Trust
Security and data practices
A clear summary of how the app handles your data — what is protected, what is manual, and what we do not claim.
Total Wealth Tracker operates in personal finance, a high-trust category. This page summarizes security-relevant facts aligned with our Privacy Policy and the current product.
Manual tracking model
- The app does not connect to broker, exchange or bank APIs
- You enter and update platform totals yourself
- No live ticker feed is required for the core product model
Cloud account & transport
- Connections to our API use HTTPS (TLS)
- Passwords are stored as secure one-way hashes — never in plain text
- Account and portfolio data are hosted on EU-based servers
What we do not claim
We avoid absolute marketing language such as “100% secure” or “bank-grade encryption” unless a specific control is implemented and documented. In particular:
- Portfolio data is not currently encrypted at rest on our servers
- Technical backups are not encrypted and may retain residual copies for a limited time after account deletion
- Local app storage is not encrypted by the app itself (your device OS may still protect locked-device storage)
- Two-factor authentication is not available in the current product
- We do not claim independent security audits unless published
Privacy controls in the app
- Amount masking on Overview
- Email verification for cloud registration
- Workspace roles for shared portfolios (owner, editor, viewer)
- GDPR export and account deletion in Settings
- Optional analytics — Firebase analytics only after in-app consent; no financial amounts in analytics events
Partner sharing
Partner access is voluntary. Invites must be accepted in the app. We are not responsible for disputes between users about shared data.
Reporting a concern
Email contact@totalwealthtracker.com with “Security” in the subject line. For privacy rights, see Privacy Policy section 10.