Privacy Policy
Investment Summary is a private, non-commercial tool operated by one individual for their own household. It emails each person a daily summary of their investment account values. It is not offered to the public, it is not advertised, and there is no sign-up: an account exists only because the operator created it for a named family member.
What is collected
When you connect an institution through Plaid Link, this service receives from Plaid your investment holdings and investment transactions for the accounts you selected, together with the institution's name and a durable access token. Holdings are reduced immediately to one daily total value and day-over-day change per institution, and only those totals are stored.
Separately, the operator records the email address, send time and time zone for each recipient.
What is never collected
- Your bank or brokerage credentials. You enter those inside Plaid Link; this service never sees them.
- Your name, address, date of birth, government identifiers, or account numbers. These are not requested from Plaid and are not stored.
- Individual securities, trades or positions are not retained — only per-institution totals.
There is no advertising, no profiling, and no analytics or tracking of any kind. Nothing is sold or shared for marketing, ever. Outgoing email contains no tracking pixels and no rewritten links, so opening or reading it is not recorded.
Cookies
One cookie is used, and only to keep you signed in. It holds a random
identifier — no personal information — and exists solely so the site
can recognise your browser between page loads. It is marked
HttpOnly (unreadable by scripts), Secure (sent only
over HTTPS) and SameSite=Lax (not sent from other sites).
It is strictly necessary for signing in, is not used for any other purpose, and is not shared with anyone. Signing out deletes it and revokes the session on the server at the same time.
Who else receives data
| Recipient | What they receive | Why |
|---|---|---|
| Plaid | your connection to your institution | to retrieve holdings |
| Anthropic | institution names, account balances, daily change | to write two or three descriptive sentences in the email |
| Resend | your email address and the message | to deliver the email |
| Sentry | error text, institution names, internal identifiers — no balances | to detect failures |
| Railway | hosts the application and database | infrastructure |
How long data is kept
- Daily value snapshots and email records: 24 months, after which they are deleted automatically by the daily job.
- Your Plaid access token: until you unlink the institution or ask for deletion, at which point it is revoked with Plaid and removed.
- Your email address and preferences: until you ask to be removed.
- Sign-in links: 10 minutes, and they stop working the moment they are used. Sign-in sessions: 90 days from your last visit, or immediately when you sign out. Both are stored only as a one-way hash, so the database does not hold a value anyone could sign in with.
How data is protected
All network traffic uses TLS. The Plaid access token is encrypted at rest with AES-256-GCM under a key held only as a platform environment variable. The database is not reachable from the public internet, and the operator's hosting and source accounts both require multi-factor authentication.
Your choices
- Exclude an account from your email without unlinking it.
- Stop receiving email at any time.
- Delete everything. The access token is revoked with Plaid and every row relating to you — accounts, snapshots, send history and your user record — is deleted. This is done within 30 days of your request, normally the same day.
- Ask what is held about you and receive a copy.
You can also revoke this service's access directly at my.plaid.com or with your institution.
Contact
Requests and questions: jasonaleibowitz@gmail.com