Privacy Policy
Last updated: 5 September 2026
Colafish is a personal, non-commercial portfolio-tracking project operated by Roberto Passini (the "operator"). This page explains what data the site handles, why, and how to get it removed. The short version: we collect the minimum needed to run the service, we run no advertising or third-party tracking, and we never sell or share your data.
What we collect, and why
Account data. If you create an account we store your email address, when the account was created, and when you last signed in. We store only a bcrypt hash of your password — never the password itself.
Your portfolio. The transactions, holdings, and cash balances you enter or import are stored in your account so they follow you between devices. We also keep a short history of recent versions of your portfolio so you can restore a previous state. This data exists solely to show your own dashboard back to you — it is never used for anything else.
Usage events. For signed-in users we record which features are used (an event name and a timestamp, e.g. that an import ran) so we know what to improve. These events contain no portfolio contents.
Anonymous page views. We count visits without identifying visitors: no IP address and no browser details are stored, and no cookie or identifier is set. Each page load is recorded as a one-way hash salted with a secret and the current date, so the same visitor becomes unlinkable from one day to the next. We keep only the page path and the referring site.
Support requests. If you use "Report a problem" we store your message, the category you picked, and a reply address (your account email, or whatever a guest chooses to type). When you leave "attach diagnostics" ticked we also store: the screen you were on, the last error message shown, your browser family and window size, how many holdings and trades the portfolio has (counts only), and for import problems the file extension, delimiter, row count and column names of the last file you tried. Never the file, the rows, amounts, or your IP address. Reports are kept until resolved and deleted with the account; the operator receives an alert with the message so it can be answered.
Guest mode. If you use "Just let me in" without an account, your portfolio never reaches our server — it lives entirely in your browser's local storage. Clearing your browsing data erases it.
Server logs. Like almost every website, our web server keeps technical access logs (IP address, requested URL, time, and browser signature) to keep the service secure and to diagnose problems. They are rotated automatically and kept for at most 30 days, are never combined with the anonymous visit counting above, and are not used to identify visitors.
Cookies
Colafish sets at most two cookies, both strictly necessary for the service to work — which is why no cookie consent banner is shown. colafish_session keeps you signed in for up to 30 days. colafish_guest is set only if you continue without an account; it contains no identifier (just a flag) and its only job is to take returning guests straight to the app instead of the welcome page. There are no analytics, advertising, or third-party cookies.
Third parties
- Google Fonts — pages load two typefaces from Google's font servers, which means your browser makes a request to Google when the page loads.
- Market data — prices, fund compositions, and exchange rates come from Yahoo Finance, JustETF, and the ECB (via Frankfurter). These lookups are made by our server, so those services see which instruments were requested but never who you are or what you hold.
No user data is ever sent to advertisers, data brokers, or analytics companies.
Where your data lives
The service runs on a virtual server hosted with Oracle Cloud Infrastructure. Data is transmitted over HTTPS, passwords are stored only as bcrypt hashes, and session tokens are stored only in hashed form.
Legal basis
For users in the EU/EEA and Switzerland: account and portfolio data are processed to provide the service you signed up for (performance of a contract); usage events and the anonymous visit counting rely on our legitimate interest in running and improving a small service in the least invasive way we could design.
Retention and deletion
Your data is kept for as long as your account exists. To have your account and everything in it permanently deleted, email support@colafish.app from the address you signed up with — deletion covers your account, portfolio, its revision history, sessions, and usage events, normally within 30 days.
Your rights
Under the GDPR and the Swiss Federal Act on Data Protection you can request access to the data we hold about you, have it corrected or deleted, receive a copy of it, or object to processing. Write to the address above; there is no charge.
Changes
If this policy changes in a way that matters, the date at the top changes and material changes will be noted on this page. Continued use after a change means the updated policy applies.
Contact
Roberto Passini · support@colafish.app