Privacy Policy
Last updated 6 August 2026.
The short version
We count visits so we know which pages are worth writing, using our own software on our own servers. There are no third-party analytics, no tracking pixels and no advertising networks, and counting you stores nothing on your device, the one thing we may store is a flag saying you asked us not to. The public tools work without an account and without a login cookie. If you create a Pulse account, your portfolio data is yours. We don’t sell it, share it for marketing, or mine it.
1. Who is responsible
Niller OÜ, a company registered in Estonia under registry code 14949251, is the controller for the personal data described here. For any privacy question or request, write to hello@investingpaths.com. Our full company details, including the registered address, are in the Terms of Service.
2. What we collect
Using the public tools (no account)
You can run the backtester and calculators without identifying yourself. Our server temporarily records the IP address of tool requests solely to enforce a daily usage limit and prevent abuse. That counter is short-lived, is not linked to a person, and is not used for anything else.
Creating a Pulse account
- Account details, your email address, an optional display name, and a password stored only as a bcrypt hash (we cannot read your password).
- Portfolio data you provide, the transactions, holdings, accounts, valuations, goals and settings you enter or import, including the contents of broker statements you upload.
- Bank connection (optional), if you connect a bank account for automatic import, we store the access credential encrypted at rest and use it only to fetch your transactions. You can disconnect at any time, which deletes it.
- Subscription status, which plan you are on and when it renews. Card details are handled by our payment provider and never reach our servers.
- Server logs: standard technical logs (IP, time, request path, error traces) kept for security and debugging.
3. Cookies and what we count
We use one cookie: a signed session cookie set when you log in to Pulse, which keeps you logged in. It is strictly necessary for the service to function, so it does not require consent. There are no analytics, advertising or cross-site tracking cookies, and the public portal sets no cookie at all until you log in.
We do count page visits, on our own servers and into our own database. No third party is involved and nothing is written to your browser in order to count you, no cookie, no local storage, no tracking pixel. (The one thing we may store is the opposite: a flag saying you have opted out. See below.) To tell one visit from another we take your IP address and browser type, combine them with a secret that changes every day, and store only the irreversible result. We never store the IP address itself, and because the secret changes daily we cannot link what you read today to what you read yesterday. We record the page path. We do not keep the rest of the web address, except for the campaign tags described below.
Two things we work out from that same request and keep instead of it: the country your address belongs to (the country only (never a city or an address, and only if we have set that feature up at all) and whether you are on a phone, tablet or computer. Both are worked out once, as you arrive, and stored as the answer. We do not keep the address or the browser string they came from.
If you reach us through a link someone tagged (a newsletter, a post, an ad), that tag travels in the web address, and we keep it so we know which of those is worth doing again. While that visit lasts, your browser remembers the tag so that it is still attached if you go on to create an account. It is stored for the tab only and disappears when you close it, it is a label like “newsletter”, and it identifies nobody.
We honour your browser’s “Do Not Track” setting: turn it on and we count nothing at all. You can also switch it off here, without an account, all that puts on your device is one flag remembering you said no. Because that flag lives in the browser, it applies to this browser on this site: our app at pulse.investingpaths.com keeps its own, under Settings → Usage analytics.
You are being counted. We record the page path and nothing else. Switch it off and this browser sends nothing at all.
4. Why we may use it, and on what basis
- To provide the service (account, tracking, calculations, imports), performance of our contract with you.
- To take payment and meet accounting/tax obligations , contract and legal obligation.
- To keep the service secure and prevent abuse (rate-limit counters, logs), our legitimate interest in a working, un-abused service.
- To send service messages you have asked for, such as strategy alerts, contract; you can turn them off.
We do not use your data for automated decisions with legal effects, and we do not profile you for advertising.
5. Who else processes it
We keep the list short on purpose. Each of these acts on our instructions under a data-processing agreement:
- Our hosting provider, runs the servers and database (data stored in the EU).
- Our payment provider, acts as merchant of record; receives your billing details directly and handles invoicing and VAT.
- Your bank, only if you choose to connect one, and only to read the transactions you asked us to import.
Market data providers receive only the ticker being looked up, never your identity, holdings or portfolio. We do not sell personal data or share it with advertisers.
6. Where it is stored
On servers in the European Union. If a processor ever needs to move data outside the EEA, we rely on an adequacy decision or Standard Contractual Clauses.
7. How long we keep it
- Account and portfolio data, while your account exists. Delete your account and we erase it, or irreversibly anonymise it where erasure isn’t possible.
- Abuse-prevention counters: cleared daily.
- Server logs, a short rolling window.
- Invoices and payment records, as long as accounting and tax law requires (typically seven years). This is a legal obligation and survives account deletion.
8. Your rights
Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or export it in a portable format. You can also withdraw consent where we relied on it, without affecting what came before.
Email hello@investingpaths.com and we will respond within one month. If you think we have handled your data wrongly you can complain to your national data-protection authority, in Estonia, the Data Protection Inspectorate (Andmekaitse Inspektsioon).
9. Security
Traffic is encrypted in transit (HTTPS). Passwords are stored only as bcrypt hashes and bank credentials are encrypted at rest. The application backend is not exposed to the public internet directly, and access to production is limited. No system is perfectly secure; if a breach ever affects your data we will notify you and the regulator as the law requires.
10. Children
The Service is not intended for children, and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.
11. Changes
If this policy changes materially we will tell account holders by email or in the app before it takes effect. The date at the top always shows the current version. See also our Terms of Service.