Security and privacy

What each edition of myTickrs keeps, what leaves your computer, and how to tell us about a problem. The legal version is the privacy policy.

Desktop edition

  • Where your data is: your transactions, holdings and settings are in one SQLite file on your computer (data/tickrs.db in the install folder). There is no account, no sign-in, no telemetry and no server of ours in between.
  • What leaves your computer: only requests for market data. The tickers you hold are sent to the price providers you turn on, such as Yahoo Finance or Finnhub, to get quotes, price history and exchange rates. Your trades, quantities and balances are never sent, unless you choose to import a screenshot or turn on sync.
  • Your market-data keys are encrypted at rest, never shown again after you save them, and tested when you enter them.
  • Sync with the cloud is off unless you turn it on in Settings → Sync. Only then does your portfolio leave your machine.
  • No sign-in means anyone who can reach the app can use it. By default it listens only on your own computer. Don't expose it to a network you don't trust.

Cloud (mytickrs.app)

  • Sign-in is with Google or Microsoft only. myTickrs never sees or stores a password, and never asks for a broker login.
  • Your data is kept apart from every other user's by the database itself (row-level security), not only by the app's code.
  • Market-data keys you add are encrypted at rest.
  • Nothing is sold or shared, and there are no ads. The services that process data for the cloud are listed, with what each one receives, on the sub-processors page.
  • Deleting your account (Settings → Profile) deletes your data.

AI import

When you import a screenshot, it is sent to the AI model (Anthropic's Claude) only to read the holdings on it, and it isn't saved. CSV, JSON and XML files whose columns are recognized are read without AI; for a file with unknown columns, only its column names and first rows are sent. You check every row before anything is saved.

This website

mytickrs.com sets no cookies and loads no third-party scripts, fonts or embeds. If you pick a light or dark theme, your browser remembers that choice; it is never sent to us. It counts page views with Cloudflare Web Analytics, which uses no cookies and keeps no personal data. Links into the app carry a short tag (such as ref=com-hero) so we can tell which page brought a sign-up.

How it's built

myTickrs is built by one person, with AI coding agents helping with the coding. Every change is reviewed and must pass the automated tests before it ships; the calculation engine, the storage layer and the API each have their own test suites. The code is public on GitHub, so you can read exactly what it does with your data.

Reporting a problem

If you find a security problem, please email admin@mytickrs.com rather than opening a public issue. Say what you found and how to reproduce it; you'll get a reply. For anything else, open a GitHub issue.