Privacy Policy
Last updated: September 13, 2026
What this is
Stacking Yields is a personal dividend income and cash flow tracker. This policy describes what information the app stores, who can see it, and what happens to it. The app is currently invite-only, so this policy applies to a small number of users. It will be updated before any wider access opens.
What is stored
The app stores exactly what you enter to make the portfolio tracker work:
- Your email address, used only for authentication and to send password reset emails. No marketing emails are sent.
- Account information: account names, account types (taxable, IRA, 401k, etc.), cash balances, and whether DRIP cost-basis dilution applies.
- Holdings: ticker symbol, number of shares, cost per share, purchase date, whether DRIP is enabled, and any notes you attach (up to 1,000 characters). Notes are freeform text that you supply; do not put sensitive information there.
- Dividend payment history: for each dividend received, the app records the ex-dividend date, payment date, amount per share, number of shares held at the ex-date, and — if DRIP was on — the price at which shares were reinvested and how many shares were purchased. This history is the core of the income ledger and is retained even after a holding is closed or removed.
- Daily portfolio value snapshots, one per account per trading day, as a running record for future chart features. These store a total market value figure, not individual position values.
- Aggregate usage analytics: the app records that certain actions happened (a ticker was searched, the calculator was used, a holding was added) along with a coarse country (not city or region). No user identifier, IP address, or session ID is ever stored in analytics data. See the Analytics section below.
Tax rate inputs you enter in the calculator are not stored. They are processed in your browser and discarded when you close the tab.
What is not stored
- Brokerage credentials or access tokens of any kind
- Social Security numbers or tax identification numbers
- Bank account or routing numbers
- Payment card details
- Precise location (city, region, or GPS coordinates)
- Device identifiers or fingerprints
The app does not connect to your brokerage. You enter positions manually or via CSV import.
Analytics
The app tracks aggregate, anonymous usage events to understand which features are used. This is intentionally minimal by design, not just by policy:
- Events record what happened (a search, a calculator use, a holding added) and when — never who.
- No user ID, session ID, IP address, or any other identifier is stored in an analytics row.
- For public-facing events (ticker searches and calculator uses), a coarse country is attached using the country code Vercel includes in the request. City and region are never captured.
- Authenticated actions (adding or editing holdings) do not include even a country, because the volume is low enough that country + timestamp would narrow identity.
- Raw event rows are deleted after approximately one year. Monthly aggregate summaries are kept permanently. The summaries contain only counts, no individual events.
No third-party analytics script (Google Analytics, Mixpanel, etc.) is loaded on any page.
Third parties that touch your data
- Supabase — database and authentication. Your portfolio data and email address are stored in Supabase's managed Postgres service, hosted on AWS in us-east-1 (US East, N. Virginia). Supabase's own privacy policy governs how they handle infrastructure-level data.
- Vercel — application hosting and serverless functions. Request logs are handled according to Vercel's data processing terms. The app does not instruct Vercel to retain logs beyond their defaults.
- Polygon.io / Massive — market data provider. The app sends ticker symbols to fetch price and dividend data. No personal information — not your email, not your holdings, not any account detail — is sent to this provider.
- Upstash — rate limiting on the public ticker API. Upstash receives IP addresses to enforce per-IP request limits. The app does not store those IP addresses itself; Upstash's own retention applies.
- Resend — transactional email delivery. Your email address is sent to Resend to deliver password reset and, when signup opens, account confirmation emails. No other personal data is sent. Resend's privacy policy governs how they handle email metadata.
No advertising networks, data brokers, or social media pixels receive any data from this app.
Data location and retention
All primary data is stored in the United States (Supabase on AWS us-east-1). Vercel may serve responses from edge locations globally, but the data at rest is US-based.
Data is retained for as long as your account exists. There is no automatic expiry for portfolio or dividend history. Raw analytics events are purged after approximately one year; aggregates are kept indefinitely but contain no personal information.
Deleting your account
Account deletion is not yet self-serve in the app. To request deletion, contact the operator at privacy@stackingyields.com.
There is a current technical limitation worth being explicit about: the app prevents deleting an account that has dividend payment history, because that history is the income ledger and removing the account would break income-by-account calculations. This means a full account deletion — one that removes all records — requires a manual step by the operator. This will be resolved with a proper data export and deletion path before public signup opens.
Note for the operator: If this app is ever subject to GDPR or CCPA, a technical path to full data deletion — including payment history, analytics events, and all derived snapshots — is required, not optional. This is a known gap that needs a lawyer's input on what "deletion" must cover when historical income records are involved, and an engineering path to carry it out.
If the project shuts down
If Stacking Yields shuts down, reasonable advance notice will be provided and a data export (your holdings and dividend history as CSV) will be made available before the service ends. No specific timeframe is guaranteed, and this is a good-faith commitment, not a legal one.
Changes to this policy
This policy will be updated when the app materially changes how data is collected or used. The last-updated date at the top reflects the most recent revision. Continued use after an update constitutes acceptance of the revised policy. For significant changes, registered users will be notified by email where that is practical.
Contact
Questions about this policy: privacy@stackingyields.com