Privacy Policy
attribook is built on one principle: your wealth data belongs to you, not to us. This page explains exactly what we collect, what we never collect, and what you can always do with your data.
COLLECTION
What we collect
- Account email address: only when you sign up. Required for login; never shared with third parties for marketing.
- Financial snapshots (cloud sync, opt-in): your asset values, balance entries, and derived metrics stay in local storage on your device by default. They are uploaded to our servers only if you turn on Cloud sync in Settings, which is off until you switch it on. You can turn it back off at any time. Two things leave your device without cloud sync: the names of the companies you hold, and a reminder date if you ask for one. Both are described below.
- A reminder date (only if you ask for it): when you finish setting up, you can tick a box asking us to write to you when your next check-in is due. If you do, we store one date against your account and nothing else: no amounts, no balances, no asset or company names, no thesis text, and no count of what you hold. The box is never ticked for you, and the reminder email carries no figures for the same reason there is nothing to put in it. Unticking the box or using the unsubscribe link in the email deletes the stored date rather than just stopping the send.
- Names of companies you hold (news searches, on by default): so that your check-in can follow the companies you actually own rather than the market in general, attribook sends the company names and the markets they trade in, stored against a one-way hash. Never how much you hold, never what you wrote about them, never any link back to you. This is on for new accounts, and Search news for my holdings in Settings → Data turns it off in one click and deletes the names already sent. Amounts and balances are not part of this and are still governed by the cloud-sync toggle above.
- Anonymous product analytics. attribook uses Umami, a privacy-friendly, cookieless analytics tool, to understand which pages and features are used. We record page views (referrer, browser, country) plus a small set of named events when you take an action: saving a snapshot, dismissing a guidance card, or changing your reporting currency. The events carry only categorical and bucketed metadata: event name, tier or type, bucketed counts (e.g. 4-7 assets), mode (local or cloud), and tenure band. They never include your balances, asset names, goal target amounts, email, or any field that could reconstruct your wealth. Trial sessions are deliberately quiet: instead of recording every page view, we record one event per unique page you visit during the trial (so revisiting the same page does not fire again) plus the key milestones in the trial flow. No cookies are set and no cross-site tracking occurs.
- Anonymised benchmark metrics (telemetry, opt-in): only if you enable Contribute to benchmarks in Settings, attribook sends derived numbers (savings rate, health score, outflow rate) tagged with anonymised cohort bands (age range, income range, country). This toggle is off until you switch it on. Your identity is replaced with a one-way cryptographic hash we cannot reverse to find you.
NEVER COLLECTED
What we never collect
- Transaction data or receipts: attribook tracks snapshots of totals, not individual transactions. We never ask for receipts, line items, or purchase history.
- Bank credentials or API tokens: attribook has no bank API integration. No passwords, no OAuth tokens, no read access to your accounts.
- Identifying fields in telemetry: when telemetry is enabled, your user ID, email, and dataset ID are stripped before any row is written. Only the cryptographic hash and cohort bands travel over the network.
- Sold or shared personal data: we do not sell, rent, or share your personal financial information with advertisers or data brokers, and we never have. Nothing attribook collects, including the company names used for news searches, is passed to anyone outside the product.
- How much of anything you hold: the news-search feature sends company names and nothing else. Quantities, balances, prices and account values are never part of it, and there is no way to tell from a stored name whether it is a whole portfolio or a single share.
YOUR RIGHTS
What you can do
- Export your data at any time: Settings → Data → Download data file produces a portable JSON file containing everything attribook knows about your wealth. Take it to any device or any compatible tool.
- Disconnect cloud sync: turning off Cloud sync in Settings stops all raw balance data from syncing to our servers. Your local IndexedDB copy is unaffected.
- Opt out of benchmark contributions: the Contribute to benchmarks toggle in Settings → Data stops new telemetry rows from being written immediately. Existing rows are retained as they are already anonymised and untraceable.
- Stop sharing the names of companies you hold: the Search news for my holdings toggle in Settings → Data stops it and, unlike the benchmark toggle above, deletes the names already sent. They are removed rather than retained because a company name is only useful while somebody holds it.
- Request account deletion: contact us via /support to request full deletion of your account and any server-side data. We will process the request within 30 days.
CONTACT
Questions about your data
If you have any questions about how attribook handles your data, or to submit a data access or deletion request, please reach out via our support page.
Last updated: August 2026