Data Deletion & Retention
Effective August 9, 2026
Delete your account yourself
In the app: Settings → Profile → Delete account. You'll confirm with your password and by typing DELETE. The deletion is immediate, self-serve, and does not require contacting anyone. If you'd rather not log in, email [email protected] from your account email and we'll do it within 7 days.
What deletion removes
Everything tied to you, permanently and in one action:
- Your profile (email, name, birthdate, location) and login credentials
- All linked-account data: accounts, holdings, balances, transaction history
- Aggregator access tokens — and we ask Plaid to revoke the connection upstream, so the institution link itself dies, not just our copy
- Your encrypted AI provider keys
- Research reports, advisor conversations, plans, goals, and portfolio history
- Your Community profile, published portfolio, likes, and comments
This is a hard delete of database rows, not a “deactivation.” It cannot be undone, by you or by us.
Retention while your account is active
- Your financial data — kept for as long as you keep your account, because history is the product (returns, dividends, and performance need it).
- Disconnecting one institution — removes that institution's access token immediately; its synced accounts and history are removed from your portfolio.
- Market data (prices, dividend records, fund compositions) is global reference data about securities, not about you — it contains no personal information and persists independently.
- Server logs — operational logs (timestamps, request paths, error traces) rotate out within 30 days and never include balances or holdings.
Backups
Encrypted database backups exist for disaster recovery and roll off on a fixed schedule; deleted data ages out of all backups within 30 days. Backups are never used to restore an account you deleted.
Third parties
Deleting your Stockveil account removes our copies and revokes our access. Records the aggregators keep as regulated processors are governed by their own policies — see the Plaid End User Privacy Policy (you can also manage Plaid connections directly at my.plaid.com). Your AI provider's handling of requests made with your own key is governed by that provider's terms.
The broader picture of what we collect and why lives in the Privacy Policy.