Privacy Policy
Last updated: March 16, 2026
This Privacy Policy explains how Invesaro ("we", "us") collects, uses, and protects your personal data when you use our service.
1. Data We Collect
- •Account data: email address, name (if provided), hashed password
- •Google account data: email, name, profile picture (if you sign in with Google)
- •Subscription data: Stripe customer ID, subscription status, billing dates
- •Portfolio data: cryptocurrency positions you add (coins, amounts, prices)
- •Usage data: pages visited, features used (if analytics cookies accepted)
- •Technical data: IP address, browser type, device type (server logs)
2. How We Use Your Data
- •Provide and maintain the Service
- •Process payments via Stripe
- •Generate personalized AI analyses for your portfolio
- •Improve the Service (anonymous analytics, if consented)
- •Communicate service changes or issues
3. Data Storage & Security
Your data is stored in a PostgreSQL database on a secured server. Passwords are hashed using bcrypt. All connections are encrypted with TLS/SSL. We do not sell or share your personal data with third parties, except as required for payment processing (Stripe).
4. Third-Party Services
- •Stripe — payment processing (subject to Stripe's Privacy Policy)
- •Google OAuth — authentication (subject to Google's Privacy Policy)
- •Google Analytics — anonymous usage analytics (only with your consent)
- •CoinGecko API — market data (no personal data shared)
5. Cookies
We use essential cookies for authentication and session management, and optional analytics cookies (Google Analytics) only with your explicit consent. You can manage cookie preferences at any time via the cookie banner.
6. Your Rights (GDPR)
If you are in the EU/EEA, you have the right to:
- •Access your personal data
- •Correct inaccurate data
- •Delete your account and all associated data
- •Export your data
- •Withdraw consent for analytics cookies
You can delete your account directly in Settings. For other requests, contact us at:
support@invesaro.com7. Data Retention
Account data is retained as long as your account is active. When you delete your account, all personal data is permanently removed within 30 days. Anonymous analytics data may be retained indefinitely.
8. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via the Service. Continued use constitutes acceptance.