Don't take our word for it.
Watch the journey.
Your most sensitive data is protected by architecture, not promises. Follow a record from your device to the cloud and back — hover any stage to see exactly what happens to it.
The path of one record.
Hover or tap a stage. Nothing leaves your device until it's already encrypted.
It starts — and stays — local.
Your portfolio, journal, notes and any broker/exchange API keys are written to local storage on the device you're using. This is the only place the plaintext ever exists in a form anything can read.
The key comes from your passphrase — and never leaves.
An encryption key is derived from your passphrase on your device. Your passphrase is never uploaded, and neither is the key derived from it. If you lose your passphrase, we cannot recover your end-to-end encrypted data — because we never had the means to.
Sealed with AES-256, on your device.
Before a single byte is sent, the record is encrypted on your device with AES-256. What leaves is a sealed envelope. The plaintext never crosses the network.
Only ciphertext travels.
The payload on the wire is ciphertext plus the minimal metadata needed to route and version it — timestamps and record identifiers. Without your key it is unreadable.
enc:v1 · 9f2a7c…e14b · aes-256-gcm · nonce=…
The server stores what it cannot read.
Our servers store the encrypted blob. We do not hold the key needed to decrypt it, so we cannot read your synced portfolio, journal, or API keys. The server's answer to "can you read this?" is false.
Decrypted only where you hold the key.
On your other device — where your passphrase can derive the same key — the envelope is decrypted locally. The plaintext reappears only on hardware you control.
Five properties, by design.
Plaintext never leaves
Encryption happens on your device before upload. The network only ever carries ciphertext.
Server stores ciphertext
We store encrypted blobs and minimal routing metadata — never readable content.
Passphrase never uploaded
Your passphrase and the key derived from it stay on your device. We can't recover them — or your data — if you lose them.
Device revocation
Remove a device from your account to stop it syncing. See your active devices in the app.
Key rotation
Change your passphrase to re-key your encrypted data, so old keys no longer apply going forward.
Broker keys stay put
Broker/exchange API keys are stored on-device and are never used to place real-money trades. Draft-only, always.
What we don't claim.
No system is perfectly secure. You are responsible for protecting your device, your credentials and your recovery keys. We use standard, well-understood cryptography — we don't invent our own, and we don't claim certifications we don't hold.
Payments are processed by Stripe; we don't store your full card details.
Responsible disclosure
Found a vulnerability? We want to hear from you. Email security@buildyourpocket.com and give us a reasonable chance to fix it before public disclosure.
Privacy or data requests: privacy@buildyourpocket.com. See the privacy policy and encrypted sync.
Security you can watch, not just trust.
Local-first, end-to-end encrypted, draft-only. Open the app and turn on sync when you're ready.
