OptionFlowPro

Privacy Policy

Effective June 30, 2026

OptionFlow Pro (“we,” “us”) operates the options-income dashboard at cldhost.com. This policy explains what personal information we collect, how we use it, and the choices you have.

1. Data we collect

  • Account data. When you sign up, we store your email address and a hashed password via Supabase Auth. We never see your raw password.
  • Brokerage account data (optional). If you choose to connect a brokerage via Plaid, we receive holdings and investment transaction data (symbols, quantities, cost basis, trade history) from your broker. We store this in an encrypted database.
  • Portfolio entries (local). Positions you enter manually are stored in your browser’s localStorage and never leave your device unless you explicitly export them.
  • Usage logs. Standard server logs (IP address, user agent, request path) held for up to 30 days for debugging and abuse prevention.

2. Data we do not collect

  • Brokerage passwords or MFA codes. Plaid handles authentication with your broker directly.
  • Social security numbers, tax IDs, or government-issued identifiers.
  • Payment card details. If we add paid tiers in the future, payments are processed by Stripe; card data goes directly to Stripe and never to us.

3. How we use your data

  • To let you view, sort, and analyze your positions inside the dashboard.
  • To sync fresh brokerage holdings when Plaid signals an update.
  • To send transactional emails (magic links, password resets, security alerts). We do not send marketing email.

4. How Plaid fits in

We use Plaid Inc. to connect your brokerage account. Plaid’s end-user privacy policy governs their handling of your credentials and data. When you disconnect a brokerage in OptionFlow Pro, we call Plaid’s /item/remove API to revoke access and delete the associated data from our database.

5. Where your data lives

  • Application code runs on Vercel (US regions).
  • Account data lives in Supabase Postgres (US region).
  • Access tokens issued by Plaid are encrypted with AES-256-GCM before they touch the database. Encryption keys are stored as Vercel environment variables and are not visible in our source code.
  • Row-level security is enforced by Supabase, so users can only access their own rows.

6. Retention and deletion

You can disconnect any brokerage from your dashboard at any time — the corresponding data (item, holdings, transactions) is deleted immediately. To delete your entire account and all associated data, email hello@cldhost.com and we’ll process the request within 7 days. All account rows in Supabase cascade-delete when the user record is removed.

7. Cookies and analytics

We use session cookies to keep you signed in. We do not run third-party marketing analytics or ad tracking on this site.

8. Sharing

We do not sell or rent your personal data. We share data only with the service providers required to run the product: Supabase (auth + database), Vercel (hosting), Plaid (brokerage connectivity). Each of those providers is bound by their own privacy commitments.

9. Your rights

You can request access, correction, or deletion of your personal data by emailing hello@cldhost.com. If you’re a California resident, the CCPA gives you specific rights of access, deletion, and opt-out of sale — we do not sell your data, so opt-out is effectively the default.

10. Children

OptionFlow Pro is not intended for anyone under 18 and we do not knowingly collect data from children.

11. Changes to this policy

We’ll update this page when the policy materially changes and update the effective date at the top. For substantive changes affecting existing users, we’ll email a notice to your account email.

12. Contact

Questions or requests: hello@cldhost.com.