Serin Privacy Policy

Effective 2026-09-14 · applies to the Serin web app and the Serin mobile app

The short version

Serin is open-source software you can run yourself. When you self-host, we run no servers and collect nothing — your portfolio lives in a database on hardware you control, and you use it through your browser. That is the default and it is free forever. (The mobile app is a Serin Cloud client and does not connect to a self-hosted instance, so self-hosting and the app are never mixed.)

Serin Cloud is different, and this policy says so plainly. If you use the hosted service, we operate the server and your data sits in a database we administer, under an account you sign in to. Serin Cloud is operated by the maintainer of the Serin project. Everything below distinguishes the two.

What Serin Cloud stores, and for how long

Data Kept Notes
Account: email address, password, and any link to Sign in with Apple or Google Until you delete the account the password is stored only as a scrypt hash, never in a form we can read
Portfolio: positions, transactions, accounts, tax lots, briefings, settings Until you delete it, or the account a lapsed subscription pauses paid features; it never deletes your data
Chat conversations 30 days, then deleted your questions, Serin's replies, and the names of the tools it consulted — never the figures those tools returned. At 30 days a message stops being shown and leaves exports at once, and a sweep that runs every few hours deletes it. You can delete a conversation yourself at any time, subscription or not
Smart Import images and files Not stored held in memory while an AI provider reads them, then discarded. Only the rows you review and import are saved
Your AI data-sharing choices Until you withdraw them, or delete the account which feature, which version of the disclosure you saw, and when you agreed
Push notification token (mobile, if you turn notifications on) Until you sign out, turn notifications off or delete the account, or Expo reports the device gone a device belongs to one account at a time; a delivery record keeps it for up to a day after a notification is sent
Brokerage connection (if you connect one on the web) Until you disconnect it, or delete the account SnapTrade's credentials for your connection, encrypted
Records that make signing out stick Until the signed-out session would have expired (at most 30 days) a fingerprint of the session, never the session itself
Deletion follow-ups Until they finish if billing, SnapTrade or Apple can't be reached while you delete your account, we keep only what is needed to finish the job: your Stripe customer id and email address, your SnapTrade user id, or an encrypted Apple sign-in token

Our request logs record the method, path, status and timing of each request — never request bodies — and are kept briefly, to operate the service.

Backups. Data you delete can remain in an encrypted database backup until that backup is deleted. Backups are kept for a limited time and used only to recover from a failure. If we ever restore one, we delete again anything that was deleted after it was taken, before the service comes back.

On your phone

Data Where Notes
Your sign-in token iOS Keychain cleared when you sign out. The Keychain outlives the app, so sign out before you hand a device on
Last portfolio snapshot App storage for offline display. Tied to the session that saved it, and cleared when you sign out or someone else signs in
App lock setting iOS Keychain Face ID or your passcode is checked by iOS itself; Serin never receives biometric data

The app checks Expo's update service for fixes. Those checks carry a random installation identifier that isn't linked to your account, and Expo's own policy covers the basic diagnostics it collects to deliver updates.

Where data goes, and who handles it

On Serin Cloud these go to Anthropic through an AI gateway we operate. The gateway records how many tokens each account used, to meter the plan; it does not store the content of requests, and we do not log them. If a provider fails, the request goes to the next one configured, and the prompt that asks your permission names every provider that could receive it. What each provider keeps, and for how long, is set by its own terms. You can withdraw permission at any time in the app (Settings → AI data sharing); withdrawing it for briefings also turns off your daily briefing.

Self-hosting, requests go from your server to whichever providers you configured (DeepSeek, Anthropic, OpenAI, Google Gemini, xAI, OpenRouter, or a local Ollama model), in the order you set, and never touch us. DeepSeek is operated from China, under its own terms and jurisdiction; if you would rather your holdings were not processed there, don't configure it. - Market data (Yahoo Finance, Financial Modeling Prep, CoinGecko): symbols only — never quantities or values. FX rates (open.er-api.com): currency codes only. - SnapTrade, if you connect a brokerage: read-only holdings sync under SnapTrade's own terms. Serin cannot place trades. - Stripe handles payment. We never see your card details. - Apple and Google, if you sign in with them, tell us who you are. Serin's Sign in with Apple access is revoked when you delete your account. - Expo relays push notifications. A notification says only "Your daily briefing is ready." — no portfolio figures — and passes through Expo's and Apple's delivery services. - Email for account setup and password resets goes through our email delivery provider. - Hosting. Serin Cloud runs on Fly.io, with its database on Supabase-managed PostgreSQL.

Connecting your own AI assistant (MCP)

Serin can be read by an AI assistant you already use — Claude Desktop, Claude Code, or anything that speaks the Model Context Protocol. This is the one place data leaves on your instruction rather than Serin's, so it is worth being exact about.

You create an agent token, you paste it into a client you chose, and that client can then read your portfolio: holdings, returns, realised gains, transactions, price history. Whatever that client sends to its AI provider is between you and them — we are not in that path and cannot see it, and its provider's policy governs it, not ours.

Agent tokens are read-only. They cannot change a position, download a backup, or create another token, and they reach only the /api/agent endpoints. Revoke one at any time under Connectors → Agent access; revoking is immediate and does not sign you out anywhere else.

Serin does not store your conversations with an assistant connected this way — they happen inside your client, not inside Serin.

Chat inside Serin is different, and is stored, as described above: kept 30 days, deletable at any time, included in your export, and deleted with your account. We treat a transcript as at least as private as the portfolio itself — it records what you asked, not only what you hold — so the same rule applies: our staff do not read it.

What we (the Serin project) receive

Self-host: nothing. No telemetry, no analytics, no crash reporting, no accounts.

Serin Cloud: what the table above lists, and nothing for advertising or tracking. We don't sell data, and we don't use your portfolio or questions to train models.

How Cloud accounts are separated

Cloud customers share one database rather than each getting a private machine. Rows carry an owner, every query filters on it, and PostgreSQL row-level security enforces the same rule underneath — so a query that forgot to filter returns nothing rather than someone else's holdings. We think that is the honest way to describe it: strong separation inside shared infrastructure, not physical isolation. If you want your data on hardware nobody else touches, self-host — that option stays free forever.

Our staff do not read customer portfolios. Access to production is limited to what is needed to operate and support the service.

Your controls

Contact

When you self-host, you are the data controller for everything in your instance and we are not involved. On Serin Cloud we are the data controller for your account and the portfolio data you store with us.