Security & Privacy
Your financial security is our top priority. Learn how we protect your data and privacy.
Encryption in transit and at rest
Free: extract local, sync when signed in
Plus: higher limits + Plus Analysis
Privacy-first analytics
The extension reads holdings from your brokerage's own pages and network responses while you are signed in there; it never receives your brokerage login and never sends a request of its own to your brokerage. Some brokerages restrict automated tools in their terms, so this kind of connection may stop working; Plaid and manual entry do not depend on the extension.
Additional Security Practices
No Credential Storage: We never store your brokerage login credentials. Extension extract runs in your browser; when you are signed in, holdings are sent to our API for analysis and storage. For Plaid linking, we store encrypted access tokens only, never your login credentials.
Secure dependency hygiene: We review dependencies and apply updates to address known vulnerabilities as part of normal engineering practice.
Minimal Data Collection: We only collect data necessary to provide our service. Account and service data (such as your Google sign-in email) are collected to operate the product under this Privacy Policy; optional web analytics require cookie consent.
Right to Deletion: You can delete your account and request removal of cloud data at any time. Uninstalling the extension removes local Chrome storage only; signed-in cloud data requires account deletion or a privacy request.
Secure Development: We follow secure coding practices, including input validation, dependency scanning, and automated security testing.
Secure Account Connection via Plaid
For web app users who choose to link investment accounts, we use Plaid, the same secure infrastructure trusted by Robinhood, Venmo, and Betterment.
- Read-only access: We can view your holdings but cannot trade or move your money
- OAuth security: Your brokerage credentials are never stored or visible to us
- Encrypted tokens: Plaid access tokens are encrypted with AES-256-GCM before storage; holdings use host/database encryption at rest
- No sale of data: We do not sell portfolio data; we share only with processors needed to run the service (see Privacy Policy)
Security Best Practices
We follow industry best practices for security, including regular dependency updates, automated vulnerability scanning, and secure coding guidelines.
Security Questions?
If you have any questions about our security practices or discover a potential vulnerability, we'd love to hear from you.