Last updated 14 August 2026. OmniAsset keeps your data on your device by default. Some optional features send a limited amount of data off the device — this policy says exactly what, and when. It reflects how the app actually behaves.
Your accounts, holdings, transactions, cash flow, goals, snapshots and settings are stored locally on your device, encrypted at rest. No account is required for the core app, and this local data is never uploaded on its own.
The health/research report is computed on our server. When you run it, a compact snapshot of your holdings (units, amounts, dates and fund codes) is sent to our analysis engine, used to compute the report, and discarded — it is processed transiently and not stored. Your bank descriptions, raw statement files and credentials are never sent.
If you turn on Cloud, your portfolio is stored on our cloud provider (Supabase, encrypted on their servers, not end-to-end) so it can sync across your devices. This needs an account (email). You can delete your cloud data at any time (see “Account deletion”); local-only use never creates an account.
AI interpretation is off unless you enable it. When enabled, only a compact set of portfolio metrics and health flags (and, for the second opinion, the primary proposal) are sent to the AI route you chose. Your transaction ledger, daily NAV history, bank descriptions, raw holdings files and credentials are never sent.
If you buy Built-in Premium, the purchase is handled by Google Play. We receive confirmation of entitlement, not your card details.
You can delete your account and cloud data at any time — from the app, or on the web at /delete-account without reinstalling. Deleting the account removes active cloud data and sessions; encrypted backups age out under the retention policy. It does not cancel a Google Play subscription (manage that in Google Play).
Questions about privacy: [email protected].