Last Updated: December 15, 2025
Overview
This Privacy Policy describes how Chinook ("we," "us," or "our") collects, uses,
and protects your personal information when you use our portfolio management application.
Information We Collect
We collect the following types of information:
- Account Information: Name, email address, and password (encrypted)
- Portfolio Data: Investment plans, funds, transactions, and metrics you enter
- Usage Data: Login times, IP addresses, and browser information for security purposes
- Session Data: Authentication tokens and preferences stored in secure cookies
How We Use Your Information
We use your information to:
- Provide and maintain the portfolio management service
- Authenticate your identity and manage your account
- Generate reports and analytics for your portfolio
- Detect and prevent security threats and unauthorized access
- Communicate important updates about the service
Data Security
We implement industry-standard security measures to protect your data:
- Passwords are hashed using Argon2id encryption
- All data is stored in encrypted SQLite databases
- Sessions use secure, HTTP-only cookies
- Geographic access controls to prevent unauthorized access
- Rate limiting to prevent brute force attacks
- Content Security Policy (CSP) headers to prevent XSS attacks
Data Sharing
We do not sell, rent, or share your personal information with third parties except:
- When required by law or legal process
- To protect our rights, property, or safety
- With your explicit consent
Your Rights
You have the right to:
- Access your personal data stored in our system
- Request correction of inaccurate information
- Request deletion of your account and associated data
- Export your portfolio data in CSV format
- Object to processing of your personal information
Data Retention
We retain your data for as long as your account is active. Upon account deletion,
all personal data and portfolio information is permanently removed from our systems,
except where required by law to maintain certain records.
Cookies
We use essential cookies to maintain your authenticated session. These cookies are
required for the application to function and cannot be disabled. We do not use
tracking or advertising cookies.
Changes to This Policy
We may update this Privacy Policy from time to time. Significant changes will be
communicated via email or a notice on the login page.
Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights,
please contact your system administrator.