Privacy Policy
1. Introduction
Salt Scale Capital ("we," "our," or "us") operates the Personal Portfolio Management System (PPMS), a self-hosted household financial management application. This Privacy Policy explains how we collect, use, store, and protect your personal and financial information when you use PPMS, including features powered by Plaid.
2. Information We Collect
2.1 Information You Provide
- Account credentials: Name, email address, and password (stored as a bcrypt hash โ we never store plaintext passwords).
- Manually entered data: Financial holdings, real estate values, and other portfolio data you enter directly.
2.2 Information Collected via Plaid
When you connect financial accounts through Plaid Link, we receive the following data from your financial institutions via the Plaid API:
- Account information: Account name, type, subtype, and institution name.
- Balance data: Current, available, and credit limit balances.
- Holdings and investment data: Securities, quantities, cost basis, and current values.
- Transaction data: Date, amount, merchant name, and category.
We access only the data categories required for portfolio management. We do not access information beyond what is necessary for the features you use.
2.3 Information from Other Integrations
- Coinbase: Portfolio holdings and transaction data retrieved via authenticated API.
- CSV imports: Data you upload from other financial services.
3. How We Use Your Information
We use your information solely for the following purposes:
- Aggregating and displaying your financial portfolio across accounts and institutions.
- Calculating performance metrics (time-weighted return, internal rate of return).
- Generating analytics, charts, and reports for your household.
- Maintaining daily portfolio snapshots for historical performance tracking.
- Providing tax-related estimates and scenario analysis.
We do not:
- Sell, rent, or share your data with any third parties.
- Use your data for advertising or marketing purposes.
- Use your data for any purpose other than providing the PPMS service to your household.
4. How We Store and Protect Your Information
4.1 Self-Hosted Infrastructure
PPMS is a self-hosted application. All data is stored on infrastructure that you own and control. No data is transmitted to or stored on third-party cloud services (except as required to communicate with Plaid and Coinbase APIs).
4.2 Encryption
- In transit: All network communications use TLS 1.3. Remote access is secured via Tailscale (WireGuard encryption).
- At rest: Full-disk encryption protects all stored data. Sensitive credentials (API tokens, access tokens) are additionally encrypted at the application level using AES-256-GCM.
4.3 Access Controls
- Application access requires multi-factor authentication.
- Database access is restricted to the application container on an internal network.
- No public internet ports are exposed.
5. Data Sharing
5.1 Plaid
When you connect accounts via Plaid Link, your financial institution credentials are transmitted directly to Plaid โ they are never seen or stored by PPMS. Plaid's use of your data is governed by [Plaid's Privacy Policy](https://plaid.com/legal/#end-user-privacy-policy).
5.2 No Other Third-Party Sharing
We do not share your data with any other third parties. PPMS is a closed household application with no external data sharing.
6. Data Retention and Deletion
- Financial data is retained for up to 7 years for tax record-keeping purposes.
- Application logs are retained for 90 days.
- Session tokens expire automatically (24 hours for access tokens, 7 days for refresh tokens).
- You may disconnect any linked account at any time, which revokes the Plaid access token and schedules associated data for deletion.
- You may request full deletion of your data. See our [Data Retention Policy](data-retention-policy.md) for details.
7. Your Rights
You have the right to:
- Access all data we store about you.
- Export your data in a portable format.
- Delete your data (subject to tax-related retention requirements).
- Disconnect any linked financial account at any time.
- Revoke Plaid access to your financial accounts.
To exercise any of these rights, use the account management features in PPMS or contact the system administrator.
8. Children's Privacy
PPMS is not intended for use by individuals under the age of 18. We do not knowingly collect data from minors.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be noted by updating the "Last Updated" date at the top of this document.
10. Contact
For questions about this Privacy Policy or your data, contact the household system administrator.