Transparency: what only you can read
Everything privacy-sensitive is readable by you alone. Your amounts, your notes, your investment cases and your strategy are encrypted with a key tied to your password. I don't have that key, so I cannot read any of it. The one exception is the server copy, which is off unless you turn it on yourself. I keep your portfolio on one server in Frankfurt, and not all of it is encrypted. Below is what an administrator with database access can and cannot read without your key. The privacy policy is the formal version; this is the readable one.
Who I am
Dyon Beaart, a freelance developer in the Netherlands. I build and run Foliotron on my own: no employees, no investors, no data partners. Questions go to hello@foliotron.com, and you get an answer from me.
Password, recovery code and key
It helps to keep these three apart:
- Your password. It lives in your head. Your browser never sends it on. It works out a code that cannot be turned back into your password, and sends only that. So your password never reaches my server, not even by accident in a log file.
- Your recovery code. A 32-character code shown to you once, when your account is created. Write it down and keep it somewhere safe. It is there for the day your password is gone.
- Your key. The app makes it itself, at random, in your browser. You never see it and you never type it. It is what locks your data. The server keeps two copies of it, both locked: one opens with your password, the other with your recovery code. The password and the recovery code themselves I keep nowhere.
Log in on a new device and it fetches the first copy and opens it with your password. Change your password and that copy gets a new lock. Nothing about your data changes.
What is encrypted
- Quantities, prices, fees and amounts on every transaction, your cash movements and balances, and the records that come out of an exchange connection.
- Your notes: on an instrument, on a platform, in your research and in the articles you save.
- Your investment cases, including every saved version and the reason you wrote alongside a change.
- The strategy and description of every portfolio.
- Your AI documents and your conversations with the assistant.
- The API keys you enter for an exchange or an AI provider. Those sit behind your key, not behind a key of mine.
What stays readable
This is the honest core of this page. The shape of your portfolio stays readable; the numbers do not. That shape is your history too: a position you sold does not disappear from it.
- Dates and types. That you bought something on 3 March, and that it was a purchase and not a dividend.
- Which instrument, which platform. So: that you hold, or once held, ASML at DEGIRO, and whether you still hold anything meaningful in it. Not how much, not at what price, and not what it is worth now or ever was.
- Names and labels. The names of your portfolios, platforms and accounts, your tags, and the title and link of a research note. That title sits in the note's URL, so it cannot be locked. The note underneath it is.
- Your reminders. Title, text, date, instrument and price threshold.
- The composition of your own benchmark.
- Your settings and preferences.
- Images you upload. For now they stay as they are, so a screenshot of a statement is readable even when the note around it is not. Encrypting your uploads is planned; until that lands, anything you would rather not have seen is better typed out than photographed.
Where your data lives
- On my server (AWS, Frankfurt, EU): your account (your email address, and the code your browser works out from your password, stored in a form that cannot be turned back), the two locked copies of your key (three if you turn on the server copy), and your portfolio: platforms, transactions, cash balances, dividends, research, reminders, tags and settings. Encrypted or readable per row, according to the two lists above.
- Only in your browser: the file you import from your broker. It is read on your device; only the resulting transactions are sent to the server. The file itself is never uploaded, unless you attach it to a support report yourself; then I delete it after at most 30 days.
- In backups (AWS, EU): a nightly copy of the database, plus a daily snapshot of the whole server. What is encrypted in the database is encrypted in the backup too: a backup in the wrong hands yields no amounts and no notes. Both expire on their own within 30 days. Delete your account and it is gone from every backup at most 30 days later.
What I can and cannot see
- No portfolio view. My admin interface has no view of any user's portfolio and no way to log in as another user. What it does show: accounts (email address, when created, last login), overall counts (users, transactions, instruments), error logs, background-job status, and the feedback you send.
- Error logs. When something fails, a log line records the technical context: which account, which instrument, what went wrong. Those lines contain no amounts or quantities, only enough to trace what failed.
- Direct database access. I can open the database directly, for backups, repairs and upgrades. Your amounts and notes sit there as encrypted text and I do not have the key, unless you have turned on the server copy. What I do see is the list under "What stays readable".
- While you are in the app. When you interact with the app, your browser sends the key along, so the server can unlock your data for that request. As soon as the request is handled the key is gone on the server side, except for an exchange synchronisation that request started: that keeps it for the few minutes it runs, even if you close the tab. After that the same holds: it is stored nowhere, and there is no screen and no script that shows it to me.
- What remains. I run the software. Whoever changes the code could intercept the key at the moment you log in. Encryption does not protect against that, in any tool, not at your bank either. What encryption does do: a backup, a stolen server or a look at the database yields nothing.
The flip side
Encryption I cannot get around is also encryption I cannot get around on your behalf.
- Gone is gone. Lose your password and your recovery code and have no server copy turned on, while logged in nowhere, and you no longer have access to the encrypted data. There is no way to recover it then, other than searching very hard for your password or recovery code. Recovering then makes a fresh key and deletes all unreadable data. That asks for confirmation three times, and it is stated when your account is created.
- Password gone, recovery code in hand? Then nothing is lost: the reset email sets a new password, you type your recovery code, and your key moves across with it.
- Both gone, but still logged in on your phone? Open the reset email on that phone, because that device holds your key. Note: on an iPhone a link from Mail opens in Safari, which is separate from the app on your home screen.
- Everything happens when you open the app. Settling dividends, updating connections and applying splits can only run while you are there. Stay away for a month and that month is caught up on your next visit.
- Reminders do still fire while you are logged out, because their date and instrument are readable. The email names the date and the dividend per share, never how much of it you hold.
- I cannot quietly repair anything. A repair to your amounts can only happen while you are in the app.
If you want an MCP assistant to read along
Connect your own AI client over MCP (Claude, ChatGPT or another) and it reads only what you allow on the consent screen, and it does not have your key. Without the server copy it sees the structure only: which assets you traded and when, names, dates and reminders. Amounts and texts arrive empty, marked as encrypted, whether or not you are in the app. If you want an assistant to read your amounts and notes too, there is one switch for that: the server copy below.
If you turn on the server copy
What it is. Foliotron then keeps a copy of your key on the server, locked with a key of the server's own. This is off by default and you have to turn it on yourself.
What it gives you. The connected MCP assistant has access to all your Foliotron data. You can now, for example, have ChatGPT or Claude read and discuss all your holdings, notes, research and investment cases directly. Where you allow it, an assistant can write as well: your investment case and a review on it, a research note, the note on a holding, your strategy, and create, snooze or complete a reminder. Every write is kept as a version marked “via MCP”. Another benefit is an extra layer of protection against losing your data in Foliotron: if you lose both your password and your recovery code, the reset email is enough.
What it costs. Whoever can get into your mailbox can replace your password with the reset email and keep your data. And whoever has full access to the running server can open your data. Even then I have no direct access: there is no screen, no overview and no script that lets me look at your amounts or notes, and in the database they stay encrypted text. The app uses the copy for two things: your assistant and your reset email. Looking in takes three things at once: the database, the server's key, and software that would have to be written for it. I am the one who could write it. That is the whole difference: with the copy off I cannot, with the copy on I do not. A backup or a stolen disk yields nothing even with the copy on: the server's key is not stored readably there.
On and off. Under Settings, Account or Settings, AI. Turning it off deletes the copy at once. Your data stays as it is, a connected assistant sees only the structure again, and the reset email can no longer bring your data back.
What sits outside the encryption
- Files you attach to a support report yourself, such as a CSV or a screenshot. You send those deliberately, and I delete them after at most 30 days.
- Error logs (without amounts), email delivery records, login events and waitlist data.
What leaves the server
- Price providers (Yahoo Finance, CoinGecko): only ticker symbols. Never who holds what, never quantities.
- Email (Mailjet, EU): your address and the content of the emails Foliotron sends you, such as reminders and alerts. No amounts, and no open or click tracking.
- AI providers (Anthropic, OpenAI or Google): only if you enter your own API key and turn AI on. Then, per question, the assistant receives the data it needs to answer: the positions, notes or transactions you ask about. Those are opened with your key for that purpose, on your request, and go to the provider you chose. Your key is used for your own requests only; I never use it for my own checks.
- Exchanges you connect (Kraken, Bitstamp, Bitfinex, Bitvavo, Iconomi, eToro): requests are signed with your read-only key, which is opened with your key at the moment the connection runs. Nothing about your Foliotron account goes to the exchange.
- External AI assistants over MCP (Claude, ChatGPT and others): only after you approve the connection yourself. Reading and, where you allow it, writing; amounts and texts only with the server copy on, and you can revoke it under Settings → AI.
What I never do
- I do not sell your data, and I never use your financial or portfolio data for advertising or for third-party marketing profiles.
- I do not run third-party analytics or tracking scripts. I do count general usage actions ("viewed the dashboard", "created a transaction") in my own database to see which features are used; no page URLs, no session recordings.
- I do not give investment advice and I do not make automated decisions based on your data.
- I do not track whether you open an email or click a link.
What you can do
- Keep your recovery code. That is the only homework this setup gives you, and it is the only way back if your password is gone.
- Delete everything. Ask me at hello@foliotron.com; I erase your account and all its data within 30 days.
- Check the details. The privacy policy lists every data category, retention period and external service, and says per category whether it is encrypted.
- Ask, or report something. If something here is unclear, you want to know more, or you found something that looks wrong, write to me; security reports go to the same address.