Privacy Policy
Last updated 22 July 2026.
The short version
We run no analytics, no tracking pixels and no advertising networks on this site. The public tools work without an account and without a login cookie. If you create a Pulse account, your portfolio data is yours — we don’t sell it, share it for marketing, or mine it.
1. Who is responsible
Niller OÜ, a company registered in Estonia under registry code 14949251, VAT number EE102274200, at Laane tee 13, Haaslava küla, Kastre vald, 62107 Tartu maakond, is the controller for the personal data described here. For any privacy question or request, write to hello@investingpaths.com.
2. What we collect
Using the public tools (no account)
You can run the backtester and calculators without identifying yourself. Our server temporarily records the IP address of tool requests solely to enforce a daily usage limit and prevent abuse. That counter is short-lived, is not linked to a person, and is not used for anything else.
Creating a Pulse account
- Account details — your email address, an optional display name, and a password stored only as a bcrypt hash (we cannot read your password).
- Portfolio data you provide — the transactions, holdings, accounts, valuations, goals and settings you enter or import, including the contents of broker statements you upload.
- Bank connection (optional) — if you connect a bank account for automatic import, we store the access credential encrypted at rest and use it only to fetch your transactions. You can disconnect at any time, which deletes it.
- Subscription status — which plan you are on and when it renews. Card details are handled by our payment provider and never reach our servers.
- Server logs — standard technical logs (IP, time, request path, error traces) kept for security and debugging.
3. Cookies
We use one cookie: a signed session cookie set when you log in to Pulse, which keeps you logged in. It is strictly necessary for the service to function, so it does not require consent. There are no analytics, advertising or cross-site tracking cookies, and the public portal sets no cookie at all until you log in.
4. Why we may use it, and on what basis
- To provide the service (account, tracking, calculations, imports) — performance of our contract with you.
- To take payment and meet accounting/tax obligations — contract and legal obligation.
- To keep the service secure and prevent abuse (rate-limit counters, logs) — our legitimate interest in a working, un-abused service.
- To send service messages you have asked for, such as strategy alerts — contract; you can turn them off.
We do not use your data for automated decisions with legal effects, and we do not profile you for advertising.
5. Who else processes it
We keep the list short on purpose. Each of these acts on our instructions under a data-processing agreement:
- Our hosting provider — runs the servers and database (data stored in the EU).
- Our payment provider — acts as merchant of record; receives your billing details directly and handles invoicing and VAT.
- Your bank — only if you choose to connect one, and only to read the transactions you asked us to import.
Market data providers receive only the ticker being looked up — never your identity, holdings or portfolio. We do not sell personal data or share it with advertisers.
6. Where it is stored
On servers in the European Union. If a processor ever needs to move data outside the EEA, we rely on an adequacy decision or Standard Contractual Clauses.
7. How long we keep it
- Account and portfolio data— while your account exists. Delete your account and we erase it, or irreversibly anonymise it where erasure isn’t possible.
- Abuse-prevention counters — cleared daily.
- Server logs — a short rolling window.
- Invoices and payment records — as long as accounting and tax law requires (typically seven years). This is a legal obligation and survives account deletion.
8. Your rights
Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or export it in a portable format. You can also withdraw consent where we relied on it, without affecting what came before.
Email hello@investingpaths.com and we will respond within one month. If you think we have handled your data wrongly you can complain to your national data-protection authority — in Estonia, the Data Protection Inspectorate (Andmekaitse Inspektsioon).
9. Security
Traffic is encrypted in transit (HTTPS). Passwords are stored only as bcrypt hashes and bank credentials are encrypted at rest. The application backend is not exposed to the public internet directly, and access to production is limited. No system is perfectly secure; if a breach ever affects your data we will notify you and the regulator as the law requires.
10. Children
The Service is not intended for children, and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.
11. Changes
If this policy changes materially we will tell account holders by email or in the app before it takes effect. The date at the top always shows the current version. See also our Terms of Service.