Skip to content
Security

Data security in your portfolio tracker: your financial data deserves real protection

Portfolio and wealth data are among the most sensitive things you manage online. Here's how Planafolio handles it.

TLS encryptionNo data salesTwo-factor loginServers in FrankfurtRead-only APIs

Security

Your financial data deserves real protection

Portfolio and net-worth data is sensitive. Planafolio treats it accordingly.

Servers in Germany

Credentials and backups encrypted

Broker credentials and 2FA keys with AES-256-GCM, passwords stored only as bcrypt hashes, backups with AES-256, every connection over TLS.

No product sales

Planafolio sells neither financial products nor your data. Your portfolio data never goes to an advertising partner; ad measurement only with your consent.

Servers in Frankfurt

The application and database run at OVH in Frankfurt. Which service providers (e.g. payments, email) process data is listed in the privacy policy.

Clear terms

Cancel online, no reason needed — monthly plan cancellable each month, yearly plan at the end of its term.

In detail

Concrete safeguards

Not just promises — these are the technical measures behind them.

In case of an incident

How Planafolio handles security incidents

No system is completely secure. For a personal data breach, the GDPR sets fixed obligations — and Planafolio follows them.

Information when the risk is high

If a breach is likely to result in a high risk to your rights, Planafolio informs you without undue delay (Art. 34 GDPR).

Secure first, then explain

First, affected access is locked and the gap closed. Then Planafolio discloses what happened.

Reporting to the supervisory authority

Planafolio reports notifiable personal data breaches to the responsible data protection authority, where feasible within 72 hours (Art. 33 GDPR).

Your data

Data export

CSV export of your transactions, dividends and acquisition data is part of Planafolio Pro.

Regardless of plan: you can get access to your stored data (Art. 15 GDPR) and data portability (Art. 20 GDPR) on request to [email protected] — in a structured, commonly used format.

You can delete your account including all data yourself at any time in Settings under “Data”.

Service providers

Third-party services in use

Each provider only receives the data it needs for its task. The binding version is section 6 of the privacy policy.

  • StripePayment processing for Planafolio Pro, only when you take out a subscription. Card or bank details never reach Planafolio's servers.
  • ResendSending transactional emails (e.g. confirmations, password reset, price alerts) and delivering the contact and cancellation forms.
  • Google"Sign in with Google". Google Analytics only runs after your consent.
  • RedditMeasuring ads on Reddit (pixel and Conversions API), only after your consent.
  • CloudflareContent delivery network and reverse proxy, bot protection (Turnstile) on login and sign-up, and an encrypted secondary backup copy (R2).
  • SentryTechnical error reports, processed in Sentry's EU region.
  • Market data providersPrices, security identifiers and logos. They only receive tickers, ISIN/WKN or currency codes — no personal data.
  • Broker and exchange APIsOnly if you set up automatic sync.
Go to the privacy policy (German)

System status

Whether the web app, database, CSV import and email delivery are running right now is shown on the status page — checked automatically.

Go to status page

Contact

Questions about security or found a vulnerability? Write directly — reports are treated confidentially.

Security questions

Frequently asked

See for yourself, for free.

Start for free