Privacy Policy
Last updated: July 16, 2026
Pinnacle is a product of Pinnacle Fi, Inc. ("Pinnacle," "we," "us"). This policy explains what information we collect, how we use it, and the choices you have. We built Pinnacle to help you track investments and get AI-generated ideas — not to profit from your personal data. We do not sell your personal information, we do not share it for advertising, and the app contains no advertising, analytics, or user-tracking software.
How Pinnacle works
Pinnacle is a mobile app backed by an internet-hosted service that we operate. Your portfolio and app data are stored on our servers — not only on your device — so that prices stay current, alerts can reach you when the app is closed, and your account works across devices. Data is encrypted in transit between the app and our service.
Information we collect
- Account information. Your email address and authentication credentials, handled on our behalf by a third-party authentication provider. Your password is never visible to us or stored on our systems.
- Portfolio and app data. The holdings you enter (symbol, quantity, purchase price and date, and any notes you add), your watchlist, your portfolio value over time, your stated risk tolerance, and any custom price or indicator alerts you create.
- Security information. If you enable two-factor authentication or biometric sign-in, we store the associated secret or a device identifier. If you create a developer API key, we store only a one-way hash of it.
- Exchange connections. If you choose to link a cryptocurrency exchange, we store the read-only API credentials you provide so we can import your balances. See "Connected exchanges" below.
- Support correspondence. If you contact us through the app or our website, we store the name, email address, and message you submit, so we can respond and keep a record of the request.
- Images you choose to import. If you use the photo-import feature, the image you select is sent for text recognition and returned to you as suggested holdings. We do not store the image.
- Device and usage data. Basic technical data — device type, app version, and, if you opt in, a push-notification token — needed to operate the app and send the alerts you request.
We do not collect an advertising identifier, contact list, precise location, or browsing history, and we do not store IP addresses or browser identifiers alongside your account. Our hosting and security providers process such technical data transiently in order to deliver and protect the service.
How we use your information
- To provide core features: portfolio tracking, prices, Orion analysis, and alerts.
- To send the push notifications you have enabled (you can turn each category off at any time in the app).
- To process subscriptions. Card details are entered directly into our payment provider's secure interface and never reach our servers; we retain only the identifiers needed to manage your subscription.
- To respond to your support requests.
- To maintain security, prevent abuse, and comply with legal obligations.
Where your data is processed
Pinnacle relies on a small number of trusted third-party service providers to function. We describe them by the category of processing they perform rather than by name, because our suppliers may change over time. Each processes data only as needed to perform its function, under contract, and none is permitted to use your data for its own purposes or for advertising.
- Authentication. Holds your email address and credentials and verifies your sign-in.
- Hosting and database. Operates the servers and database where your portfolio and app data are stored.
- AI analysis. Powers Orion. See "How Orion uses your portfolio" below.
- Market data. Supplies prices, charts, and news. We send only the asset symbols being looked up — never your identity, quantities, or position sizes.
- Payments. Processes subscription payments. Your card details are entered into this provider's own secure interface and are held by that provider — they never reach our servers, and we cannot see or retrieve them. We hold only the identifiers needed to manage your subscription.
- Push notification delivery. Delivers the alerts you opt into. The notification content may name assets you hold or watch.
- Text recognition. Reads text from an image you explicitly submit for import.
- Support handling. Routes your support message to our team so we can respond.
- Backups. Stores encrypted-in-transit copies of our database so the service can be restored after a failure.
How Orion uses your portfolio
Orion's analysis is produced by a third-party AI provider, which means some of your data is sent to that provider to generate a response. We want to be specific about what:
- When you request a portfolio analysis or risk report, we send the contents of that portfolio — the symbols, quantities, prices, position values, and computed risk measures. We do not send your name, email address, or account identifier.
- When you request an investment thesis for a single asset, we send that asset's market and technical data. Where relevant we also send a short description of your stated risk tolerance and your portfolio's overall risk level — not your individual holdings.
- When you contact support, your message, name, and email address are sent to the AI provider to categorise and summarise the request.
We do not keep a transcript of your Orion questions. Our AI provider does not use this data to train its models.
Connected exchanges
Linking an exchange is entirely optional. We ask only for read-only API credentials, which allow us to see balances and never to trade, transfer, or withdraw. Your API key and secret are encrypted before they are stored, are never returned to the app or shown again after you enter them, and are used only to import your balances. You can unlink an exchange at any time, which deletes the stored credentials.
Security
Traffic between the app and our service is encrypted in transit. Particularly sensitive values — two-factor authentication secrets and exchange API credentials — are additionally encrypted at rest, and API keys and biometric device identifiers are stored only as one-way hashes. Access to your portfolio data is scoped to your account and verified on every request. No system is perfectly secure, and we cannot guarantee absolute security.
Data retention and deletion
We keep your account and portfolio data for as long as your account is active. You can delete individual holdings and watchlist entries at any time in the app.
You can also delete your entire account from within the app (Profile → Delete Account). This permanently removes your holdings, portfolio history, watchlist, risk profile, alerts and alert history, subscription record, push tokens and preferences, saved security settings, and any connected exchange credentials, and it deletes your sign-in account with our authentication provider. It cannot be undone.
A few things survive that deletion, and we want to be upfront about them:
- Messages sent through this website's contact form. This website has no sign-in, so a message sent here is never linked to your account and deleting your account cannot reach it.
- Messages sent from the app while signed out. A support message sent from the app when you were not signed in is not linked to any account either. Messages you sent from the app while signed in are deleted with the rest of your data.
- Email you have sent us directly. Email sits in our mailbox as correspondence with us rather than as data in your account, and deleting your account does not erase it.
- Backups. Residual copies of data may persist in our off-box database backups for up to about 7 days, and in our database provider's point-in-time-recovery history for up to a few hours, before they age out.
If you would like correspondence removed as well, email privacy@pinnaclefi.app and we will delete it.
Your choices
- Turn any category of push notification on or off in the app.
- Link or unlink an exchange at any time.
- Delete individual holdings, your watchlist, or your whole account from the app.
- Request a copy of, correction to, or deletion of your data by emailing us.
Children
Pinnacle is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has given us data, contact privacy@pinnaclefi.app and we will delete it.
Anyone under 18 may use Pinnacle only with the consent and supervision of a parent or legal guardian. A parent or guardian can contact us at the address above to review, export, or delete their child's data. In parts of the EEA the minimum age for consenting to data processing without the authorisation of a parent or legal guardian is higher (up to 16); where that applies, the higher age governs.
Changes to this policy
If we make a material change to how we handle your data, we will update this page and revise the "last updated" date above.
Contact
Questions about this policy? Reach us at privacy@pinnaclefi.app.