Data security in your portfolio tracker: your financial data deserves real protection
Portfolio and wealth data are among the most sensitive things you manage online. Here's how Planafolio handles it.
Security
Your financial data deserves real protection
Portfolio and net-worth data is sensitive. Planafolio treats it accordingly.
Credentials and backups encrypted
Broker credentials and 2FA keys with AES-256-GCM, passwords stored only as bcrypt hashes, backups with AES-256, every connection over TLS.
No product sales
Planafolio sells neither financial products nor your data. Your portfolio data never goes to an advertising partner; ad measurement only with your consent.
Servers in Frankfurt
The application and database run at OVH in Frankfurt. Which service providers (e.g. payments, email) process data is listed in the privacy policy.
Clear terms
Cancel online, no reason needed — monthly plan cancellable each month, yearly plan at the end of its term.
In detail
Concrete safeguards
Not just promises — these are the technical measures behind them.
Every connection to Planafolio runs over HTTPS (TLS). Via HSTS your browser remembers to only open the site encrypted.
Passwords are stored exclusively as a bcrypt hash, never in plain text.
API keys for automatic broker or crypto sync are stored encrypted with AES-256-GCM.
The secret behind your two-factor codes is stored encrypted with AES-256-GCM. A database dump on its own is not enough to generate valid codes.
Database backups are encrypted with AES-256 before they are stored. The additional copy at Cloudflare R2 can't be read without the key; the key is not stored at Cloudflare.
The application and database run on an OVH server in Frankfurt am Main. An encrypted backup copy is additionally kept at Cloudflare R2.
For automatic sync, Planafolio only calls read-only endpoints of your broker or exchange and has no function for trading or withdrawals. Use only API credentials with read permissions. For Binance, Coinbase and OKX, Planafolio checks the key's permissions automatically and rejects keys with trading or withdrawal rights; for all other providers, the permissions you grant are not checked automatically.
Optional for email-and-password sign-in, enabled in account settings (TOTP) — an extra layer of protection against compromised passwords. If you sign in with Google, your Google account's two-factor setting applies instead — if you have enabled it there.
The application accesses your data through its own database role without superuser rights. Superuser rights are reserved for maintenance and backups.
Session cookies are set httpOnly and secure and expire automatically — scripts in the browser can't read them, and they are only sent over HTTPS.
Planafolio is funded by the Pro subscription, doesn't sell your portfolio and wealth data and doesn't pass it to any advertising partner; ad measurement only runs with your consent.
You can report security vulnerabilities directly and confidentially — reports are handled promptly, before any details are published.
In case of an incident
How Planafolio handles security incidents
No system is completely secure. For a personal data breach, the GDPR sets fixed obligations — and Planafolio follows them.
Information when the risk is high
If a breach is likely to result in a high risk to your rights, Planafolio informs you without undue delay (Art. 34 GDPR).
Secure first, then explain
First, affected access is locked and the gap closed. Then Planafolio discloses what happened.
Reporting to the supervisory authority
Planafolio reports notifiable personal data breaches to the responsible data protection authority, where feasible within 72 hours (Art. 33 GDPR).
Your data
Data export
CSV export of your transactions, dividends and acquisition data is part of Planafolio Pro.
Regardless of plan: you can get access to your stored data (Art. 15 GDPR) and data portability (Art. 20 GDPR) on request to [email protected] — in a structured, commonly used format.
You can delete your account including all data yourself at any time in Settings under “Data”.
Service providers
Third-party services in use
Each provider only receives the data it needs for its task. The binding version is section 6 of the privacy policy.
- StripePayment processing for Planafolio Pro, only when you take out a subscription. Card or bank details never reach Planafolio's servers.
- ResendSending transactional emails (e.g. confirmations, password reset, price alerts) and delivering the contact and cancellation forms.
- Google"Sign in with Google". Google Analytics only runs after your consent.
- RedditMeasuring ads on Reddit (pixel and Conversions API), only after your consent.
- CloudflareContent delivery network and reverse proxy, bot protection (Turnstile) on login and sign-up, and an encrypted secondary backup copy (R2).
- SentryTechnical error reports, processed in Sentry's EU region.
- Market data providersPrices, security identifiers and logos. They only receive tickers, ISIN/WKN or currency codes — no personal data.
- Broker and exchange APIsOnly if you set up automatic sync.
System status
Whether the web app, database, CSV import and email delivery are running right now is shown on the status page — checked automatically.
Contact
Questions about security or found a vulnerability? Write directly — reports are treated confidentially.
Security questions
Frequently asked
Not by default. Holdings can be entered manually or imported via CSV/PDF from your own account statements. If you optionally set up automatic broker or crypto sync, you provide the API credentials needed for that — stored encrypted (AES-256-GCM) and used only to fetch your transaction history on your behalf. Planafolio only calls read-only endpoints and has no function for trading or withdrawals. Use only API credentials with read permissions. For Binance, Coinbase and OKX, Planafolio checks the key's permissions automatically and rejects keys with trading or withdrawal rights; for all other providers, the permissions you grant are not checked automatically.
No. Planafolio sells neither your data nor financial products, and your portfolio and wealth data never go to an advertising partner. Ad measurement only runs if you consent to it. Details are covered in the privacy policy.
Yes. In Settings under “Data” you can permanently delete your account including all portfolios, transactions and profile data. Encrypted backups expire on fixed schedules (14 days locally, 90 days for the off-site copy).
Report it directly via the support page with details about the vulnerability. Responsible reports are treated confidentially and prioritized.