Effective 2026-07-07
CIOport is built so that the analysis comes to your data, not the other way around. The computation that binds world events to your portfolio runs in your browser — which means most of the data you'd expect a finance app to collect, we simply never receive.
The following lives only in your browser's local storage. It is never sent to us:
cioport.holdings.manual)cioport.userRules)cioport.mdkey.*) — vendor keys you
paste in are stored locally and used by your browser to talk to that vendor directlyClearing your browser's site data deletes all of it. We have no copy — which also means we cannot recover it for you, so export a backup if it matters.
The app works without an account. Signing in (which unlocks quote and news layers) uses your Google account: Google confirms who you are (under Google's privacy policy), and our own sign-in service turns that confirmation into short-lived session tokens your browser holds. Inside those tokens we see your e-mail address and an opaque Google account identifier — and that is all. The session lives entirely in signed tokens (one of them an HttpOnly cookie — see the cookies page): nothing about you is stored on a server, and we do not maintain a database of user profiles.
Some market data (for example crypto and equity price history) is fetched by your browser directly from the data vendor — CoinGecko, or an equity vendor you hold a key for (Twelve Data, Alpha Vantage). Those requests go from your device to the vendor and are governed by the vendor's own privacy terms; they never pass through us.
The site and its data layers are served via Cloudflare, which produces standard server logs (including IP addresses) for security and operations, under Cloudflare's privacy policy. Our data pipeline runs on Google Cloud and processes public market and event data only — no personal data.
A future release will offer optional server-side portfolio sync (so your holdings can follow you across devices). If you choose to use it, that data will be stored for you — and this policy will be updated before that feature ships, with the changes dated and summarized here.