Privacy Policy
Last updated: August 2026
Capendium (“the App,” “we,” “us”) is a personal capital intelligence platform for tracking a multi-asset investment portfolio. This page explains what data the App stores about you, why, and where it lives.
1. Information we collect
- Google account info — if you sign in with Google, we receive your name, email address, and profile picture URL (the standard
email + profile + openidOAuth scopes). We do not receive your Google password or any other Google data. - Email and password — if you sign in with email/password instead, we store your email and a hashed password (managed by our auth provider, Supabase).
- Portfolio data you enter — transactions, NAV history, target allocations, FX rates, and portfolio configuration. This data is stored only because you typed or imported it.
- IBKR Flex token — if you connect Interactive Brokers, your Flex Query token is encrypted with AES-256-GCM before being stored. The plaintext token never leaves your browser unencrypted and the server never returns it.
- Session tokens — a JWT issued by Supabase to keep you signed in. Stored in your browser’s
localStorage.
2. How we use it
- To authenticate you and keep you signed in.
- To display your portfolio on your dashboard.
- To compute returns, risk metrics, and projections using your data.
- To fetch market quotes and FX rates on your behalf from public sources (Yahoo Finance, MAS).
We do not use your data for advertising, analytics, profiling, marketing, or any form of sale or sharing with third parties beyond the infrastructure listed below.
3. Where data is stored
- Supabase (Postgres database, hosted in the Singapore region) — portfolio data is stored in a per-user key-value table with Row-Level Security enforcing that you can only read your own rows.
- Vercel — hosts the App’s static files and serverless API endpoints.
- Your browser —
localStorageholds your session token plus a cache of your portfolio data for offline-resilient page loads.
4. Third-party services
- Supabase — auth and database. Privacy policy.
- Vercel — hosting. Privacy policy.
- Google — if you use Sign in with Google as your identity provider.
- Yahoo Finance and MAS (Monetary Authority of Singapore) — read-only market data fetched server-side. No personal information is sent to these services.
- Interactive Brokers (Flex Query API) — only if you connect IBKR. We call IBKR’s API on your behalf using your encrypted Flex token.
5. Data retention and deletion
Your data is retained for as long as you have an account. If you want to delete your account and all associated data, email us (see Contact) and the data will be removed from Supabase within a reasonable time. You can also clear your browser’s localStorage at any time to remove the local cache.
6. Security
- All traffic is served over HTTPS.
- Supabase Row-Level Security policies prevent users from accessing one another’s data.
- IBKR Flex tokens are encrypted at rest using AES-256-GCM with a server-held key.
- Capendium is not a regulated financial service. Do not store data here that you would not be comfortable losing if the App were compromised or shut down.
7. Cookies and tracking
The App does not use cookies for tracking. It does not run third-party analytics, advertising pixels, or behavior trackers. The only browser-side storage is the Supabase session token and a portfolio data cache in localStorage.
8. Children
The App is not directed at children under 13 and we do not knowingly collect data from them.
9. Changes to this policy
If this policy changes materially, the “Last updated” date above will change. Continued use of the App after a change indicates acceptance of the revised policy.
10. Contact
Questions, deletion requests, or anything else: support@capendium.com.