PRIVACY · UPDATED JULY 23, 2026
Privacy
A plain-language summary of what qyu collects, why it is used, and the financial safety boundary around portfolio data.
Information collected
Depending on how you use qyu, the current product can process:
- Name, date of birth, country, email address, optional phone number, and password-derived authentication data for account access.
- Uploaded broker CSV text, holdings screenshots, manually entered holdings, portfolio names, positions, and market selections.
- When you use CAS import, the PDF content and optional document password are processed transiently to prepare a holdings review. The application stores neither; only the positions you confirm are added to your portfolio.
- When you use screenshot import, up to four selected images are processed transiently to prepare a holdings review. qyu does not store the image files; only the positions you confirm are added to your portfolio.
- Watchlist requests, monitored companies, and notification state.
- Public Atlas searches and ordinary technical logs needed to run, secure, and debug the service.
How it is used
qyu uses this information to authenticate you, resolve holdings against market coverage, generate cited briefs, compute portfolio analytics, maintain watchlists, prevent abuse, and operate the service.
The current build does not implement advertising tracking or sale of personal data.
Security and retention
qyu does not ask for, hold, or store an account password. Sign-in is passwordless — either through Google or through a one-time code sent to your email — and your session is carried by a signed token that expires.
A CAS PDF and its optional document-opening password are used only for the import request. PAN, folio, bank details, PDF bytes, extracted statement text, and the password are not written to the portfolio store.
Screenshot files are checked for safe size and format, stripped of image metadata, and used only to produce the review. The original and processed image bytes are not written to the portfolio store.
Portfolios, positions, watchlists, saved searches, and workspace items can be deleted where the product exposes those flows. Account-level deletion and privacy requests can be sent to hello@qyu.finance.
Who else processes your data
qyu relies on a small number of third parties to operate. They process data on our behalf and only for the purposes below.
Clerk provides authentication. It handles sign-in and holds your email address and the identifiers for any connected sign-in provider, such as Google.
Vercel hosts the site and provides privacy-preserving usage analytics. Analytics tell us which pages are visited; they are not used to build an advertising profile of you.
OpenAI provides model processing for supported holdings descriptions and screenshot imports. It receives the selected content only to prepare the review draft; qyu disables response storage for screenshot requests.
Market, filing and news data is retrieved from public sources. We do not sell your data, and we do not share your holdings with any third party for their own purposes.
Sensitive data
qyu does not request trading access and cannot move money.
Outside the designated CAS import, do not upload trading credentials, government identifiers, payment-card data, private keys, one-time passwords, or files unrelated to understanding your holdings.
A CAS may contain PAN, folio and bank details. The CAS parser is designed not to return or store those fields; review the extracted holdings before saving.
Before uploading a screenshot, crop out your name, account or folio numbers, email address, phone number, balances unrelated to the holding rows, and other personal details.