Version date: 2026-08-03
The controller for the processing of your personal data is:
⟨Anbietername eintragen⟩
⟨Ladungsfähige Anschrift eintragen⟩ Email: ⟨Kontakt-E-Mail eintragen⟩
No data protection officer has been appointed; none is required by law. Please address enquiries to the above.
The service runs on a server administered by the provider itself, in a data centre in Germany (operator: netcup GmbH). The database is operated by the provider itself.
No managed database or backend service that could read your data in clear text is used — deliberately. The aim is to keep the number of parties able to read your data as small as possible.
Transmission between your device and the server is encrypted in transit (HTTPS) without exception. Credentials for bank and broker interfaces are additionally encrypted at rest (see section 4).
Account and sign-in data: email address, display name, first and last name, country, language, avatar selection, password only as a hash; where two-factor authentication is enabled, the encrypted shared secret and the hashes of the recovery codes; the times of creation and last sign-in.
Session and security data: session identifier (as a hash only), IP address and browser identification at the time of sign-in, timestamps, failed attempts for rate limiting, and acceptances of the legal texts with time, IP address, browser identification and a checksum of the wording displayed.
Content data: everything you record or import into the service — transactions, holdings, valuations, ideas, decisions, notes and comments, uploaded research documents and the analyses derived from them.
Bank and broker connection data: interface credentials you store yourself. PINs and TANs are not stored.
Server logs: technical logs of the web server and the application for troubleshooting and attack detection.
Processing for advertising purposes, any sale of data and any cross-mandate evaluation of your content do not take place.
Hosting: netcup GmbH, Germany — operation of the servers. Processing on behalf of the controller under Art. 28 GDPR.
Email delivery: ⟨Mailjet — enter the exact contracting entity (company, registered seat) and the status of the data processing agreement⟩. Transmitted are your email address and the content of the respective message. The content of transactional messages is limited to a link, its expiry and one sentence of context — no portfolio data.
Market data providers (including Yahoo Finance, Finnhub): to update prices and metrics the server retrieves data from these providers. This transmits security identifiers and the server's IP address — not your identity, not your holdings and not your quantities. Your own IP address is not transmitted, because the retrieval originates from the server, not from your device.
Your bank or broker where you set up a connection: transmitting your credentials to that institution is a necessary part of the retrieval you trigger. The institution is the controller for the processing that takes place there.
Public authorities, insofar as we are legally obliged.
As matters currently stand, no transfer to countries outside the EU and the EEA takes place.
The service sets a single cookie: the session identifier after sign-in. It is technically necessary, becomes invalid on sign-out and serves no analytical purpose.
There is no tracking: no analytics services, no advertising networks, no embedded external fonts, maps or scripts. There is therefore also no cookie consent banner.
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21 GDPR). Any consent given may be withdrawn at any time with effect for the future.
Please write to ⟨Kontakt-E-Mail eintragen⟩. While the self-service functions for export and deletion are not yet available, we handle such requests manually within the statutory period of one month.
You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your residence, place of work or the place of the alleged infringement. The authority responsible for us is: ⟨enter the competent data protection supervisory authority⟩.
No automated decision-making producing legal effects or similarly significant effects within the meaning of Art. 22 GDPR takes place. The scores, rankings and colour codes shown in the service are evaluations of your own inputs, not a decision about you; see no investment advice.
Providing an email address and a password is necessary to create the account. All further details are voluntary; without them individual functions are unavailable.
This policy is adapted when the processing changes. An amended version is presented to you at your next sign-in.