What your net-worth app can read about you
Every wealth tracker sits in one of four positions, and the position determines what its operator can see. Here is the survey, written to be useful rather than to arrive at a particular conclusion.
· 7 min
Why the business model predicts the answer
You can usually work out what a financial product can see by asking who pays for it, because data access follows revenue. A product paid by advertisers needs to know enough about you to segment you. A product paid by advisor referrals needs to know when your balance crosses a threshold worth a phone call. A product paid by subscription needs only to know that your subscription is current. None of this requires assuming bad intent; it is what the accounts require.
The aggregators, paid by someone other than you
Empower's Personal Dashboard is free and excellent, and it is the entrance to a wealth-management business — that is stated, not hidden. To do its job it connects to your accounts and reads balances, holdings and often transactions. It knows what you earn, roughly what you spend it on, and precisely when you become worth calling. If you are comfortable with that trade, it is a strong product at a price of zero.
The subscription trackers, paid by you
Kubera and Finary are paid by their users, which removes the incentive to monetise what they see. It does not remove the ability. Both hold your figures in readable form on their servers, because both compute on them. Finary reaches your accounts through regulated aggregators rather than storing your credentials directly, which is a meaningful design choice and worth crediting. But the balances land in a database that the company operates and can read.
The crypto trackers, and a different threat model
CoinStats, Zapper, DeBank and their peers do something the others do not: many of them read from public chains, which means an address you give them can be linked in their records to the identity you signed up with. That is a genuinely different exposure from a bank balance, because the chain is public and permanent — a balance from 2019 is gone from a bank's active system and an address's history is not. Most of these tools also accept manual entry, and doing so avoids that specific linkage while leaving the rest of the picture unchanged.
The local-only tools
Rotki is the clearest example: it runs on your machine and nothing is transmitted, which makes the question of what the vendor can read trivially answerable. Nothing. It is open source, so the claim is checkable rather than taken on trust. The cost is that it runs where you installed it — one machine, your own updates, your own backups — and that is a real cost that filters out most people who would otherwise want it.
Where we sit, since you are reading this on our site
Vault encrypts every figure in your browser before it is sent, under a key derived from a phrase we never receive. What our server holds is ciphertext, row identifiers, dates and record types. We can tell that an account exists, who it belongs to, that it holds crypto and property, and when a row last changed. We cannot tell you what any of it is worth, and neither can anyone who takes the database. We are not local-only, which is a weaker position than Rotki's, and we say so on the comparison page.
The question to ask, whichever you choose
If you lost every credential and every recovery method, could the company show you your figures again? Yes means they can read them. No means they cannot. Everything else on a privacy page is commentary on that one answer, and it is the same question whether the product is free, paid, connected or manual.
There is no universally correct choice here — there is a trade between convenience, coverage and exposure, and different people should land in different places. What is not defensible is not knowing which trade you made.