Data security in your portfolio tracker: your financial data deserves real protection
Portfolio and wealth data are among the most sensitive things you manage online. Here's how I handle it at Planafolio.
Security
Your financial data deserves real protection
I know how sensitive portfolio and net-worth data is. So I treat it accordingly.
Stored encrypted
Credentials and holdings are stored encrypted, never in plain text.
No product sales
I don't sell financial products and never pass your data on for advertising or resale.
Hosted in Germany
Servers and backups run on German infrastructure.
No subscription risk
Pro can be cancelled monthly at any time — no minimum term.
In detail
Concrete safeguards
Not just promises — these are the technical measures behind them.
Passwords are stored exclusively as a hash, never in plain text. The connection to Planafolio is TLS-encrypted throughout.
Optional, enabled in account settings — an extra layer of protection against compromised passwords.
Your data is backed up regularly, so a technical failure doesn't mean data loss.
Internally I follow the principle of least privilege: access to user data is restricted to what's technically necessary.
Session cookies are set httpOnly and secure and expire automatically — a stolen cookie can't be read out via JavaScript.
You can report security vulnerabilities to me directly and confidentially — I handle reports promptly, before any details are published.
In case of an incident
How I handle security incidents
Security isn't a one-time checkbox, it's an ongoing process. Should an incident still occur, you have clear rights and I have clear obligations.
Notification without delay
In the event of an incident risking your data, I notify affected users without undue delay, per GDPR requirements.
Containment before communication
The cause is isolated and access is closed off first — transparent follow-up communication comes after.
Reporting to the supervisory authority
Notifiable incidents are reported to the responsible data protection authority within the required deadline.
Security questions
Frequently asked
Not by default. Holdings can be entered manually or imported via CSV/PDF from your own account statements. If you optionally set up automatic broker or crypto sync, you provide the API credentials needed for that — stored encrypted (AES-256-GCM) and used only to fetch your transaction history on your behalf. Trading or moving funds is not possible with these credentials.
No. I don't sell financial products and don't share your data for that purpose. Details are covered in my privacy policy.
Yes. In account settings you can permanently delete your account along with all stored data.
Contact me directly via the support page with details about the vulnerability. I treat responsible reports confidentially and prioritize them.