Publisher: WM STUDIOS. Last updated: 21 August 2026. This page describes data properties and architectural choices. It is neither investment advice nor legal advice.
What a portfolio reveals about you
Take the detail of a portfolio and its movements over a few years. Without any field being called « profile », a great deal can be read from it.
- The level of wealth, and how it has progressed over time.
- Income, from the regularity and size of contributions.
- An employer, when shares arrive through a share award.
- Family circumstances, from the number and nature of accounts opened.
- Life events: a property purchase, an inheritance, an exceptional expense all show up in the flows.
- Habits: how often transactions occur, at what hours, and the periods of inactivity.
None of this was declared. All of it is inferred. That is what makes this kind of document particular: its informative value goes well beyond what it literally contains.
Three properties that change everything
It is cumulative. A snapshot says little; a history says a great deal. The value of a portfolio stored somewhere therefore grows with time, without anyone having to act. What is deposited once keeps gaining precision.
It is not revocable. A compromised password is changed in a minute. Wealth is not. You cannot rotate your investment history, nor undo the fact that it was readable at a given moment. That asymmetry is the most important point on this page.
It is made of quasi-identifiers. A portfolio is almost always unique: the combination of holdings, quantities and dates is enough to distinguish one person from nearly every other. That is not a technical footnote, and it is what makes the notion of anonymity more fragile than it looks.
« Anonymised » does not mean what people think
The two words are often used interchangeably, although the law separates them clearly.
Pseudonymisation replaces an identifier with a code: it reduces risk, but it is reversible, and pseudonymised data remains personal data under the GDPR. Anonymisation requires re-identification to become impossible in practice. The threshold applied by the CNIL, the French data protection authority, is a re-identification risk that is not insignificant: as soon as tracing the person back does not require unreasonable effort in time, cost and means, the data is not anonymous.
Applied to a portfolio, that criterion is demanding. Removing the name from a set of quasi-identifiers does not anonymise it: one other dataset is often enough to cross-reference. The CNIL gives the example of a database of addresses, which cannot be treated as anonymous once other databases hold the same addresses alongside identities.
The useful conclusion is not that one should be wary of any particular processing. It is simpler than that: the best protected data is the data that was never transmitted.
What « local first » means, and what it does not
The phrase deserves to be pinned down, because it is sometimes used in absolute terms when it never quite is.
What it does mean. Data is stored on your device, and processing happens there: valuation, cost basis, taxation, projections. There is no account to create, so no user database, and nothing to ask a server for in order to read your own portfolio. A local first application also works offline, because its calculations depend on no remote service.
What it does not mean. It does not mean « no connection ». A portfolio tracker needs prices, which necessarily come from outside: the request transmits security identifiers, which is still information, even though it carries no quantity and no identity. If an AI analysis feature is enabled, it sends the relevant data to the provider you chose. And activating a paid licence means verifying that licence with the publisher, once.
Saying « no servers at all » would therefore be false, and a false promise is worth less than an accurate description. The correct wording is more modest and more verifiable: the calculations are local, and the outbound calls are limited, enumerable, and triggered by you.
The price of this choice, which you should know up front
This architecture is not free, and presenting its advantages without its trade-offs would be dishonest.
Backing up is on you. Since nothing is stored remotely, nobody can restore a portfolio lost along with the device. There is no spare copy elsewhere. Exporting regularly is not an optional precaution; it is the condition of the model.
There is no « forgot my password ». When data is encrypted locally with a secret only you hold, losing that secret means losing the data. That follows directly from the publisher holding nothing: it cannot unlock what it cannot read.
Synchronisation is not automatic. Moving between devices takes an explicit step, a backup file or a direct transfer, where remote storage would have made it invisible.
What encryption at rest adds, and what it does not
Encrypting data on the device protects against one specific and common scenario: losing or having the hardware stolen, or someone accessing the file without going through the application.
It does not, however, protect a device that is already compromised while you are using it, since the data must be decrypted in order to be displayed. Encryption at rest solves a problem of storage, not a problem of use. Presenting it as general protection would be an overstatement.
The regulatory angle: collecting less means less surface
The GDPR sets out minimisation as a principle: personal data collected must be limited to what is necessary in relation to the purposes pursued (art. 5(1)(c)).
A local architecture addresses that principle upstream rather than downstream. The usual debate concerns retention periods, access rights, security measures and subprocessing. All of those questions remain legitimate, but they only exist for data that was actually collected. Data that never leaves the device has no retention period to define, no recipient to declare and no possible leak at a third party.
That is the difference between a policy and an architecture. A policy commits to what will be done with data; an architecture decides what can be done. The second is verifiable, the first asks for trust.
How PulseMyPortfolio applies this choice
Your holdings, transactions, amounts and API keys stay on your device, and every calculation happens there. No account is created, and none of that data passes through our servers, of which we hold no corresponding database.
Outbound calls are enumerated rather than glossed over: prices, from a market data provider that only ever receives security identifiers; AI analysis if you enable it, with the provider whose key you supply; and the first activation of a Pro licence, which verifies the key and registers the device. Details are in the privacy policy.
The trade-offs described above apply in full: backing up is on you, and a lost vault secret cannot be recovered by us.
Sources
- CNIL, anonymisation of personal data: distinction from pseudonymisation, re-identification criterion. In French.
- CNIL, identifying personal data: the notion of quasi-identifier and cross-referencing. In French.
- GDPR, article 5: principles relating to processing, including minimisation.
Further reading
The privacy policy sets out, item by item, what leaves the device and why. The frequently asked questions answer the most common queries on this point.