Privacy policy
dmscs is a private, invite-only portfolio analysis tool run by an individual, not a company. This page explains what it stores about you, who can see it and how to have it deleted.
What is stored
- Your sign-in identity. When you sign in with Google, dmscs receives your name, email address and Google's account identifier. It never sees or stores your Google password.
- Your portfolio data. The accounts, holdings, cost basis, transactions, income and planning inputs you enter or import.
- Linked financial accounts, if you choose to link any. Connections go through Plaid. You give your bank or brokerage login to Plaid, never to dmscs. dmscs stores the access token Plaid issues, encrypted, and the balances, holdings and transactions it retrieves.
- Security records. Sign-in sessions and an audit log of security-relevant actions, such as sign-ins and linking or removing an account.
How it is used
Only to show you your own portfolio analysis. Your data is not sold, rented, used for advertising or shared with anyone for their own purposes.
Who can see it
Only you, inside the app. Each person's data is kept separate from everyone else's. The operator has administrative access to the database to run and repair the service, and does not look at your data except to fix a problem you report or when required by law.
Services involved
- Google confirms your identity when you sign in.
- Cloudflare checks access before any request reaches the app and carries traffic to it.
- Amazon Web Services hosts the app and its encrypted database in the United States.
- Plaid connects financial accounts, only if you link one.
- Market data sources (Yahoo Finance, OpenFIGI, SEC EDGAR, fund issuers' websites) receive the ticker symbols and security identifiers needed to look up prices and fund contents. These requests never include your name, email, amounts or account details. Company logos are fetched from Google's favicon service by the company's website address.
Market data the app keeps (prices, fund contents, analyst estimates) is shared across users, but it contains only public facts about securities.
Security
Traffic is encrypted in transit. The database and backups are encrypted at rest, and linked-account tokens are encrypted separately. Access requires an invitation and a sign-in at two separate layers.
Keeping and deleting your data
Your data is kept while you have an account. Email privacy@dmscs.app to get an export or to have everything deleted. Deletion removes your data and disconnects any linked accounts at Plaid. Copies in encrypted backups are not edited; they are deleted when those backups expire.
Changes
If this policy changes in a way that affects you, invited users will be told before the change takes effect.