFIGI (Bloomberg): converting an ISIN or CUSIP code into a stock symbol, when adding a holding and to name the holdings filed with the SEC.
- FRED (Federal Reserve Bank of St. Louis): central bank policy rates and sovereign yields on the Markets page.
These requests contain only security identifiers (stock symbol, ISIN or CUSIP code) and public filer identifiers. No amount from your portfolio, no quantity and no personal data appears in them. That said, as with any financial website you might visit, these providers do see which securities are requested from your connection.
4. Bug reports sent by e-mail
If you use the "Report this bug" button, an e-mail is pre-filled with: PMP version, active route, timestamp, browser user-agent, error message and technical stack (truncated, with the systematic removal of any string resembling an API key).
It's your mail client that takes over. You see the full content, you can edit it or cancel it. No automatic transmission.
Reports are sent to the support address.
5. No tracking in the app, minimal audience measurement on the site
PMP uses no analytics tool: no Google Analytics, Mixpanel, Plausible, nor Sentry / Bugsnag / Datadog, no tracking cookies, no fingerprinting.
That statement is about the app. This website, on the other hand, counts its page views, its downloads and the time spent per page, using our own counters and no third-party tool. The measurement is cookieless and has no visitor identifier: what is recorded is the page visited, the file downloaded and its version, the time spent, the browser language reduced to two letters, and the country when our host provides it. No IP address (neither in the clear nor hashed), no cookie, no browser fingerprint, no session identifier. The country is never derived from an IP address. There is therefore no "unique visitor" and no row can be tied back to a person. Detail is kept for at most 24 months, after which only monthly totals remain. Turning off JavaScript is enough not to be counted.
6. Your rights (GDPR)
PMP does not collect any personal data server-side (everything stays on your device). The usual rights nonetheless apply:
- Access: your data is on your device. Export it via Settings → Data → Export. The file carries the .pmpbackup extension and its contents are readable JSON.
- Erasure: Settings → Data → "Erase all data", or uninstall the application.
- Portability: the .pmpbackup export is designed to be re-importable into any PMP instance. Backups saved as .json by earlier versions remain importable.
- Objection: use a different AI provider, or none (PMP works in "no-AI" mode, with the Yahoo signals only).
- Rectification and restriction: since your data is on your device, you correct or freeze it directly in the application. For the few items we do hold (see "Buying a Pro licence" below, and support exchanges), write to us: we will correct the data or restrict its processing.
- Complaint: you may at any time lodge a complaint with the supervisory authority. In France that is the CNIL (3 place de Fontenoy, 75334 Paris Cedex 07, cnil.fr). If you reside in another EU country, you may also contact your own national authority.
Support exchanges. When you write to us ("Report a problem" button or e-mail), we keep the conversation thread for as long as it takes to handle the request, then for at most 24 months to track defects. Legal basis: our legitimate interest in providing support and fixing faults.
7. Buying a Pro licence
This section describes the only processing for which WM STUDIOS holds data about you. It applies as soon as sales open. While no purchase is possible, none of this data exists.
- What is collected: your e-mail address (to deliver your licence key) and the billing data required (name, country, amount). We never see your card number: payment is handled by Stripe, acting as payment processor.
- Why: to perform the sales contract (licence delivery, support, any refund) and to meet our accounting and tax obligations.
- Legal basis: performance of the contract for delivery and support, and a legal obligation for keeping accounting records.
- For how long: the register of issued licences is kept for as long as the licence is valid, so that we can re-issue it if you lose it. The device fingerprint is deleted when you deactivate the device, and at the latest 24 months after its last online verification. Invoices are kept for 10 years, as required by article L123-22 of the French Commercial Code. That period cannot be shortened on request.
- Who else has access: Stripe (payment) and our mail host, each only for the part that concerns them. No resale, no profiling, no advertising.
- On activation: the key and a hashed device fingerprint (details in the next paragraph), stored on our licence server hosted in the European Union.
Activation (inside the app). On the first activation of a purchased licence, the app contacts our licence server, sending the key and an anonymous (hashed) device fingerprint: never your identity, never your portfolio. That fingerprint is used solely to limit activation to 2 devices at a time and to prevent licence sharing. You can free a slot at any time from the app. The app then works offline again. An occasional re-check happens when a connection is available (30-day tolerance window). Unlike the rest of the application, purchase and activation do involve a server: it is the only part of PMP that is not offline.
Legal basis for the fingerprint: our legitimate interest in preventing the sharing of a personal licence. It is kept for as long as the licence is valid, and disappears when you free the slot.
The rest of this policy still holds: your positions, accounts, analyses and API keys never leave your device and are tied to no account of ours. Buying a licence does not create a user account, and all computations (valuation, taxation, projections) remain local.
8. Changes to this policy
This policy may evolve (adding an AI provider, changing the support channel…). The last-updated date at the top of the page indicates the current version. Significant changes are announced in the application's release notes.
Contact
Publisher and controller: WM STUDIOS (61 rue de Lyon, 75012 Paris, France). Apart from buying a licence (see section 7), no personal data is retained on our servers: the PMP backend acts as a plain relay, with no storage and no logging of request contents. On the desktop versions (Windows, macOS, Linux) that relay runs on your own device and nothing passes through us. On the Android app, requests go through our relay server before reaching the AI provider: if you import a screenshot containing personal data, it passes through us for the duration of the call, without being recorded.
For any question relating to privacy, write to us at the support address, or see the legal notice.