Privacy & Security
Your data stays yours.
Global Wealth Portfolio is designed with privacy by design and security by default. This policy describes what data we collect, how we use it, and the choices available to you.
1. Contact
For any privacy-related requests or concerns, use the contact form on our website. We aim to respond within 30 days.
2. Data collection & purpose
We collect the minimum data necessary for the service to function:
- Financial data (investments, expenses, goals, EMI) — stored in your browser's
localStoragefor offline use. Never sent to our servers. - Blog subscribers — email address only, stored in encrypted Cloudflare KV, used solely to send new-post notifications. Unsubscribe one-click at any time.
- Usage analytics — anonymized page view data via Google Analytics (G-J020W8NDX9). Google sets cookies for this purpose. No personally identifiable information is collected.
- Advertising — contextual ads via Google AdSense. Google may set cookies to personalize ads. No advertising is based on your financial data within the app.
3. Security measures
🔒 HTTPS with TLS 1.3
All data in transit is encrypted using TLS 1.3 via Cloudflare's edge network. HSTS is enforced (max-age=63072000; includeSubDomains; preload).
🔐 AES-256-GCM encryption at rest
You can optionally encrypt all localStorage data with AES-256-GCM using a passphrase (Settings → Encryption). Key derivation uses PBKDF2 with 600,000 iterations. The passphrase is never stored — data remains encrypted at rest until you unlock it in a session.
🛡️ Access controls & audit logs
All data changes are recorded in an append-only audit log with timestamps and action descriptions. The admin panel is protected by a passphrase with optional OTP-based password reset via EmailJS.
📦 Encrypted server storage
Server-side data (blog posts, subscriber emails) is stored in Cloudflare KV, which encrypts all data at rest using AES-256. Admin API endpoints require a Bearer token (ADMIN_TOKEN).
🧹 Local processing
Bank statement OCR (Tesseract.js) and PDF import run entirely in your browser. Uploaded files are never transmitted to any server and are discarded after processing.
4. Your data choices
- Export your data — Settings → Import/Export → Export JSON
- Edit or delete data — directly in the app (all changes are local). Use "Reset all data" in Settings to clear everything.
- Unsubscribe — click the unsubscribe link in any newsletter email to stop receiving notifications.
- Ad preferences — Google's ad settings can be managed at adssettings.google.com.
- Contact us — use the website contact form for any data-related requests.
5. Cookies
Google Analytics and Google AdSense set cookies in your browser when you visit this site. These cookies help us understand site usage and serve relevant ads. You can control cookie settings through your browser preferences.
6. Data retention
Local data persists until you clear your browser data or use "Reset all data". Subscriber emails are retained until the subscriber unsubscribes (DELETE request) or requests removal. Analytics data is retained per Google's data retention policy (26 months).
7. Third-party services
- Cloudflare (CDN, DNS, KV storage, edge network) — Privacy Policy
- Google Analytics (anonymized page views) — Privacy Policy
- Google AdSense (contextual ads) — Privacy Policy
- Google Fonts (typography) — Privacy Policy
- Resend (newsletter email delivery) — Privacy Policy
8. International transfers
Data may be processed on Cloudflare's global edge network (Standard Contractual Clauses in place). Local data stays on your device and never crosses your browser's origin.
9. Policy updates
This policy was last updated on June 15, 2026. Changes will be posted here. For significant changes, returning users will see a notice on the dashboard.
Contact
Use the contact form on the website for any privacy-related requests.