Privacy Policy
How we collect, use, and protect your financial data.
1. Introduction
Omnicogi, a product of Iteruti Ltd ("we," "us," or "our"), respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard your information when you visit our website or use our application.
2. Information We Collect
We collect and process the following types of information:
- Account Information: When you register for an account, we collect your email address and any other information you provide during the registration process.
- Financial & Asset Data: We collect financial data that you voluntarily upload to the Service, including your transaction history (buys, sells, dividends, interest) and point-in-time account snapshots. This data is provided via CSV file exports or manual entry: we do not collect it automatically. While Omnicogi is in closed beta, uploaded files are retained for up to 90 days as part of our beta diagnostics program so we can investigate and fix imports that go wrong (see Data Security below).
- Usage Data: We may collect information about how you access and use the Service, including your IP address, browser type, and device information.
- Push Notification Data: If you enable notifications, we collect a device push token and your notification preferences so we can deliver alerts to your device.
- Diagnostic Data: We automatically collect crash reports, error logs, and performance traces to help us maintain and improve the Service's reliability. Personal information is scrubbed from this data before it reaches our diagnostic providers; only an anonymous account identifier is retained.
3. How We Use Your Information
We use the information we collect for various purposes, including:
- To provide, maintain, and improve our Service.
- To generate and display your asset performance metrics and net worth analysis.
- To communicate with you about your account and Service updates.
- To monitor and analyse trends and usage to enhance user experience.
- To diagnose failed or incorrect CSV imports and improve how accurately we read each broker's export format.
- To comply with legal and regulatory requirements.
4. Data Security
We implement appropriate technical and organisational measures to protect your personal information from unauthorised access, disclosure, alteration, and destruction. Specifically:
- Encryption in the cloud: All data stored on our servers is encrypted using AES-256 encryption via Google Cloud (Firebase) infrastructure.
- Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS (Transport Layer Security), preventing interception during transfer.
- No broker account access: Because we do not connect to your brokerage accounts, there is no risk of credentials or live account data being compromised through Omnicogi.
- Minimal data collection: We only store what is necessary to provide the Service. Uploaded CSV files are retained for up to 90 days and are then deleted automatically; if you delete your account any retained CSVs are permanently removed straight away. The resulting transaction and portfolio data is retained as part of your account.
- Reviewing imports during the beta: We keep uploaded files for up to 90 days for two reasons: so an import can be re-processed if it needs correcting, and so we can open and replay it to work out why it failed and improve support for your broker’s export format. This is done under our legitimate interest in making the Service work correctly and is limited strictly to diagnosing imports; we do not use your files for any other purpose and never share them. Participation in import diagnostics is a mandatory condition of the closed beta test to allow us to resolve broker formatting issues and improve reliability. If you delete your account, any retained files are deleted immediately.
While we take reasonable steps to safeguard your data, no system is completely secure. We encourage you to use a strong, unique password for your Omnicogi account.
5. Third-Party Services
We use the following third-party services to support our operations. Each provider processes data according to our instructions and in compliance with their own privacy policies:
- Firebase (Google Cloud): hosting, authentication, database (Cloud Firestore), file storage, cloud functions, remote configuration, product analytics (Firebase Analytics), crash reporting (Crashlytics), performance monitoring (Firebase Performance), and push notification delivery (Firebase Cloud Messaging).
- Sentry: cross-platform crash and error reporting plus performance tracing across our web app and our in-development iOS and Android apps. Personal information is scrubbed before it reaches Sentry, and only an anonymous account identifier (not your name or email) is attached to reports. This diagnostic reporting is on by default under our legitimate interest in keeping the Service reliable.
6. Your Rights
Under the UK General Data Protection Regulation (UK GDPR), you have rights regarding your personal data, including the right to access, correct, delete, or restrict the processing of your information. To exercise these rights, please contact us.
You can export your complete data at any time via Export data (JSON) under Profile in the app, or request complete account deletion which immediately purges all portfolio and diagnostic files.
7. Changes to This Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date.
8. Contact Us
If you have any questions about this Privacy Policy, please contact us at help@omnicogi.com.