Privacy Policy
Last updated: May 10, 2026
What-If Portfolio (the "Service", "we", "us") is operated as an independent, free-to-use investment simulator. This policy explains what data we collect, how it is used, and the rights you have under the EU General Data Protection Regulation (GDPR) and similar frameworks. We have built the Service to collect as little personal information as technically possible.
1. Data we collect ourselves
None that identifies you. The core simulator does not require an account. Your portfolio configuration (selected assets, weights, date range, initial investment) is stored entirely in your browser using localStorage and the URL hash. It never leaves your device unless you explicitly use the "Share" feature, which encodes the configuration into a URL you choose to send.
If you create an optional account to unlock additional features, we store only the information required to authenticate you (email address, hashed password or OAuth identifier) via our authentication provider. We do not sell, rent, or share this data with marketers.
2. Data collected by third parties
We use the following third-party services. Each operates under its own privacy policy:
- Google AdSense displays advertisements to free users. AdSense uses cookies (such as
__gads,__gpi, and DoubleClick identifiers) to personalise ads and measure performance. See Google's advertising policy. - Yahoo Finance public API supplies historical price data. Requests are made from your browser; Yahoo may log standard request metadata (IP, user-agent).
- Authentication and storage backend (used only when you sign in) handles session tokens and any saved simulations you choose to persist.
3. Cookies and similar technologies
We display a cookie consent banner on your first visit. Until you accept, no advertising cookies are set. See our Cookie Policy for the full list.
4. Your rights under GDPR
Because we hold no identifying data for anonymous users, there is nothing for us to export or delete on your behalf — clearing your browser storage removes everything. For authenticated accounts, you may request access to or deletion of your account data by emailing us. We respond within 30 days.
5. Children
The Service is not directed to children under 16 and we do not knowingly collect data from them.
6. Changes
We will update the "Last updated" date when this policy changes. Material changes will be announced on the homepage.
7. Contact
Questions or privacy requests: contact@prepmify.com.