Skip to main content
Investing Dividend Tracker
Security

How your data is protected

A plain-English description of the controls actually in place, and an honest list of what we do not claim.

No broker credentials

We can't access your accounts because we never connect to them.

Private by default

Access control is enforced in the database, not just the interface.

No card data

Paddle handles payments end to end as merchant of record.

The smallest possible security surface

The single biggest security decision in this product is what we chose not to build. There is no broker connection, no open banking link and no read-only API key storage. Holdings are entered by hand. That means a compromise of this service could never be used to move money or place a trade in your accounts, the credentials simply do not exist here.

Access control

  • Every portfolio, holding, dividend record and note is scoped to the account that created it.
  • Access rules are enforced at the database layer with row-level security, so a bug in the interface cannot expose another user's data.
  • Community features publish only what you choose to publish, and support anonymous posting with a masked identity.
  • Administrative access is role-based and separate from ordinary accounts.

Encryption and infrastructure

  • All traffic is served over HTTPS with modern TLS; the app is not reachable over plain HTTP.
  • Data is stored in a managed, access-controlled Postgres database with encryption at rest.
  • Passwords are salted and hashed by our authentication provider, we never see or store them.
  • Sign-in with Google is supported, so you can avoid holding another password entirely.
  • Automated backups are taken by the managed database platform.

Payments

Subscriptions are processed by Paddle acting as merchant of record. Card numbers, billing details and tax handling stay with Paddle; we receive only a subscription status. Nothing card-related is stored on our side.

Your control

  • Export your data at any time from the account page.
  • Delete your account and its data from the account page.
  • Turn email notifications off without losing access to the app.
  • Post to the community anonymously, or not at all.

What we don't claim

We do not hold ISO 27001, SOC 2 or any equivalent certification, and we are not an authorised financial institution. We are a small independent software product, and we would rather say that plainly than imply assurance we cannot evidence.

Found something that looks wrong? Report it through the support page and we will respond. See also our privacy policy and data & methodology.

Frequently asked questions

Do you connect to my broker or bank?

No. There is no broker, bank or open-banking connection in the product. You enter holdings manually, so we hold no credentials that could be used to access your money.

Can other users see my portfolio?

No. Portfolio and dividend data is private to your account and enforced at the database level. Only what you explicitly choose to share, such as a payout post, is visible to others, and you can post anonymously.

Do you store my card details?

No. Payments are handled entirely by Paddle, our merchant of record. Card details never reach our servers.

Can I delete my data?

Yes. You can delete your account from the account page, which removes your holdings, dividend records and profile.

Are you certified to a security standard?

We do not currently hold a formal certification such as ISO 27001 or SOC 2, and we will not claim one we do not have. The controls described on this page are what is actually in place today.

Ready to get started?

Free forever to start. No credit card required.