Security

What stands between your records and everyone else.

Verdemar asks you to write down what you are worth. That is a lot to hand to a company you have not heard of, so this page says plainly how it is held, who can reach it, and how you take it back out. Every claim here describes how the thing is actually built.

Signing in

There is no password

Verdemar has never had one. You sign in either with a one-time link sent to your email address, or with your Google account. There is no password to guess, to reuse somewhere it shouldn't be reused, or to find in somebody else's breach, and no password for us to store, which means no store of them to lose.

The email route is checked by Cloudflare Turnstile before it reaches our authentication provider, so an automated attempt to work through a list of addresses does not get that far. The Google route uses PKCE: the code Google hands back is tied to a secret your own browser generated and never sent anywhere, so intercepting the code on its own gets an attacker nothing.

The practical consequence is worth stating, because it moves rather than removes the risk: whoever controls your email account, or your Google account, can reach your Verdemar account. Protect those two the way you would protect a bank login, with a second factor on each.

Who can read your rows

The database decides, not the application

Most software asks the database for data and then filters it in application code. That works until one query somewhere forgets its filter. Verdemar reaches the database carrying your own identity, and policies attached to every table (row-level security, enforced inside Postgres) are what decide which rows come back. Your user id is part of the query the database runs, not a condition the application remembered to add.

So the boundary between two customers is held one layer below the application. A mistake in a page cannot hand you somebody else's holdings, because the page is not what is enforcing it. The key published to your browser (the live-price connection needs one) is not a way in either: it holds no privileges on the tables your portfolio lives in, and every policy that guards a file you have uploaded answers a signed-in identity and nothing else.

Where it lives

Frankfurt and London

Your database is in Frankfurt; the application runs in London. Both are covered by UK and EU data protection law, and your financial data does not leave the EU except where the privacy policy says it does, supplier by supplier.

What Verdemar is not

We cannot move your money

Verdemar is not a broker, a custodian or a payment service. It records what you own; it never holds your money, never moves it, and has no standing instruction anywhere that could. Whatever went wrong here, the failure could not be a transfer.

Third parties

Who else sees anything

We do not sell your data, we do not advertise to you, and there are no analytics or advertising trackers in the app. Browser storage keeps you signed in and caches your own figures so pages load quickly; nothing follows you to other sites.

The suppliers who run the service are named individually in the privacy policy, with what each one receives. Two are worth knowing before you start. When Verdemar estimates how a fund splits across sector, geography and currency, the model is sent the fund's name and identifier and nothing else: not you, not your holdings, not a balance. When you upload a statement to the document reader, Google's Gemini reads the whole document, including whatever name, account number and figures are printed on it; we are on the paid tier, so those documents are not used to train its models.

Market data works the same way. The providers we price against receive the instrument being priced, never who is asking.

Documents you upload

Your statements are kept for a set time, then deleted

The file you upload is your bank or broker statement, so it is treated separately from everything else. It is stored privately, and is only ever readable through a link created for you that stops working after an hour. If you accept the entries it proposed, it is kept for 12 months so you can go back to it, then deleted; the oldest go sooner if your account holds more than 50 MB of them. If you reject the entries, it is deleted straight away. Closing the window without deciding leaves it there so you can come back to it, for no more than 90 days. A document we cannot import is not kept at all.

That is not a promise resting on good intentions: a job runs every day to delete the originals that are past their window, along with any file the database has lost track of.

Getting out

You can take all of it, any day

Export everything whenever you like, in formats that read back in: a backup taken today restores into Verdemar tomorrow. It is not a decorative PDF, and it is the same export whatever is happening to us or to you. It keeps working after you stop paying.

Ask us to delete your account and your financial data goes; backups roll off within 30 days. Because deletion here is immediate, with no quiet grace period in which we keep a copy of your financial history after you have asked us to erase it, closing your account emails you the complete backup as part of closing it. You can also ask for a copy, a correction or an export at any time. It is free, and we aim to answer within 30 days.

The privacy policy is the detailed version of this page, and names every supplier. The Q&A answers what people ask before they start.