Legal
Privacy Policy
This policy explains how Compndr ("Compndr", "we", "us") handles personal information when you use the Compndr application at compndr.io. Compndr is an Australian product and this policy is written with the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth) in mind. It describes what we actually collect and do today — not what we might do later.
Information you give us
- Account details. Your email address and, if you sign in with Google, the basic account identifiers Google returns. Passwords are handled by our authentication provider and are never stored by us in readable form.
- Profile settings. An optional display name, your reporting currency, your timezone and, only if you choose to enter it, your date of birth (used to set projection horizons).
- Portfolio information. The portfolios, transactions, holdings, opening balances and reconciliation adjustments you enter — asset symbols, quantities, dates, prices, fees and notes. This is financial information about you, and you choose what to record.
- Imports. CSV files and screenshots you upload. We store the resulting transactions plus import records (file name, row count, column mapping, status and any error).
- Goals. Wealth goals, target amounts and target dates you create.
- Questions you ask. The text you type into Ask Compndr, which is processed to produce an answer (see AI processing below).
Information collected automatically
- Product analytics. We record events such as which screens you open and which features you use, together with a session identifier, an anonymous device identifier, the route, timing and whether the action succeeded or failed. Event details are limited to a fixed internal list of fields — free text is not captured.
- Device and technical information. Broad device category, operating system, browser and a coarse viewport size band, plus the app version.
- Coarse location. Where our hosting platform supplies it, we store a country and region code with analytics events. We do not store your IP address and we do not perform IP geolocation ourselves.
- Referral information. A referrer category or domain and any campaign parameters in the link you arrived through.
- Diagnostics. Error codes and operational records (for example failed imports, AI request outcomes, notification delivery results) used to keep the service working.
Seeds, notifications and support records
If you use Seeds — Compndr's in-app reward currency — we store your balance and a ledger of how Seeds were earned, spent, refunded or adjusted. If you enable push notifications we store the browser push subscription your device generates (endpoint and keys) and a delivery history. If an administrator acts on your account (for example a support adjustment or account status change), that action is recorded in an internal audit log.
Why we use your information
We use your information to run Compndr: to authenticate you, to calculate and display your portfolio value, performance, allocation, replay, projections and journey, to generate your Daily Briefing and Ask Compndr answers, to operate Seeds and entitlements, to send notifications you have enabled, to prevent abuse and rate-limit expensive operations, and to understand and improve how the product is used. We do not use your portfolio data for advertising.
AI processing
Compndr uses AI features that send data to an AI provider through the Lovable AI Gateway, which currently routes those requests to a Google Gemini model:
- Ask Compndr. Your question, the recent messages in that conversation, and a factual summary of your portfolio (such as holdings, symbols, quantities, values, cost bases, allocation and profit and loss) are transmitted so the model can answer using your own numbers. Your email address and account identifiers are not included.
- Daily Briefing. A factual summary of your portfolio movements and related market context is transmitted to generate the written briefing.
- Screenshot import. The image you upload is transmitted so the transactions in it can be read.
Ask Compndr conversations are not stored on our servers. We keep only a usage record of each attempt — its status, error code and the Seeds charged or refunded — and your conversation stays in your browser until you leave or reload the page. Generated Daily Briefings are stored against your account so the same day's briefing can be shown again, and expire automatically.
Service providers we use
- Hosting, database and authentication. Lovable Cloud (built on Supabase) stores your account, portfolio, analytics and Seeds records and handles sign-in.
- AI. Lovable AI Gateway, routing to Google Gemini models, as described above.
- Market and reference data. CoinGecko, Yahoo Finance, Binance, OKX, CoinPaprika, Marketaux and an open exchange-rate service. We send asset symbols and date ranges to these services — never your identity, balances or quantities.
- Email. Authentication and account emails are sent from our verified sending domain, notify.compndr.io, using our email infrastructure provider.
- Google Sign-In. Used only if you choose "Continue with Google".
These providers process information so that Compndr can operate. We do not sell your personal information, and we do not disclose it to third parties for their own marketing.
Overseas processing
Our hosting, AI, email and market-data providers operate internationally, so your information may be stored or processed outside Australia, including in the United States and other countries where those providers run infrastructure. We do not control the exact region for every provider.
Cookies and local storage
We do not use advertising or third-party tracking cookies. Compndr stores your sign-in session and some preferences in your browser's local storage, and uses first-party identifiers for analytics sessions. Clearing your browser storage signs you out.
Security
Your data is held in a managed database with row-level security rules so that a request can only read or change records belonging to the authenticated account. Traffic to Compndr is served over HTTPS. Administrative access is limited to accounts holding an admin role, and administrative actions are logged. No online service can be perfectly secure, and we cannot guarantee absolute security.
Retention and deletion
We keep your information while your account exists. You can edit or remove individual transactions, holdings and goals at any time inside the app. You can permanently delete your account from Settings, which removes your account records — including transactions, portfolios, goals, Seeds and profile information. Some limited records may persist briefly in routine backups or in aggregated, non-identifying statistics. Daily Briefings and cached market data expire automatically. We have not set fixed retention periods beyond this.
Access, correction and complaints
Most of your information is visible and editable directly in the app. You can also ask us for access to the personal information we hold about you, ask us to correct it, or make a privacy complaint — reach us through the Contact page. We will respond within a reasonable time. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner at oaic.gov.au.
Children
Compndr is not intended for children. You should not create an account unless you are at least 18 years old. If we become aware that we hold personal information about a child, we will delete it.
Changes to this policy
If we make material changes we will update this page and the date below. Continuing to use Compndr after a change takes effect means you accept the revised policy.
Effective 28 August 2026. Last updated: 28 August 2026.