Gusi Portfolio Tracker privacy policy

Last updated 28 September 2026.

The short version

We store what you put into the app and what your broker sends us when you connect one, and we use it to show you your portfolio. You can delete all of it yourself, from inside the app, and it goes immediately.

The rest of this page is the detail behind those two sentences, because a summary that cannot be checked is worth nothing. Everything we hold is listed below.

Who is responsible

Gusi Portfolio Tracker is provided by Gusi Studios LLC, 2200 W 4th St. Apt. B, Hattiesburg, Mississippi 39401, United States. For anything on this page, write to support@gusistudios.com. Under the GDPR we are the controller of the data described here.

What we hold, and why

Your account

Your email address, a password that is stored only as a hash and is never readable by us, the date you accepted the risk disclaimer and which version you accepted, and the settings you choose: display currency, strategy, chart timeframes, colours, column order, and whether you want email or push notifications. If you want alerts sent to a different address than the one you sign in with, we store that too.

We need this to give you an account at all, and to show the app the way you set it up.

What you put in

Positions, purchase prices and dates, sales and the gains they realised, your watchlist and the notes you write on it, and the supply and demand zones and trend lines you or the app derive from price history. This is the substance of the app and the reason it exists.

Brokerage connections

When you connect a brokerage account, the connection is made through SnapTrade, on SnapTrade's own hosted portal. Your brokerage username, password and any two-factor code are entered there and never reach us. We never see them, never store them and could not replay them if we wanted to.

What we do store is the connection itself: an identifier for it, the broker's name, whether the connection is still working, identifiers and names for the accounts you choose to import, and the positions and transactions imported from them. We also store the identifier and secret that let us call SnapTrade on your behalf. These are ours, not yours, and they permit reading your connected accounts, not trading in them.

If you upload a Swissquote positions file instead, we store the account number that appears in it, so repeat uploads land in the same place, along with the positions.

Households

If you join a household, other members see what you choose to share, and you see what they choose to share. We store which household you belong to, when you joined, who owns it, and the invite codes used to join it, stored as hashes rather than as codes. What each member can see is described in the app at the point where you choose it.

Notifications

If you turn on push notifications, we store a device token and the platform it came from, so a message can reach that device. Removing the app or turning notifications off removes it.

Subscriptions

Your plan, its status, which store you bought it from, the billing period, when the current period ends, and an identifier from RevenueCat, which is what tells us whether a subscription is live. We never see or store card numbers or any other payment details. Those stay with Apple, Google or the payment processor.

Technical records

Server logs, which include the usual request details, and records of the scheduled jobs that check zones and send alerts. These exist so that a failure can be found and fixed, and so an alert that did not arrive can be noticed.

That is the whole of it. If something is not listed above, the app does not collect it, and this page changes whenever that list does.

Why we are allowed to hold it

Under the GDPR, each of these needs a legal basis. Ours are:

Who else touches it

We use a small number of providers. Each one gets only what it needs to do its job.

Market data and company filings come from EODHD, Yahoo Finance, Financial Modeling Prep and the SEC's EDGAR system. Those requests ask about a stock. Nothing about you goes out in them, and those providers are not told who is asking or what you hold.

Where it is

The database and the server code run in the United States, in the AWS us-east-1 region. If you are in the European Economic Area, the United Kingdom or Switzerland, your data is therefore transferred to the United States. That transfer relies on the European Commission's standard contractual clauses, and on each provider's own transfer terms.

How long we keep it

For as long as you have an account. Delete your account and it goes at once: this is a real deletion, not a flag on a row, and it takes your positions, sales, watchlist, notes, zones, trend lines and brokerage connections with it, including at SnapTrade. There is no grace period and nothing to undo, which is why the app asks you to confirm.

Deleted data is removed from live systems immediately and falls out of routine backups as those are rotated. Server logs and job records are short-lived by design. We keep the minimum we are required to about a deletion or a payment where the law says so.

How to delete your account, including what to do if you cannot sign in.

What you can ask for

Wherever you are, you can ask us for a copy of what we hold about you, to correct it, or to delete it. Write to support@gusistudios.com and we will answer within 30 days.

In the European Economic Area, the United Kingdom and Switzerland you also have the right to object to or restrict processing, the right to portability, and the right to withdraw consent at any time, which for us means turning off notifications. Withdrawing consent does not undo what was done before you withdrew it. If you think we have got this wrong, you can complain to your national data protection authority, and we would rather you told us first so we can fix it.

In the United States, including California, we do not sell personal information and do not share it for cross-context behavioural advertising, so there is nothing to opt out of. The access, correction and deletion rights above apply to you the same way.

Security

Every table in the database is protected by row-level security, so a request can only reach rows it is entitled to even if something above it is wrong. Passwords are hashed by Supabase's authentication service. Brokerage credentials never reach us at all. Traffic is encrypted in transit.

No system is perfect, and we would rather say that than imply otherwise. If you find a problem, write to support@gusistudios.com and we will take it seriously.

Age

Gusi Portfolio Tracker is for people aged 18 and over. It is not directed at children and we do not knowingly collect anything about them. If you believe a child has an account, write to us and we will delete it.

Changes

If this page changes in a way that affects you, we will say so in the app rather than quietly editing the date at the top. The date at the top tells you when it last changed.