Skip to content

Privacy Policy

Last updated: September 4, 2026

Who we are

Vault and Compass, LLC ("Vault & Compass") is a software company that builds financial tools for individuals and financial advisors. We are not a registered investment advisor, broker-dealer, or financial institution. Our products are software tools: they help you understand and organize financial information, but they do not manage money or provide regulated financial services.

This policy covers all Vault & Compass products: Prismfolio, Sheetful, and vaultcompass.io. Where a product's own privacy policy provides more specific terms for that product, the product's policy controls.

The short version

  • We collect only what we need to make the products work.
  • We do not sell your data. Ever.
  • We do not use your financial data for advertising.
  • We use Plaid for read-only bank and investment data. We never see your banking credentials.
  • On vaultcompass.io we use Plausible Analytics for aggregate site statistics, not ad profiling or cross-site tracking.
  • Prismfolio keeps on-page analysis local in your browser. Plaid connections open in the web app only; if you sign in there, we store only what saved accounts and one read-only Plaid sync require, encrypted at rest.
  • Payments for paid plans are processed by Stripe. Card details are collected directly by Stripe and do not pass through our servers.
  • You can request deletion of your data at any time.

What we collect and why

Website and waitlist

When you submit our contact or waitlist form, we collect your email address and any message you write. We use this to respond to you and, if you opted in, to send product updates. We do not add you to marketing lists without your consent.

On vaultcompass.io we use Plausible Analytics to understand aggregate traffic (for example, page views, referrers) and a small set of optional, action-focused events (for example, which call-to-action areas are used). Plausible is designed for privacy-friendly statistics: it does not use advertising cookies, and it does not follow you across unrelated websites. How Plausible handles data is described in Plausible's privacy policy.

You can turn site analytics on or off for this browser using the control below. Your choice is stored locally and applies only on this device.

Checking your analytics preference...

Prismfolio (free tier)

The free tier is a Chrome extension that reads portfolio data from supported brokerage pages (Fidelity, Schwab, Vanguard). On those pages, analysis runs locally in your browser. Sign in on the web app to save up to three accounts and connect one read-only Plaid sync (Plaid Link is web-only); we store only what sync requires, encrypted at rest. No sign-in is required to use the extension on a broker tab.

Prismfolio (signed-in and Plus)

Free signed-in users can save up to three accounts and one read-only Plaid sync in the web app (including Fees analysis). Plus adds unlimited web Plaid connections and deeper Analysis (Allocation, Concentration, Performance). When you sign in or connect sync via the web app, we collect:

  • Google account: Your name and email via Google Sign-In (Chrome Identity API). Your Google credentials never touch our servers; authentication happens through Google's OAuth infrastructure. Available on Free and Plus.
  • Investment data via Plaid: Holdings, balances, and securities data from your connected brokerage accounts. This connection is read-only. Plaid never grants us the ability to move or modify your funds. Your credentials are encrypted in your browser and passed directly to Plaid. They are never transmitted to or stored by Vault & Compass. Connections are opened in the web app (Plaid Link). Free includes one sync connection; Plus is unlimited. Categories your institution may include with connected-account data are described in the Bank and investment account connections section.

We store your Plaid access token encrypted using AES-256-GCM. Your investment data is stored to power signed-in sync and historical tracking. You can disconnect your accounts and delete all stored data at any time from your account settings.

Sheetful

Sheetful syncs bank transactions to your Google Sheet or Excel workbook (OneDrive). To do this, we collect:

  • Bank transaction data via Plaid: Account names, balances, and transaction history from your connected bank and credit card accounts. Read-only access. Your banking credentials are encrypted in your browser and passed directly to Plaid. They are never transmitted to or stored by Vault & Compass. Categories your institution may include with connected-account data are described in the Bank and investment account connections section.
  • Google account (if using Google Sheets): OAuth access to write to your designated Google Sheet. We request the minimum permissions required: write access to the specific spreadsheet you connect, not your entire Google Drive.
  • Microsoft account (if using Excel): OAuth access via Microsoft Graph to write to your designated Excel workbook in OneDrive. Microsoft's consent screen describes this permission (Files.ReadWrite) as access to your files, which is broader than Google's per-file permission. Graph offers no equivalent scope limited to files the app created. We use it only to read and write the workbook you connect.
  • Email address: For account management and product communications.

Plaid access tokens are stored encrypted using AES-256-GCM. Google and Microsoft OAuth tokens are stored with the same level of protection. You can revoke any connection at any time from your account settings or directly through your bank, Google, or Microsoft account.

Billing and payments

Paid subscriptions (Prismfolio Plus and paid Sheetful plans) are processed by Stripe, our payment processor. Your card number and full payment details are collected directly by Stripe. They are never transmitted to or stored by Vault & Compass.

What we do store is a Stripe customer identifier linked to your account, plus your subscription status and plan. Your invoices and billing history are maintained by Stripe; we access them for account management, support, and tax and accounting obligations.

Refunds and payment disputes are handled through Stripe. How Stripe handles your data is governed by Stripe's privacy policy.

Bank and investment account connections

Vault & Compass products access financial account data through Plaid, an account aggregator. These connections are made under read-only scopes: they cannot move, transfer, or modify funds in a connected account.

Depending on the product and the accounts you connect, the categories of information accessed through a connection are:

  • Account balances: Current balances and account details for the accounts you connect.
  • Holdings and securities data: Positions and security information for connected investment accounts.
  • Transaction history: Transactions your financial institution reports for the connected accounts.
  • Account-holder identity and contact information: Identity and contact details that your financial institution includes with connected-account data. Financial institutions may share this category regardless of which data a product requests.

Connected-account data syncs periodically for as long as an account connection remains active.

We use connected-account data to provide the product features you connected the account for. It is shared with the service providers listed under "Third-party services" below that are involved in operating those features, and may be disclosed where required by law or legal process. It is retained while the connection and your account remain active, and is deleted as described in the "Data retention" section of this policy.

You can end a connection in two places. In the product, use account settings to disconnect the account: this stops further syncing and lets you delete the data already stored. At your bank, use the bank's own connected-apps or security settings (for example, Citi Online under Profile, then Connected Apps). Changing your bank password does not revoke this access.

Each product's own privacy policy governs how that product handles the data from your connections. See the Prismfolio privacy policy and the Sheetful privacy policy.

Third-party services

We use a small number of third-party services to operate our products:

  • Plausible Analytics: Privacy-oriented website statistics for vaultcompass.io (aggregate traffic and limited custom events). See plausible.io/privacy.
  • Plaid: Bank and investment account connectivity. Plaid's privacy policy governs how Plaid handles data during the connection process. See plaid.com/legal.
  • Google: OAuth authentication and Google Sheets integration. See Google's privacy policy.
  • Microsoft: OAuth authentication and Microsoft Graph access for Excel and OneDrive sync (Sheetful). See Microsoft's privacy statement.
  • Stripe: Payment processing for paid subscriptions. Your card details are collected directly by Stripe and never pass through our servers. See stripe.com/privacy.
  • Formspree: Handles contact and waitlist form submissions on our website.
  • Upstash: Managed infrastructure (data caching, queues, and rate limiting) supporting our services. See Upstash's privacy policy.
  • Resend: Transactional email delivery: account and service notifications (such as welcome, sync alerts, and billing confirmations) and support correspondence. See resend.com/legal/privacy-policy.
  • Sentry: Error and performance monitoring for our products. Where session replay is enabled, all on-screen text is masked and media is blocked before capture, and error reports are configured to minimize personal data. See sentry.io/privacy.
  • PostHog: Product usage analytics for Prismfolio and Sheetful. See posthog.com/privacy.

No advertising network, tracking pixel, or cross-site profiling script runs on our sites or in our products. We do not use analytics providers that build cross-site advertising profiles of you, and we do not sell personal data for marketing or ad targeting.

Data retention

We retain your data for as long as your account is active or as needed to provide services. If you delete your account, your personal data is removed from active systems within 30 days, except where retention is required by law or necessary to resolve disputes. Security audit logs are kept for up to 90 days and then deleted automatically. Residual copies in encrypted backups expire automatically within our hosting provider's point-in-time recovery window (currently up to 7 days). Once these windows lapse, deleted data cannot be recovered.

For waitlist signups with no associated account, we retain your email until you unsubscribe or request deletion.

Data deletion requests are confirmed within 24 hours of receipt. We will notify you by email once your data has been removed.

Your rights

You can request at any time:

  • A copy of the personal data we hold about you
  • Correction of inaccurate data
  • Deletion of your data and account
  • Disconnection of any Plaid or Google connection

To exercise any of these rights, email privacy@vaultcompass.io. We respond within 30 days.

Children

Our services are not intended for users under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal information, contact us and we will delete it promptly.

Security

We use industry-standard security practices including encrypted storage of tokens and credentials, HTTPS for all data in transit, and access controls limiting who can view your data internally. No system is perfectly secure. If you discover a vulnerability, please report it to security@vaultcompass.io.

Changes to this policy

We will update the "Last updated" date at the top of this page when we make material changes. If changes significantly affect how we handle your data, we will notify active users by email.

Contact

Questions about this policy or your data:

Vault and Compass, LLC
privacy@vaultcompass.io

We use privacy-friendly analytics (Plausible) for aggregate site traffic. Privacy Policy