What this is, what you may do with it, and what happens to your data.
This is the long version of the notice at the foot of every screen. It is written so that each claim on it can be checked against the product rather than taken on trust — the same standard the rest of this site holds itself to, and the only one worth anything on a page like this.
Last updated 21 September 2026
1. What this is
Folionomiq performs descriptive analysis of price history for a portfolio you type in. It measures what a set of holdings has done — volatility, drawdown, concentration, how much each position contributed to the whole — over a window it names every time.
It is not, and does not attempt to be, any of the following:
- Investment advice. It makes no personal recommendation to buy, sell or hold anything.
- A suitability assessment. It knows nothing about your circumstances, your other assets, your obligations or your tolerance for loss, and it never asks.
- A prediction. No figure on this site forecasts a price, a return, or the probability of either.
Because it makes no personal recommendation concerning a financial instrument, it is not an investment service within the meaning of MiFID II or Law 126/2018, and it is not authorised or supervised by ASF. It does not need to be — but that boundary is the reason, so the boundary is kept deliberately.
That is a claim, so here is the evidence rather than the assurance: /method prints how every figure on the site is computed, its window, and what it does not support — generated from the engine itself rather than from prose kept beside it, so it cannot describe a figure the product does not actually produce. A tool that forecasts has no such page to show you.
What you do with the numbers is your decision, and yours alone.
2. Who runs it
Folionomiq is built and run in Romania, as a non-commercial research and education project. There is no company behind it and no investor.
Contact: [email protected] — an address on this domain, forwarded to a mailbox kept only for this. Mail is read by the person who wrote the product. It is also the address for anything in the privacy section below.
If this ever stops being free — which it cannot do before the licence question in section 3 is settled — a registered entity will have to exist, and this section will then name it, its registration number and its registered address.
3. It is free, and that is load-bearing
Nothing is charged. There is no plan, no checkout, no paywall, no subscription, no advertising and nothing sold — not as a launch offer, but as a condition the rest of the product depends on.
The price data comes from sources whose free terms cover research and education and not commercial use or redistribution. Free, non-commercial, and redistributing nothing is precisely what keeps this deployment inside those terms. It follows that on the day money is taken for access, a commercial display licence has to already be in place — not be arranged afterwards. That order is written into the project's own repository as a gate, so taking the money first would mean breaking something recorded rather than overlooking something.
What being free does not create
No entitlement to availability, to any particular feature, or to notice before either changes. This may be modified or shut down at any time. It runs on a free hosting tier that sleeps when idle, so the first load after a quiet period can take around half a minute; that is the tier, not a fault.
4. Where the numbers come from
End-of-day closing prices from public sources, together with dividends, fund metadata and academic factor data. The detail, figure by figure, is on /method.
- Prices can be wrong, late, or missing. Corporate actions are handled by the source; this project does not audit them.
- What leaves the server is derived — volatilities, drawdowns, contributions, scores. Raw quotes appear in two places only, and only for a ticker you asked about.
- There is no bulk export and no download of price series. That is a deliberate limit, not a missing feature.
5. What you may do with what you read here
This project publishes measurements in order for them to be used and argued with. So the permission is stated plainly and broadly, rather than reserved by default and negotiated on request.
You may, without asking
- Read it, and use it for your own decisions.
- Quote figures, sentences and whole findings, with attribution and a link to the page you took them from.
- Do anything you like with the report about your own portfolio, including pasting it into another AI. That report is yours. Nothing here claims a right over it, or over the holdings you typed in.
- Use it through the connectors we publish for AI assistants (ChatGPT, Claude and others that speak MCP), described at /connect. The same rules apply there: no bulk extraction, no redistribution of prices, no presenting the output as advice.
You may not
- Access the API directly, scrape the site, or extract data in bulk. The API exists to serve this app and the connectors we publish, and nothing else.
- Redistribute the underlying price series, whole or in part, or build a data feed out of them. This one is not ours to waive — it is the term the free sources impose on us.
- Present the output as advice, as your own analysis, or as coming from someone else.
The pages, text, design and code of this site belong to its author. Open-source components keep their own licences, and their notices ship inside the application bundle.
6. No warranty
Figures may be wrong. Sources may be wrong. The code may have bugs — this project's own audits have found and published a number of them, and there is no reason to believe that has stopped. The site is provided as is, with no warranty of accuracy, completeness, availability or fitness for any purpose.
Every figure is shown with the method that produced it, the window it covers and the limit of what it supports. That is the honest maximum a tool like this can offer: it can tell you what was measured. It cannot tell you what will happen.
7. Liability
To the fullest extent Romanian law permits, the author is not liable for any loss arising from use of this site or from reliance on anything shown on it, including investment losses.
Romanian law does not permit excluding liability for harm caused intentionally or through gross negligence (Civil Code, art. 1355), and nothing here attempts to. If you are a consumer, the mandatory protections of your country of residence apply whatever this page says.
8. Privacy
The controller is the person described in section 2, reachable at [email protected].
What is not done here
No accounts. No cookies. No third-party analytics, no advertising network, no tracking pixel, no fingerprinting, and no profile of you held anywhere.
Your browser contacts no third party. Every file these pages load comes from this domain, including the typeface — it used to be fetched from Google Fonts, which meant your browser asked Google for it and Google saw your address in the request. That was disclosed here while it was true; the files now sit on this server, so there is nothing left to disclose. The site's security policy no longer permits any outside host either, so this cannot quietly come back.
The server does contact others, on your behalf. That first sentence used to read “no third party is contacted at all”, which was true about your browser and false about the server. The difference matters, so here it is plainly: prices have to come from somewhere. When you search for a fund, the words you typed go to Yahoo Finance. When you paste an ISIN, it goes to OpenFIGI (Bloomberg) to find out which listings it names. When a price is not already stored here, the ticker goes to Yahoo Finance. The US and euro-area consumer price indexes arrive on a schedule from the Federal Reserve Bank of St. Louis and the European Central Bank; nothing is sent to them. When a US fund is looked through, its ticker goes to the US Securities and Exchange Commission for the fund's own public filing of its holdings, and the identifiers of the companies in that filing go to OpenFIGI to be turned into tickers. What does not go with any of it: your address, your name, your portfolio, or anything saying that two requests came from the same person. Two more files arrive on a schedule rather than because anyone asked — the European Central Bank's daily exchange rates, and the published factor series Kenneth French keeps at Dartmouth — and neither carries anything of yours.
Through an AI assistant. When your assistant measures a portfolio through our connector, it sends the holdings here on your behalf, exactly as the app does: they are measured and never stored. The request carries the assistant's address, not yours. What goes back to the assistant is the measurement, never price series. What the assistant then does with it, and what it keeps, is governed by its own terms, not these.
There is no consent banner because nothing is placed on your device for our benefit — only the three items listed below, each strictly necessary for the thing you asked for.
Counting visitors
A few numbers a day are kept: pages served and which of our own pages they
were, how many of those pages
actually ran in a browser (the page says so once, after it has drawn, with
an empty request — it is how a reader is told apart from something that
only downloads the file), quick checks run on the front page, app opens,
analyses run,
decision receipts copied, distinct daily readers, and how many readers
reached each of four first steps (a first fund added, a second one,
"Save and analyse" pressed, arriving in the app from the front page's
quick check), how many readers came from each country, how many of them
opened the app, how many opened the quick check and how many measured in it,
and how many ran an analysis (the country of the connection,
as our network provider reports it; a count per country per day, never tied
to you) — plus the
host that linked here
(reddit.com, say), never the thread, the query string or the
search term. Machines are counted apart and never as readers: search
engines and AI assistants by the name they announce
(Googlebot, GPTBot, say), with the public pages
they fetched.
If your browser sends Global Privacy Control, none of that
happens. A request carrying Sec-GPC: 1 is recorded
as one objection for the day and then dropped: not a visit, not a reader,
not credited to a country, not added to any step. The single number is
kept so the page can say how much of a day objected — an exclusion nobody
can see is one nobody can argue with. This was true of the pooled tables
below from the day they were written, and not of this counter until
21 September 2026; the sentence has been corrected rather than the
practice defended.
- How a reader is counted once
- Your IP address is combined with a random salt that changes every day and is never written down anywhere, hashed, and part of that hash used as a one-day identifier — so ten page views by one person are not ten people. The identifiers exist in memory only and are discarded when the day rolls over. Only the resulting counts are saved.
- Legal basis
- Legitimate interest, GDPR art. 6(1)(f): knowing whether anyone uses this at all.
- Retention
- What is stored is an aggregate with no personal data in it, so there is nothing about you to retain. The daily identifiers last at most a day and never leave memory.
- If you answer "Was this useful?"
- Your stars and the boxes you tick each add one to a count for the screen you were on — the same kind of daily number as the rest of this list. There is nowhere to type, so there is no text of yours to keep, and no record of your answer on its own: only the running totals. The one-day identifier above is used, in memory only, to take at most three answers from one reader a day.
- If you copy a decision receipt
- The receipt is written by your browser from the result on your screen, and its text is never sent here. What reaches the server is only that a receipt was copied, which adds one to a daily count; the one-day identifier above counts how many different readers did it and takes at most five copies from one reader a day.
- The registry of measured combinations
-
When a portfolio is measured — in the app's overview, or in the quick
check on the front page — one is added to a pooled count of
the combination, coarsened: the funds in it by symbol,
each weight rounded down to a band of ten percentage points, with every
individual stock pooled into a single slice called "stocks" (and cash
likewise); the month, and the day,
which is kept for fourteen days and then dropped, so that "what was
measured most this week" can be answered; the country the
request came from, as two letters; and the currency it
was measured in. Country and currency are tallied separately, never
against each other. A reader counts at most once a day, using the one-day
identifier above in memory only; the owner's own visits are not counted,
and a browser sending Global Privacy Control is not counted at all.
While a combination is rare, the count is all that is kept. Until it has been measured five times in a month it carries no country, no currency and no day — because a combination few people hold, next to a country and a date, can point at one person even though none of those three is a name. Until 21 September 2026 that floor was applied when a page was drawn rather than when the file was written, so the detail sat in the file unshown. Nothing about any combination is published below fifty measurements either way. - What the funds hold, pooled
- Where this site has already worked out what sits inside your funds — the quick check on the front page, and the Look-through view — the sectors the money lands in (technology, healthcare, energy…) are added to one pooled table: a running total of each sector's share, and how many portfolios went into it, per month. Averages are made from those two numbers. The table is not attached to a combination, a country or a person, so there is no way back from it to anyone; the same once-a-day rule and the same exceptions apply, and nothing is shown below 50 portfolios.
- What the registry shows
- Nothing, until at least 50 measurements over three months share a combination. Below that it exists only as a number in a file. At 50, the combination can get a public page on this site, measured at the middle of each band, with any country under 50 grouped into its region. Legal basis: legitimate interest, GDPR art. 6(1)(f) — knowing which combinations are worth a page. The counts contain nothing about a person, so there is nothing about you in them to access or erase.
- The mirror
- A measurement in the app's overview also adds to pooled tallies of six structural figures — number of holdings, independent bets, the share of the movement in one direction, the share of the risk in the heaviest holding, volatility, and the share of the money in single stocks — each put into a bin (five percentage points, one point of volatility, half a bet), per month, for everyone, per country and per region; three of them (the share in one direction, independent bets and volatility) also per week. Within bands of the share moving in one direction, it also counts which funds are held and, from the Decision Lab, which funds were added or removed in a tested change and which way the change moved that share. Funds by symbol only; single stocks are never named. Counted once a day per reader, with the same exceptions as above.
- What the mirror shows
-
A group — a place over three months, or a band — only from
50 portfolios, and inside it a map cell, a fund or a
tested change only from 10. The figures are published
as percentiles in steps of five, never as the bins. Where your own
portfolio stands is worked out in your browser from figures already on
your screen, and is not sent back. The page at /mirror
reads the readings the app keeps in
rcp-history-v1for this, and writes nothing. - Never recorded
- Amounts, exact weights, exact figures, individual stocks by name, portfolio names, your address, and any free text. The portfolio you send is measured and not written down; only the pooled counts above are.
Your portfolio, and what is on your device
Your portfolio is stored in your browser and nowhere else —
five entries in this site's local storage, and nothing besides:
rcp-workspace-v1 (the portfolio),
rcp-check-v1 (the portfolio typed into the quick check, kept
apart from the one above so neither can overwrite the other),
rcp-history-v1 (a few past readings, so a page can say what
changed since last time), rcp-decisions-v1 (the changes you
tested in the Decision Lab, and whether you kept them) and
rcp-theme (light or dark). The app
also caches its own files so it keeps working offline; there is no personal
data in that cache.
A sixth entry exists for a fraction of a second and holds nothing:
rcp-probe, written and immediately deleted when the app
opens, purely to find out whether this browser will keep anything at all.
If it will not — a private window, blocked site data, a full store — the
app says so at the top of the page instead of letting you type a
portfolio that vanishes when the tab closes.
One further entry exists only on the site owner's own phones and computers:
rcp-owner, set when the owner presses a button on a private page,
so the owner's own use is left out of the visitor counts. It is never placed
on a visitor's device. The same private page keeps its access token for the
length of one tab (rcp-stats-token, session storage, gone when
the tab closes); that page is not reachable without the token, so this never
touches a visitor either.
Storing anything on your device normally requires consent under art. 5(3) of the ePrivacy Directive and Law 506/2004. These are exempt because they are strictly necessary to provide the thing you asked for — an app that remembers the portfolio you typed into it. Nothing is stored for any other purpose, and none of it is an identifier.
Holdings are sent to the server to be measured, and are never stored there — apart from the pooled, rounded count of which funds are combined, described under the registry above, which holds no portfolio and nothing about you. You can erase everything from the foot of any screen in the app, or by clearing this site's data in your browser. Nobody has to be asked, because there is no copy anywhere else to delete.
If you write to us
Mail sent to [email protected] is kept so that it can be answered — your address, and whatever you put in it. It is forwarded by Cloudflare Email Routing into a Google mailbox. A plain address is offered rather than a contact form, deliberately: a form means storing what strangers write, and that should not be the first thing this product keeps about anybody. Do not send anything you would not want held in an ordinary mailbox.
Where it runs, and what crosses a border
- Hosting
- Render, on servers in the United States (Oregon). Your IP address reaches that server as part of any ordinary web request, which is where the counting above happens.
- Edge, DNS, and storage of the counts
- Cloudflare. What is stored there is the aggregate counts, which contain nothing about a person.
- Mailbox
- Google, for the address above.
- Prices, exchange rates and fund records
- Yahoo Finance (United States) for prices and for fund searches; OpenFIGI, run by Bloomberg (United States), when you paste an ISIN and for the companies named in a fund's filing; the US Securities and Exchange Commission (United States) for a US fund's public filing of its holdings; the European Central Bank for the daily exchange rates and the euro area's price index; the Federal Reserve Bank of St. Louis (United States) for the US consumer price index; Dartmouth College (United States) for the published factor series. They receive a ticker, a search phrase or an ISIN. They do not receive your address, and they never receive a portfolio.
- Transfer outside the EU
- Because the server is in the United States, this is a transfer under Chapter V GDPR, relying on the standard contractual clauses in those providers' data-processing terms. What actually crosses is your IP address and, when you ask for an analysis, the holdings in that request. Both are in transit only: the address becomes a one-day pseudonym for the counting described above, and the portfolio exists for as long as the answer takes and is not written down anywhere. No account, no name.
Your rights
Access, rectification, erasure, restriction, objection and portability. In practice there is very little to exercise them against, because nothing identifying you is kept — but write to the address above and you will get a straight answer rather than a form. You may also complain to ANSPDCP, the Romanian supervisory authority (dataprotection.ro), or to the authority in the country where you live.
9. Age
This site is not directed at anyone under 18, and no service is knowingly offered to them.
10. Governing law, and changes
Romanian law governs these terms. If you are a consumer resident elsewhere in the European Union, that does not deprive you of the mandatory protections of your own country's law, and you may bring proceedings there. No arbitration clause and no exclusive jurisdiction clause is imposed here, because against an EU consumer such clauses would not hold — and a clause that would not hold has no business on a page whose whole point is that it says only what is true.
This page carries the date it last changed, at the top. There are no accounts, so there is nobody to notify; changes are made by editing this page, and earlier versions are kept in the project's repository.