Privacy Policy

Last updated 29 September 2026

MarketPulse is a market tracker for private investors. This page explains what personal data it handles, why, who else touches it, and what you can ask for. In short: it keeps only what the app needs to work, shows no ads, uses no analytics or tracking tools, and never sells your data.

Who is responsible

MarketPulse is run by Rui Baião, an individual based in Sweden, who is the data controller for the personal data described here. You can reach him at support@marketpulse.watch.

What we collect

  • Your account. Your email address and name. If you sign up with a password, only a secure hash of it is stored, never the password itself. If you sign in with Google, see Signing in with Google.
  • Signing in. One cookie keeps you signed in. Each sign-in session also records your IP address and browser type, to help keep your account secure. A session stops working when you sign out, or 30 days after you last used it.
  • What you add. Your portfolios and the holdings and transactions in the files you import, your watchlists, price alerts, signal rules, calendar reminders, target weights, decision-journal notes, chart drawings, flags and favourites, and your settings. An imported file is read to extract those records; its file name and row counts are kept, the file itself is not.
  • Notifications. If you turn on browser notifications, the delivery address your browser issues for them is stored. Email alerts go to your account's address. If you send a test email to another address, that address is used once and not stored.
  • In your browser only. Your theme and a few layout preferences, such as which watchlist is open, are kept in your browser's local storage and never sent to us.

MarketPulse sets no cookies other than the sign-in cookie, and uses no advertising, analytics or tracking tools.

Signing in with Google

If you choose “Continue with Google”, Google shares your name, email address and profile picture with MarketPulse: the basic sign-in information (the openid, email and profile scopes) and nothing else. MarketPulse does not ask for, and cannot see, your Gmail, contacts, Drive, calendar or anything else in your Google account.

This information is used only to create your account, sign you in and show your name in the app. It is not used for advertising, not sold, and not shared with anyone except the service providers below that run the app. MarketPulse's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

You can remove MarketPulse's access at any time in your Google Account settings.

Why we use it

  • To run the service you signed up for: your account, signing in, your portfolio, watchlists and alerts. The legal basis is the agreement between us (GDPR Article 6(1)(b)).
  • To keep accounts secure and the service working: session IP addresses and browser types, and short-lived technical logs. The legal basis is our legitimate interest in security (Article 6(1)(f)).
  • To send notifications you switch on. The legal basis is your consent (Article 6(1)(a)); turn them off at any time and they stop.
  • To answer you when you write to us.

Who else handles it

Your personal data is never sold or rented. These providers process it on MarketPulse's behalf, only to run the app:

  • Vercel hosts the app, whose servers run in Frankfurt, Germany. It keeps short-lived request logs, including IP addresses, for security and troubleshooting.
  • Neon runs the database, in Frankfurt, Germany.
  • Resend sends the emails: sign-in links, password resets, address verification and alerts, from its EU region in Ireland.
  • Google, only if you choose to sign in with Google.
  • Your browser's push service (Apple, Google or Mozilla, depending on your browser) delivers the notifications you turn on.
  • Elbstream serves the company logos shown next to securities. Your browser fetches them directly, so Elbstream sees your IP address and which logo was requested.

To show prices, news and company information, MarketPulse's servers ask market-data providers (such as Finnhub, Twelve Data, Eulerpool and Nasdaq) about securities by ticker or ISIN. Those requests come from our servers and carry no personal data: not your name, your email or what you hold.

Where a provider may process data outside the EU/EEA, the transfer is covered by the safeguards in its data-processing terms, such as the EU Standard Contractual Clauses.

How long we keep it

  • Your account and everything you added: for as long as you have an account. When you ask for your account to be deleted, it and all of its data are deleted within 30 days.
  • Hosting and email logs are kept by Vercel and Resend for a limited period, then removed.
  • Backups: the database host keeps automatic backups for a limited time, so deleted data disappears from them as they expire.

Your rights

Under the GDPR you can ask to:

  • see the personal data held about you, and get a copy of it;
  • have it corrected;
  • have it deleted, including your whole account;
  • object to, or limit, how it is used;
  • withdraw consent, for example by turning notifications off.

Email support@marketpulse.watch from your account's address, and you'll get an answer within one month. There is no delete button in the app yet: an email is enough, and your account and everything in it will be deleted.

You can also complain to Sweden's data protection authority, IMY, or to the authority in the EU country where you live.

How it is protected

Every connection is encrypted (HTTPS). Passwords are stored only as secure hashes. Each account's data is separated in the database itself, so one account cannot read another's. Only the operator has administrative access.

Children

MarketPulse is not meant for anyone under 18.

Changes to this policy

If this policy changes in a way that matters, you'll be told in the app or by email before the change takes effect. The date at the top shows the current version. See also the Terms of Use.