Security
How the tracker protects access to your portfolio, and how to report a concern.
Protecting Access to Your Portfolio
- Account authentication: our authentication provider handles email/password and Google sign-in. Google sign-in requests basic profile information; it does not request access to your email inbox.
- Account separation: portfolio requests validate your session, and database row-level access policies restrict ordinary user access to records owned by that user.
- Session protection: the hosted tracker uses HTTPS. Its session cookies are marked Secure, HttpOnly, and SameSite, and write requests check their origin. Google sign-in uses a one-time code exchange tied to the browser that started it.
- No brokerage connection: holdings are entered manually or imported from a CSV. The tracker does not request brokerage credentials or have permission to trade or move money.
These safeguards do not make the service risk-free. Authorized administrators and infrastructure providers may access information for operations, support, or security. This page describes the current implementation; it is not a claim of an independent security certification or audit.
Steps You Can Take
Use a unique password or protect your Google account with its available security options. Sign out on shared devices. Keep downloaded exports private, and remove account numbers or personal details before sharing screenshots.
Report a Security Concern
Email a description of the issue, the affected page, and the approximate time. Share enough detail to help us investigate without accessing or downloading anyone else's records.
Do not include passwords, session tokens, full financial statements, or other users' personal information.
Opens your email app. Nothing is sent until you send the message.For account access problems or suspected unauthorized activity, contact us promptly. If your Google account is affected, secure that account directly as well.