Privacy notice
Effective 23 September 2026
InteractiveFIRE uses your email and portfolio reports to provide the service. We also record security events and usage information to keep it working and understand where people need help. Your portfolio data is not sold or used for advertising. There are no third-party analytics or advertising trackers.
Who controls your data
InteractiveFIRE operates InteractiveFIRE and is responsible for the personal data described in this notice. Privacy requests can be sent to [email protected].
Information we process
| Information | Purpose |
|---|---|
| Email address | Authentication, service messages, and support |
| IBKR Flex token | Statement retrieval; encrypted and never displayed |
| Portfolio and activity data | Portfolio reporting and analysis |
| Account identifier | A keyed, non-reversible identifier and last four digits are stored to match and distinguish accounts; the full broker account number is not stored |
| Product settings | Saving your reporting and projection preferences |
| Authentication and security events | Preventing abuse and investigating unauthorized access |
| Passkey details, if you add one | Signing you in using a stored public key; the private key stays with your passkey provider or device |
| Plan history and administrative records | Recording access entitlements, support actions and account deletion |
| Setup and usage events | Understanding signup, import failures, trial use and return visits; events include a portfolio reference, time and event type |
| Waiting-list email collected before signup opened | Inviting the people who asked |
InteractiveFIRE does not store a user password. Reports containing your name, postal address, or date of birth are rejected before import.
How information is used
- To provide, maintain, and secure the service.
- To retrieve statements and calculate portfolio analytics.
- To send authentication codes, operational alerts, and support responses.
- To meet legal, security, and accounting obligations.
Providing your account, imports and requested reports is necessary to deliver the service under the terms of use. Security monitoring, support records and usage measurement serve our legitimate interests in protecting and improving the service. You can object to processing based on legitimate interests by contacting us. Where a specific legal obligation requires processing, we rely on that obligation.
Cookies and usage information
We use essential cookies to keep you signed in and protect forms against unauthorized requests. Daily page counts have no account, session or IP address attached. Separately, we record portfolio-linked events such as completing setup, starting a trial and returning to the app. These help us understand how the service is used and find problems with setup.
Service providers and recipients
- Interactive Brokers, when the service retrieves reports using your token.
- Email delivery providers, which receive your email address and message contents.
- Hosting and infrastructure providers, which support the application, secure traffic and store backups.
- Market and fund-data providers, which receive instrument identifiers but no user identity or portfolio.
- The operator, where access is necessary for support, security, or fault investigation. Administrative access is logged.
Application servers are located in the European Union.
How long we keep it
Your portfolio and account details are kept while your account is active. Deleting your account in Settings removes the portfolio and member logins. Some administrative and usage records remain, as described below.
| Information | Retention after account deletion |
|---|---|
| Portfolio, Flex token, account, and active sessions | Immediately |
| A member’s own login, passkeys and sessions, when they delete their login | Immediately; the portfolio belongs to its owner and stays |
| Encrypted nightly backups | Within 35 days, when backups expire |
| Plan history and administrative audit logs | Our retention policy is seven years. Audit records can include the email address of the person requesting an action, including deletion |
| Portfolio reference, its settings and usage events | Retained without a scheduled expiry; these records remain after portfolio data, memberships and sign-in details are removed |
| Feedback | May be retained after removing its association with your account |
| Waiting-list record from before signup opened, where no account was created | Until removal is requested |
Backups are immutable recovery copies and are not edited individually. They expire automatically within 35 days and are used only for disaster recovery.
Your choices and rights
- Access a copy of your personal data.
- Request your data in a portable format where the right to portability applies.
- Correct inaccurate information.
- As an owner, delete your account in Settings → Account. As a member, delete your own login there; the owner’s portfolio is not changed. Either can also contact us.
- Disconnect IBKR in Settings → Data, optionally deleting the imported data, and delete the Flex token in IBKR under Performance & Reports → Flex Web Service at any time.
- Object to or restrict processing where applicable.
Plus and Pro include self-service CSV export. The right to request a copy of your personal data applies to every plan. Requests will receive a response within one month. If a request is complex and needs more time, we will explain why within that month.
You may lodge a complaint with your national data protection authority.
Security
- Flex tokens are encrypted before database storage and deleted when you disconnect.
- No reusable account password is stored.
- Connections use HTTPS.
- Each portfolio's data is kept separate, with access restrictions enforced by the database.
- Administrative access and security-relevant events are logged.
No system can guarantee absolute security. Affected users will be notified where a security incident creates a legal or material requirement to do so.