We use privacy-friendly analytics (Plausible) for aggregate site traffic. Privacy Policy
We build tools that touch sensitive financial data. Here's exactly what we collect, how we protect it, and why our business model doesn't depend on selling it.
Vault & Compass

Building financial software means asking users to trust us with data they'd normally only share with their bank. That trust only holds if we are explicit about what happens with the data, not in legal language, but in plain terms.
Prismfolio free is a Chrome extension. On supported brokerage pages, the extension reads your holdings in your browser and sends them to Prismfolio's servers, where the analysis runs.
When you open a supported brokerage tab (Schwab, Fidelity, Vanguard), the extension reads the portfolio data already displayed on the page. It doesn't log in on your behalf, and it doesn't need an account: a one-off look sends the holdings it read to our API for analysis without a sign-in, and those holdings are analyzed in memory and discarded when the response is sent; we do not store your holdings or create a portfolio record from that look.
If you sign in on the web app, you can save up to three accounts and connect one read-only Plaid sync there. Plaid Link runs in the web app only, not in the extension. Plaid access tokens are encrypted at rest with AES-256-GCM.
Signed-in Free already includes limited web surfaces (Overview, Holdings, Accounts, Fees, Compare, Trade Impact) with one web Plaid connection. Plus adds unlimited web Plaid sync and the deeper Analysis dashboards (Allocation, Concentration, Performance).
For cross-account aggregation, we use Plaid Investments in the web app. When you connect an account, you authenticate directly with your institution through Plaid's interface. We never see your username or password. Plaid returns read-only investment data (holdings, balances, transactions). That data is stored on our servers; the Plaid access token behind it is encrypted at rest with AES-256-GCM, and all data is encrypted in transit with TLS 1.2+.
We use this data to calculate your portfolio metrics: allocation, concentration, expense ratios and fee drag, and performance. We don't sell it, don't advertise against it, and don't share it with third parties except as required to operate the service.
Sheetful connects your bank accounts to your spreadsheet (Google Sheets or an Excel workbook in OneDrive). It uses Plaid Transactions.
Same authentication pattern: you connect your bank through Plaid's interface, which handles your bank credentials. We receive access tokens from Plaid (not your bank password) and store encrypted transaction records to power sync, categorization, and the web app. Rows are written to the Google Sheet or Excel workbook you authorize; your spreadsheet remains the portable copy you own.
Depending on which spreadsheet you use, we also request OAuth access from Google (to write to your Sheet) or Microsoft (to write to your OneDrive Excel file). In both cases we request the minimum scope needed: write access to the specific file you authorize, not your entire Drive or OneDrive.
We don't sell your data. There is no advertising business here. Our revenue comes from subscriptions and one-time purchases.
We don't use your financial data to train AI models or personalize advertising.
We don't share your data with data brokers, marketing partners, or acquirers. If we were ever acquired (we have no plans to seek acquisition), our privacy policy commits that any acquirer would be bound by the same data practices.
These commitments hold because the business model does not create incentives to violate them. We charge for software. The value we capture comes from the quality of the product, not from the value of the data.
A company that monetizes data has a structural incentive to collect more data and find ways to use it. We don't have that incentive. Our privacy commitments aren't just policy. They're consistent with how we make money.
If you have questions about any of this, email privacy@vaultcompass.io. We read every message.