Marisco
Privacy Policy
Marisco reads your investment statements. That is personal data you would not want loose, so this page says plainly what we collect, why, who else sees it, and how to make us delete it.
Last updated
1. Who we are
Marisco is a portfolio learning tool operated by Manu Martínez Almeida, a sole trader established in Portugal. For the purposes of the EU General Data Protection Regulation (GDPR), Manu Martínez Almeida is thedata controller for the personal data described here.
This policy covers the marketing sitetrymarisco.com and the application atapp.trymarisco.com.
Contact for any privacy matter:privacy@trymarisco.com, or thecontact form if you'd rather not email — both reach the same person. For anything else, including formal or legal notices,legal@trymarisco.com.We have not appointed a Data Protection Officer; we are not required to.
2. What we collect
Account data
Your email address, your display name, and the session cookie that keeps you signed in. If you belong to a shared workspace, we store which workspace and what role you hold in it.
Portfolio data — the part that matters most
When you upload a broker or bank statement, we store:
- the raw rows exactly as the file contained them, so an import can always be audited against the original document;
- a normalised ledger derived from them — trades, dividends, fees, taxes, deposits, withdrawals, interest, FX conversions and transfers, each with its date, instrument, quantity, price and currency;
- the cash balances your broker reported, and the portfolio settings you chose (name, base currency).
If you use a bank or spending account, this ledger also contains everyday transactions and merchants. Treat this section as covering that too.
We also store what you tell us about how you invest — your experience, goals, risk tolerance and thesis, if you complete the portfolio interview — and any reports you or the agent author on your portfolio.
Broker connections
If you connect a brokerage account directly instead of uploading files, the connection is handled by SnapTrade (see §5).
- We never receive, see or store your brokerage login credentials.You enter them with SnapTrade, not with us.
- We store the connection identifiers SnapTrade issues, together with an access secret SnapTrade gives us for your connection. That secret lets us read your account data on your behalf — it is not your brokerage password, it cannot be used to sign in anywhere, and it grants read access only. We hold it in a separate credential store and destroy it when you disconnect.
- For each account you attach to a portfolio we store its name, amasked account number (never the full one), its currency, and whether it is a paper/demo account.
- We receive from SnapTrade the same categories of data a statement contains: account balances, positions and transaction activity. SnapTrade both answers our requests and pushes updates to us when your broker reports a change.
- Access is read-only. Marisco cannot and does not place trades, move money, or change anything at your broker.
- You can disconnect at any time in the app; doing so stops further syncing immediately.
API keys you choose to supply
Marisco works without you supplying anything. If you nonetheless bring your own market-data or broker-connection API key, it is stored in our database against your account and used only to call that provider on your behalf. You can delete it at any time in Settings → Data sources.
Your conversations with the agent
Marisco is designed to be used through an AI assistant. When you ask a question, your message and the relevant portfolio data needed to answer it are sent to our AI model provider (see §5) and the response is stored with your account so the conversation persists.
Usage and diagnostics
Product analytics: pages and features used, actions taken, and errors encountered, along with device, browser, approximate location derived from IP, and referring page. Analytics requests are routed through our own domain rather than directly to the analytics vendor.
The marketing site and the app differ here, on purpose.
- Browsing this marketing site is cookieless and anonymous: nothing is stored on your device, no profile is built, and no identifier for you reaches the analytics provider. Visitor counts are estimated by the provider from a rotating, privacy-preserving hash.
- Submitting a form on it is different, and this is the line. Once you give us your email address — requesting an invitation, or writing to us — we create a record for you at our analytics provider under that address, and attach what you told us on the form: which form, the broker you named, how you describe your investing, whether you agreed to an interview, and the campaign code on the link you arrived through, if it had one. We do this on our servers, not in your browser, so it still stores nothing on your device. It does not reach back: the anonymous browsing you did before submitting is not attached to you, because it was never recorded in a way that could be. You can object under §8.
- Inside the signed-in app analytics arelinked to your account — your email address is used as the identifier so that product usage and server-side events describe one coherent session, and errors can be traced to the account that hit them. You can object to this under §8.
Marketing site submissions
If you request an invitation or write to us throughthe contact form, we store your email address, what you told us (including your message, the broker you named, how you describe your investing, and whether you agreed to be interviewed), and the context of your visit — the page you submitted from, referring page, campaign tags and codes (a link we share can carry a short code naming the campaign it belongs to) and browser language.
3. Why we use it, and on what legal basis
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Run your account and keep you signed in | Account data | Performance of a contract — Art. 6(1)(b) |
| Parse your statements, derive holdings, value them, and answer your questions about them | Portfolio data, agent conversations | Performance of a contract — Art. 6(1)(b) |
| Sync a brokerage account you chose to connect | Broker connection data | Performance of a contract — Art. 6(1)(b), on your explicit authorisation at the broker |
| Send you transactional email (confirmations, notifications) | Account data, marketing submissions | Performance of a contract — Art. 6(1)(b) |
| Understand how the product is used, how people arrive, and fix what breaks | Usage and diagnostics, marketing site submissions | Legitimate interests — Art. 6(1)(f): operating and improving a product people rely on |
| Answer you when you write to us | Marketing site submissions | Legitimate interests — Art. 6(1)(f), and your own request |
| Contact you for a user interview | Email address, interview opt-in | Consent — Art. 6(1)(a), withdrawable at any time |
4. What we do not do
- We do not sell your personal data. There is no version of this where we do.
- We do not share your portfolio data with advertisers or data brokers.
- We do not use your portfolio data to train third-party AI models. Our AI provider processes your data to answer your questions and is contractually barred from training on it.
- We do not execute trades, hold your money, or take custody of your assets.
- We do not make automated decisions producing legal or similarly significant effects about you (GDPR Art. 22).
5. Who we share it with
We use a small number of service providers to run Marisco. Except where the table says otherwise, each is a processor: it handles personal data only on our instructions, under a data processing agreement.
SnapTrade is the exception. For the step where you hand over your brokerage credentials it acts as anindependent controller, not our processor: it decides how it collects and secures those credentials, and it does so under its own terms and privacy policy, which you accept when you connect. For the account data it then returns to us, we are the controller. Read its policy before you connect a broker — that part of the transaction is between you and them.
| Provider | What it does | What it sees |
|---|---|---|
| Netlify | Hosting and content delivery for the site and app | Request metadata, IP addresses |
| Neon | Managed PostgreSQL database | Everything stored: account, portfolio and ledger data |
| Anthropic | AI model that powers the assistant | Your messages and the portfolio data needed to answer them. Not used for model training. |
| SnapTrade (independent controller — see above) | Brokerage account connectivity, if you connect a broker | Your brokerage credentials (which we never see) and the account data it returns to us |
| Financial Modeling Prep | Market data — prices, FX rates, company profiles | Instrument identifiers only (ISINs, tickers). No account identifiers and no personal data. |
| PostHog | Product analytics and error diagnostics | Usage events, device and browser data, IP address. Anonymous while you browse the marketing site; once you submit a form there, or sign in to the app, also your email address and what you told us — see §2. |
| Resend / SendGrid | Transactional email delivery | Your email address and the message content |
We will also disclose data where legally required — a valid court order, regulatory demand, or to establish or defend a legal claim.
If Marisco is ever acquired or merged, personal data may transfer as part of that transaction. You would be told before it happened and before any new controller applied a different policy.
6. International transfers
Some providers above process data outside the European Economic Area, principally in the United States. Those transfers rely on the European Commission's Standard Contractual Clauses, or on an adequacy decision where one applies. You can ask us for details of the safeguards in place for any specific provider.
7. How long we keep it
- Account and portfolio data — for as long as your account exists. Deleting a portfolio deletes its statements, ledger and derived data.
- Your whole account — deleted on request, with its portfolios, statements, ledger, reports and conversations, within 30 days. Backups age out on their own schedule, within 90 days.
- Your conversations with the agent — for as long as your account exists, unless you delete the conversation or the portfolio it belongs to.
- Unrecognised statement uploads — if a file matches no parser we keep it for no more than60 days so we can build support for that format. Once that window passes its contents are erased and only the fact that an import failed remains. The same countdown is shown to you in the app, and you can delete the file yourself at any time without waiting for it.
- Contact and invitation submissions — kept while the invitation list is live, because the list is what early access is drawn from, and reviewed when it closes: anything we no longer need is deleted then. We delete yours sooner on request, at any time, and that is the faster route if you want it gone.
- Usage analytics — no longer than12 months, the retention period we set at our analytics provider.
8. Your rights
Under the GDPR you have the right to:
- Access — get a copy of the personal data we hold about you.
- Rectification — have inaccurate data corrected.
- Erasure — have your data deleted.
- Portability — receive your data in a structured, machine-readable format, or have it sent to another provider.
- Restriction — have processing limited while a dispute is resolved.
- Objection — object to processing based on legitimate interests, including analytics.
- Withdraw consent — where we rely on consent, withdraw it at any time, without affecting processing already carried out.
Write to privacy@trymarisco.com to exercise any of these, or use the contact formwith the "Privacy, data access or deletion" topic. We answer within one month, as the GDPR requires, and we do not charge for it — though the GDPR lets us charge a reasonable fee for, or decline, a request that is manifestly unfounded or excessive, in particular a repetitive one. If a request is complex we may extend that by up to two further months, in which case we will tell you why inside the first month (Art. 12(3)). Where we cannot tell from the request that you are who you say you are, we may ask for something that establishes it — we will not use what you send us for anything else.
You also have the right to lodge a complaint with a data protection supervisory authority — your own local one, or ours, theComissão Nacional de Proteção de Dados (CNPD) inPortugal. Raising the matter with us first is usually faster.
9. Cookies and similar technologies
This marketing site stores nothing on your device. It sets no cookies and writes nothing to local storage — not for analytics, not for anything else, and that holds whether you browse it or submit a form on it. That is why you are not being asked to consent to anything: there is nothing stored to consent to. Visits are counted by our analytics provider from a rotating hash computed on its own servers, which does not identify you and cannot follow you between sites or across days. What happens after you hand over your email address is described in §2 — it is a record on our side, not a tracker on yours.
The signed-in application sets asession cookie, which is strictly necessary to keep you signed in and cannot be turned off without signing you out. It also uses analytics storage tied to your account, as described in §2 — that is part of operating a product you have an account with, and you can object to it under §8.
We do not use advertising or cross-site tracking cookies anywhere.
10. Security
All traffic runs over TLS. Access to your data in the application is scoped to your account and, where applicable, your workspace — a portfolio is readable only by its owner and the people it has been shared with, or by anyone if you deliberately make it public. Access to production infrastructure is limited to the operator.
No system is perfectly secure, and we do not warrant that ours is. Where a personal data breach is likely to result in a risk to your rights, we will notify the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, and will tell you directly in the cases where the GDPR requires that.
Found a vulnerability? Write tolegal@trymarisco.com, or pick the "Security vulnerability" topic on thecontact form, before disclosing it publicly. We will not pursue anyone who reports a genuine issue in good faith.
11. Children
Marisco is not intended for anyone under 18 and we do not knowingly collect their data. If you believe a minor has given us personal data, write to us and we will delete it.
12. Changes to this policy
We update this page when what we do changes. The "last updated" date at the top always reflects the current version. Material changes — a new category of data, a new purpose, a new class of recipient — are announced by email to account holders before they take effect.
Marisco is an educational analysis tool. It is not a financial advisor and does not provide investment advice. See theTerms of Service for what that means in practice.