TulaIQ← Back to home
Legal

Privacy Policy

Last updated: May 2026 · Questions? privacy@tulaiq.app

TulaIQ is built on a simple principle: your financial data belongs to you. We collect only what is necessary to run your dashboard, we never sell your data, and we never use it for advertising.

1. What Data We Collect

To operate your portfolio dashboard, we collect and store the following:

  • Holdings data — instrument names, ISINs, quantities, purchase prices, face values, settlement and maturity dates, and coupon rates.
  • Calculated values — yields, DCF fair values, accrued income, and unrealised gains. These are derived from your holdings and market data.
  • Account data — your email address, name, country, currency preference, and experience level selected during onboarding.
  • Session data — authentication tokens managed by Supabase to keep you logged in.

We do not collect bank statements, login credentials for any financial institution, national identification documents, or any other personal documents beyond what is described above.

2. How Your Data Is Stored

All portfolio data is stored in a PostgreSQL database hosted by Supabase on servers located in the United States. By using TulaIQ, you consent to your data being processed and stored in the US.

We apply row-level security (RLS) to every database table, ensuring that your data is only accessible by your authenticated account. Data is encrypted at rest and in transit using industry-standard TLS encryption.

3. PDF Processing

TulaIQ offers optional PDF statement upload to help you import holdings automatically (Pro tier). When you upload a PDF:

  • The document is processed in real time and deleted within 60 seconds of upload.
  • Only extracted numerical data — instrument names, quantities, prices, and dates — is saved to your holdings.
  • All personally identifiable information (PII) present in the document, including account numbers, full names, and addresses, is discarded before storage.
  • No raw documents are retained in our systems after processing.

4. AI Processing

The TulaIQ portfolio assistant is powered by the Anthropic Claude API. When you use the AI chat feature, a summary of your portfolio data is sent to Anthropic to generate a response.

Anthropic does not use data submitted via the API to train their models. Raw documents and personally identifiable information are never sent to Anthropic. All AI requests are proxied through TulaIQ's server — your API calls are never made directly from your browser.

For full details, see Anthropic's Privacy Policy.

5. Third-Party Services

TulaIQ uses the following third-party services to operate the platform. Each service processes data in accordance with their own privacy policies:

  • Supabase — database, authentication, and row-level security. Privacy Policy
  • Anthropic — AI portfolio assistant. Privacy Policy
  • CoinGecko — live cryptocurrency prices. No personal data is sent. Privacy Policy
  • EODHD — London and Johannesburg stock exchange prices. No personal data is sent. Privacy Policy
  • Finnhub — US stock prices. No personal data is sent. Privacy Policy
  • Open Exchange Rates — live currency conversion rates. No personal data is sent. Privacy Policy

6. Your Rights

Under the Zambia Data Protection Act 2021 and general data protection principles, you have the following rights:

  • Right to access — view all holdings and account data stored against your profile at any time from your dashboard.
  • Right to deletion — delete any individual holding directly from your dashboard, or permanently delete your entire account.
  • Right to portability — export your holdings as a CSV file at any time.
  • Right to rectification — edit any holding or account detail at any time.
  • Right to object — contact us to raise concerns about how your data is processed.

To exercise any right or make a data-related request, contact us at privacy@tulaiq.app. We will respond within 14 days.

7. Data We Do Not Collect

We do not collect, store, or process:

  • Bank statements or bank account credentials
  • National Identification Cards or passport details
  • Tax Identification Numbers (TPIN)
  • CSD portal credentials
  • Biometric data of any kind
  • Browsing history or behavioural data for advertising

8. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email using the address associated with your account. Continued use of TulaIQ after any change constitutes acceptance of the updated policy.

9. Contact

For privacy-related questions or requests, contact our data team at privacy@tulaiq.app.

TulaIQ · Lusaka, Zambia

Terms & ConditionsData Policy← Back to TulaIQ