Summary
How Valivra collects, uses, shares, and protects information when you use the Valivra website and app.
This privacy policy describes how Valivra (“Valivra”, “we”, “us”) collects, uses, shares, and protects information when you use the Valivra website and application. By using Valivra, you agree to the practices described here.
1. Who we are
Valivra is a financial data platform (“Financials. Filings. Fundamentals.”) that combines market data, SEC filings, and your own investment records in one workspace. Valivra is operated by Carson Cole. Contact: [email protected].
2. Information we collect
Account information. When you sign up we collect your email address and password (stored only as a secure hash), and any name you choose to add to your profile.
Investment data you provide. Accounts, holdings, transactions, tax lots, orders, watchlists, notes, and similar records you create or import into your team. This data is owned by your team (organization), not by Valivra.
Brokerage connection data. If you connect a brokerage (for example, Schwab or IBKR), we store the OAuth access and refresh tokens needed to sync your accounts (encrypted at rest), the external account identifiers you map, and sync metadata such as last-sync timestamps. We never see or store your brokerage password.
Market data. Security prices, company fundamentals, filings, news, dividends, and splits that Valivra retrieves from public sources and third-party market data providers and exposes to you.
Support and AI features. Questions you send to the Support Assistant, email you exchange with the Valivra inbox, and portfolio agent runs you start. Support Assistant chat content (your questions and the answers) is encrypted at rest and deleted automatically after 24 hours. LLM features send the relevant context (for example, your portfolio positions or your question) to the configured AI model provider in order to generate an answer.
Usage and session data. Sign-in sessions (including agreement acknowledgments with IP address and browser user agent) and operational logs needed to run and secure the service.
3. How we use information
We use the information above to operate and provide Valivra: authenticating you, syncing and displaying your investment data, serving market data, answering support requests, running AI features you initiate, sending service emails (for example, invitations, digests, and daily summaries you enable), and maintaining security. We do not use your investment data to advertise, and we do not sell personal information.
4. Brokerage connections
Brokerage integrations use provider OAuth. Connecting a provider authorizes Valivra to access the accounts you choose, typically with read-only scope. Tokens are encrypted, used only to sync the accounts you mapped, and stop working when you disconnect the connection or revoke access with your broker.
5. Third-party services
Valivra relies on a small number of processors and data providers:
- Market data providers — security prices, company fundamentals, and filing data shown to you.
- SEC EDGAR — public company filings retrieved from the SEC’s public EDGAR system.
- Your brokerage (for example, Charles Schwab, Interactive Brokers) — account and position data you choose to sync.
- AgentMail — hosting for the Valivra support inbox and outbound mail.
- AI model providers — the OpenAI-compatible providers configured for Support Assistant and portfolio agents.
These services receive only what is needed to perform their function. We do not otherwise disclose personal information except as required by law.
6. Cookies and local storage
Valivra uses a single session cookie to keep you signed in and remember your active team. We do not use advertising or cross-site tracking cookies.
7. Data retention and deletion
Your investment data is retained while your account is active. You can delete individual records at any time; deleting an account, connection, or team removes the associated data. Support Assistant chat history is ephemeral: questions and answers are deleted automatically 24 hours after you send them (an automated hourly job removes expired chats). Contact us to close your account and request deletion of remaining personal information. Sync tokens are deleted when a connection is removed.
8. Security
Passwords are stored as salted hashes, OAuth tokens are encrypted at rest, and access to investment data is scoped to your team and the account grants your team sets. No method of transmission or storage is perfectly secure, but we work to protect your information and to limit internal access.
9. Children’s privacy
Valivra is not directed to children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal information from them.
10. Changes to this policy
We version this policy by effective date. When we make material changes, we publish a new version on this page with an updated effective date. Continued use of Valivra after a new version takes effect constitutes acceptance of the updated policy.
11. Contact
Questions about this policy or about how Valivra handles your information: [email protected].