達人のように投資する
情報および調査目的のみ。投資助言ではありません。

プライバシーポリシー

2026-07-25

本書は簡体字中国語版が正文であり、英語版は参照用です。

This Privacy Policy explains how Masterfolio ("we", operated by 【entity name TBD】) collects, uses, shares and protects your information, and the rights you have over it. It applies to masterfolio.app and the emails we send. By using the service you agree to this policy.

Effective date: 2026-07-25. Material changes will be announced in advance.

1. Information we collect

Account identifiers: your email address; with Google sign-in, also the name and avatar Google provides.

Content you save: favorited strategy cards and saved portfolios — references to public cards and display parameters, impersonal by nature.

Transaction data: your subscription tier, status and billing references. Payments are processed by Stripe; your card number and full payment credentials go directly to Stripe and are never received or stored by us.

Usage data: pages viewed, clicks, device and browser type, approximate region inferred from IP (product analytics via PostHog); and server security logs (IP address, user agent, access time) for abuse prevention and troubleshooting.

Communications: emails you send to [email protected] and our replies.

2. What we do NOT collect (by design)

We do not ask for or collect your actual holdings, account balances, income, net worth or any personal financial circumstances — the product has no feature that needs them. A portfolio you save is a combination of references to public strategy cards, not your real positions.

We serve no third-party advertising, integrate no ad-tech partners, perform no device fingerprinting, no cross-site behavioral tracking, and buy nothing about you from data brokers.

3. How we use information (and legal bases)

To perform our contract with you: creating and maintaining your account, delivering content, processing subscriptions and billing, sending service emails (sign-in links, billing notices).

For our legitimate interests: keeping the service secure, preventing abuse and fraud, and aggregate product analytics and improvement (using de-identified or aggregated data wherever possible).

With your consent (where consent is required): sending the content emails you can unsubscribe from — each carries a one-click unsubscribe link, and every line can be managed on the account page.

To comply with legal obligations: tax and accounting records, and responding to lawful requests.

We make no automated decisions with legal or similarly significant effects, and build no behavioral-targeting profiles.

4. Who we share with

Infrastructure processors (only as needed to provide the service, each bound by data-processing terms): Supabase (accounts and database, US), Stripe (payments, US), Resend (email delivery, US), Cloudflare (content delivery and storage, US/global edge), PostHog (product analytics, US).

Legal compliance: we may disclose information where necessary to comply with law, regulation, legal process or enforceable governmental requests, or to protect the rights, property or safety of Masterfolio, our users or the public.

Corporate transactions: in a merger, acquisition or asset sale your information may transfer as part of the assets; we will give advance notice, and this policy continues to bind the recipient.

Beyond the above, we disclose your personal information to no third party. We do not sell personal information, and we do not "share" it for cross-context behavioral advertising (as defined by California law).

5. Cookies and similar technologies

Essential cookies: sign-in session and security (the service cannot work without them).

Preference and analytics cookies: remembering basic preferences; understanding how features are used (PostHog).

We use no third-party advertising cookies. You can manage or clear cookies in your browser; disabling essential cookies prevents sign-in. Because we do no cross-site tracking, browser "Do Not Track" signals have nothing here to opt out of.

6. How long we keep information

Account data and saved content: for the life of your account; deleted when the account is deleted.

Billing and transaction records: for the periods required by tax and accounting law (typically up to 7 years).

Server security logs: generally no more than 90 days.

Analytics: retained in aggregated or de-identified form.

7. Your rights

All users: access, correct, export (portable copy) and delete your personal information; unsubscribe from any email at any time (account-page switches or the one-click link in each email).

EEA/UK users (GDPR/UK GDPR): additionally, restriction of processing, objection to processing based on legitimate interests, withdrawal of consent (without affecting prior processing), and the right to lodge a complaint with your supervisory authority.

California users (CCPA/CPRA): the rights to know, delete, correct, and non-discrimination. We do not sell or share your personal information, so no opt-out is needed. You may use an authorized agent with written authorization.

To exercise any right, email [email protected]. We verify identity first (e.g., via your registered email) and respond within the timeframes applicable law requires.

8. Where data is stored and international transfers

Our infrastructure providers operate servers globally: the primary databases are currently hosted in the United States (by the processors listed above), and content is delivered through global edge nodes. Our operating team is located in China and may access data from China to the extent necessary to provide the service.

Your information may therefore be stored or processed in the United States, China, and other locations where our infrastructure operates. Wherever you are, using the service means you consent to these transfers; for transfers from the EEA/UK we rely on applicable lawful transfer mechanisms (such as Standard Contractual Clauses; exact mechanism 【to be confirmed with counsel】).

9. Security and incident notice

We protect your information with industry-standard measures: encrypted transport throughout (HTTPS/TLS), database row-level access isolation, least-privilege key management, and a zero-touch architecture for payment data.

No internet service can guarantee absolute security. If a security incident affects your personal information, we will notify you and the relevant regulators as required by applicable law, without undue delay.

10. Minors

The service is intended for users 18 and older. We do not knowingly collect personal information from minors; if you believe we have, contact us and we will delete it promptly.

11. Third-party links

The service may link to third-party sites (such as SEC.gov). Their privacy practices are not covered by this policy — please review theirs.

12. Changes and contact

We will give notice on-site or by email before material changes take effect; continued use constitutes acceptance. The latest revision date always appears at the top.

General questions: [email protected]; privacy and rights requests: [email protected].

戻る
ホームプロツールマイライブラリアカウント