Frequently Asked Questions

General

Three things: your data is end-to-end encrypted and never pulled from your bank, the analytics go where most trackers stop, and anything you can put a price on is trackable — not just listed securities.

Imports run through CSV, paste or manual entry rather than Plaid, and metrics like FX attribution and specific-lot cost basis apply to real estate and private equity as readily as to stocks. Read how Capitally compares against the field.

Capitally is built for the investor who outgrew a spreadsheet but wants to keep its control. It computes time-weighted and money-weighted return, FX attribution between capital gain and currency gain, FIFO / LIFO / Average Cost / specific-lot cost basis and options Greeks, and refreshes prices with no formulas to maintain.

Your data stays yours — exportable to CSV or Excel anytime, end-to-end encrypted on your device. The spreadsheet-alternative page has the full comparison.

Capitally is built for long-term DIY investors running their own money across several brokers, currencies and asset classes who want the math behind every number — the right fit once you have outgrown a spreadsheet but don't want to lose the control it gave you.

Best for advanced DIY investors (TWR vs MWR, FX attribution, specific-lot cost basis), HNW investors (several entities, private equity beside public markets), expats (one base currency, local record intact) and FIRE investors (forecast income, yield-on-cost). How it compares.

Capitally works in any country, with 130+ currencies available for cash, transactions and reporting. Native pricing covers stocks and ETFs from 50+ exchanges across North America, Europe, APAC, South America and the Middle East, plus mutual funds (US, Canada, Western Europe), precious metals, crypto, indexes and commodities — see the supported markets and assets.

Anything without a public quote, such as a local fund or a private holding, goes in as a custom asset priced by hand.

Yes, for portfolio tracking and analysis. You keep the data control that made you choose a spreadsheet — export everything to CSV, Excel or JSON any time — without maintaining formulas, price lookups and FX conversions by hand.

Yes. Three routes, depending on what your old tool exports: paste rows from a spreadsheet, import a CSV or Excel file, or rebuild from broker statements. Built-in presets cover Sharesight, Snowball Analytics, Portfolio Performance, Delta, myFund and StockMarketEye; anything else — Kubera, Empower, your own sheet — goes through the column mapper, which saves the mapping for next time.

Importing Data walks through all three. Missing a preset? Send a sample export to support@mycapitally.com.

No — and that is architecture rather than backlog: every project is encrypted on your device, so Capitally's servers hold ciphertext and have nothing to serve.

Exports return the data an API would, in three shapes: a full export of everything you have put into the app, a selective export of just the rows you pick, or a history export covering only what changed since the last one — as JSON, CSV or Excel. See Is there an API?

Subscription

Capitally is a paid subscription — there is no permanent free tier. The 14-day trial is fully featured, takes no credit card, and runs on whichever plan you're considering.

Pricing rises as features expand, and subscribing locks in today's rate for as long as the subscription stays continuous — lapse, and you resubscribe at the new one. Subscription and billing covers renewals, invoices and plan changes.

Yes, in Settings → Subscription — no email, no support ticket. You keep the plan to the end of the period already paid for, and can reactivate before that date. On the 14-day trial there is nothing to cancel: it takes no card and ends by itself.

Nothing is deleted when you leave, plan switches are prorated, and your price stays locked to the day you subscribed as long as it runs unbroken. Subscription and billing covers billing, Account and login retention and deletion.

Yes. An invoice is emailed after every payment, and past ones stay in Settings → Subscription. Add your Tax ID at checkout for a company name and VAT number — Subscription and billing.

The Captain plan, which also covers value-based pricing, stock options and lot groups. Every plan starts with a 14-day free trial with full access — no credit card required. See Tracking Private Equity for what's covered.

The Navigator and Captain plans have no limit on transaction history; Sailor covers up to 25 years. Either way the whole history is recalculated from current market and FX data, so long-term TWR and IRR reflect each trade's real environment. Subscription & billing lists the per-plan limits.

Normally no. The 14-day trial exists so you can test everything before paying, and once you have, purchases are final. Two windows are the exception: subscribe before those 14 days since your trial started have elapsed and you can have that payment back within the same window, no questions asked; a renewal that took you by surprise can be refunded within three days of the transaction. Ask at support@mycapitally.com — details in Subscription and billing.

Nothing is charged, and there is nothing to cancel. The 14-day trial takes no payment details at all, so there is no card on file and no way to bill you — on day 14 the account simply goes inactive.

Your data stays end-to-end encrypted and available for at least 6 months, so subscribing later restores the full history with nothing to rebuild. Account and login covers exporting everything first, or deleting the account outright.

Tracking Wealth

Upload a CSV or XLS export from your broker — most major brokers have a native import preset, and the flexible importer maps the columns of any other file. You can also paste from a spreadsheet, add transactions by hand, or just keep account balances current if that is all you track.

There is no Plaid-style broker link, by design — importing data walks through every route.

Yes. Paste transactions straight out of Excel, Google Sheets or Numbers and Capitally maps the columns into its transaction model on the fly; CSV and XLS files import the same way. The mapping saves as a reusable preset, so the next paste is one click, and your data exports back to CSV whenever you want.

No. You pick the tracking depth per account or asset, anywhere between a periodic balance update and a full transaction history — a pension as one balance, your IBKR account as every trade.

Balances are quick to maintain but thin for cost basis and tax; transactions unlock realised gains and FIFO / LIFO / average-cost / specific-lot reporting. Add the detail later and the balances reconcile themselves — nothing is lost.

It stays. Your project is kept end-to-end encrypted for at least 6 months after the trial or subscription ends, so resubscribing within that window restores the full history with nothing to rebuild. Permanent deletion is a one-click action inside the app whenever you want it instead.

Either way, export everything to CSV, Excel or JSON before you go, so the full record stays with you regardless.

Anything you can put a price on. Stocks, ETFs, mutual funds, currencies, crypto and commodities arrive with automatic pricing and dividend data, options with Greeks; cash, bonds, real estate, private equity, collectibles and liabilities are custom assets you value yourself. Depth is per asset: full transaction history, or periodic balance updates.

Market data lists what is priced natively, and Getting Started has a walkthrough per asset class.

Yes. A liability is an asset with a negative quantity: create a custom asset of type Loan or Mortgage and book the borrowing as a Buy with a negative quantity. The Portfolio's Market Value tab then reads Owned, Owed and Debt Ratio side by side.

Tracking Debt has the setup — including loans that price their own interest — and Tracking Mortgage the property side.

Yes. Record them as Other transactions on the asset itself — property maintenance, repairs, insurance, custodian and management fees — so the cost sits in the same ledger as that position's purchases, valuations and income.

A one-off cost goes in as a negative Value; a recurring one goes in the Fee field, which also feeds the Fees metric. Either way it reduces the position's return rather than its invested principal. See Tracking Expenses.

As far back as your broker statements go on the Navigator and Captain plans; the Sailor plan covers 25 years.

Prices and FX rates are rebuilt across the whole imported history, so a position opened in 2004 gets its cost basis and currency impact from 2004 rather than from today. What the plan limits count has the rest of the per-plan limits.

Private equity tracking is for LP fund stakes where you know the price per unit and need capital commitments, calls and distributions with DPI, TVPI and RVPI — see Tracking Private Equity.

Value-based pricing is for managed accounts where you only know the total value and your deposits and withdrawals; you enter the balance and Capitally derives the returns — see Tracking Black-box Investments.

Yes. LP fund stakes, managed accounts, stocks, ETFs, options, crypto, real estate and collectibles live in the same project, and the rollup blends them into one net worth, one base currency and one set of reports.

Each side keeps its own metrics: PE positions report Committed Capital, Paid-In, DPI, TVPI and RVPI, public positions report TWR, money-weighted return / IRR and FX attribution. See Tracking Private Equity for the LP fund workflow.

Yes, for any statement that exports CSV or Excel. Map its columns to Capitally's transaction fields once in Import from a file, save that mapping as a preset, and every later statement from the same provider imports in seconds.

For LP fund statements — capital calls, distributions, NAV updates — use the private-equity workflow. For a managed account that reports only a period-end NAV, use value-based pricing.

Every transaction keeps the currency you paid in — USD trades stay in USD, EUR trades in EUR — and converts into your viewing currency at the trade-date rate, which you can switch whenever you like.

Returns then split into the asset's own capital gain and the currency gain or loss on top, so a 12% USD return that lands as 4% in EUR reads differently from a 12% EUR return. Portfolio metrics defines the split.

Yes. One project holds any number of accounts — personal, company, trust, IRA, ISA, IKE/IKZE — plus the liabilities that finance them, so one net-worth view nets debt against holdings. Every metric works at any level: per account, per filter, or across everything.

When two entities must never appear in the same report, give each its own project — same login, fully isolated data. Projects covers which side of that line an entity belongs on.

From the terms you enter, not from your bank's statement. Set the mortgage up with interest-based pricing — rate, compounding, periods, amortisation — and Capitally generates the accruals and the balance schedule; rate resets, payment holidays and refinancing are dated overrides on the same asset.

Tracking Mortgage has the fixed-rate and 5/1 ARM setups, Interest-based pricing every setting.

Yes — both, on every plan. A short is a position with a negative quantity: sell what you don't hold, buy back to close. Borrowed cash is a custom Loan asset carrying what you owe, margin interest an Interest transaction against it, and the Market Value tab reports Owned, Owed and Debt Ratio.

Tracking Short Positions and Tracking Debt cover both. Margin requirements on sold options need advanced tracking, on the Captain plan.

Yes — three metrics on the Market Value tab. Owned is what your assets are worth, Owed is everything you owe, from mortgages and loans to margin debt and shorts, and Debt Ratio is owed ÷ owned. All three follow whatever you have open: one account, a saved filter, or the whole project.

The chart on that tab plots Owned against Owed over time, with the margin requirement as a third line if you sell options or short stock. See Tracking Debt.

Yes. Put the property and its mortgage in the same account, and the Portfolio's Market Value tab reads Owned (what the property is worth), Owed (what is left on the loan) and Debt Ratio (owed / owned), with the account's own value already net of the debt.

Property valuations are yours to enter — Capitally does not price real estate automatically — while the loan balance moves with every payment. Full walkthrough: Tracking Mortgage.

Yes. A loan or mortgage history goes in through the same file importer as the rest of your portfolio — CSV, XLS, XLSX, XML, JSON or pasted rows — and the column mapping is saved as a preset, so the next statement from the same lender reuses it.

Each repayment becomes one Interest transaction: the interest paid maps to Value, the capital repaid to Amortized Quantity. See Tracking Mortgage for the setup and Import from a file for the mapping.

Yes. A REIT is an ordinary listed position priced from market data like any other equity; a physical property is a custom asset of type Real Estate whose valuations you set yourself. Both sit in one project, measured the same way in the same base currency.

Two catches: a listed REIT is typed as a stock, so Portfolio → Types → Real Estate won't include it — group the two with tags or categories. And property sits outside the Liquid assets filter. Walkthrough: Tracking Real Estate.

Yes. Rent is its own transaction type: on the property asset record a Rent transaction with the rent in Value, tax withheld at source in Tax Paid, and the manager's cut in Fees. Rent, dividends and interest stay separate in the Income tab while feeding the same Yield and Yield on Cost.

Tracking Real Estate covers recording and cloning rent; Tracking Dividends covers what counts as income.

Yes. Each property is an asset in its own currency — a Warsaw flat in PLN, a Berlin flat in EUR — and its valuations, rent, instalments and expenses stay there while the portfolio rolls up into whichever viewing currency you pick.

Returns then split into Capital Returns, which freeze the exchange rate at the opening date, and Currency Returns, the part the rate itself moved. Portfolio metrics covers both.

Yes — and unlike a painting or a watch, bullion prices update on their own. Add gold as XAU or silver as XAG from Capitally's supported currency list, then record each purchase as a Buy at the price you actually paid. Palladium (XPD) is there too; platinum is not.

The one thing to get right is the unit: XAU and XAG are quoted per troy ounce, so a 100 g bar is 3.215072. Tracking Precious Metals has the conversion table and a worked example.

Not as native instruments — there is no futures, CFD or certificate asset type, and market data does not price them. Track them as custom assets, which behave no differently from listed holdings for allocation, returns and cost basis.

Adding custom assets has the pattern, futures example included. A leveraged product on a listed underlying can instead take a price formula like 100 * price.

Tracking Dividends & other Income

Capitally posts them for you. Once it knows which dividend-paying assets you own, each declared payment is pulled from market data with its ex-date, pay-date and gross amount — no broker file needed.

Automatic dividends carry no withholding tax, though, and their pay-date can differ from your broker's. For tax reporting, import the broker file: those records count as confirmed, take priority over the automatic ones, and carry the actual WHT and FX rate. See Tracking Dividends.

Yes. Foreign dividends track exactly like domestic ones, and the withholding tax deducted at source is kept per payment: the dividend value stays gross, the withheld amount goes in Tax paid / withheld, and the net follows from the two.

A broker import fills that field in where the export carries it, and you enter it yourself where it doesn't. See Importing dividends and withholding tax, and Taxes for how tax withheld nets against tax due.

From the last five years of payouts — the next expected dividend is the last one paid, multiplied by the average growth rate over that window. Listed assets use full market history, custom assets the data you entered. Tracking Dividends has the rest.

Not yet. Dividend projections run one fixed model — the last five years of payouts, carried forward at that window's average growth rate — with no per-asset override for growth, payout cuts or DRIP.

The only lever is the underlying series: manually entered dividends feed the same projection, so editing an asset's income history changes what comes out. Scenario modelling is on the roadmap.

Yes. Rent and Interest are transaction types in their own right, sitting beside Dividend — rent for property, interest for bond coupons, deposits, savings and P2P lending — each with its own value, fees and tax paid. Every income metric covers all three: income received, yield, yield-on-cost, growth, next payment date, and the split between them.

Tracking Dividends covers rent and interest alongside dividends, including how future payments are estimated and why one-off windfalls belong in an Other transaction instead.

Yes. Expected dividends appear on the dashboard widget, in the Income tab and on transaction lists as soon as the date range reaches into the future, each with its ex-date, payment date and amount.

Every one is labelled Upcoming, Declared or Estimated, so a company announcement is never mistaken for a projection. Tracking Dividends covers how the estimates are built.

Yes, but only for strategies you actually hold — there is no simulation mode. Give each strategy its own account, then group by account in Portfolio: total return, TWR, IRR, income and yield-on-cost all split out on one chart. An account can also serve as a benchmark, plotting one strategy's return against another's.

Capitally will not model a strategy you have not recorded: forecast income uses one fixed model, with no DRIP switch and no per-asset growth override. See Tracking Dividends.

Yes. Dividends are tracked payment by payment for every supported stock and ETF — gross amount, withholding tax and net, each editable — alongside yield-on-cost, forecasted income and dividend growth. Bond coupons and rental income sit on the same ledger, so DRIP, rental and bond yield compare side by side.

Tracking Dividends is the full walkthrough, including how automatic payments are matched against your broker's report; the dividend-tracking feature page is the overview.

Yes. Capital-gains figures come from a country-specific tax preset that encodes your jurisdiction's cost-basis convention, holding-period rules and exemption thresholds; presets ship for several countries, and you can clone one or write your own for anywhere else. Cost basis is tracked per tax lot, in the currency of each trade, and the results land in the Taxes Due Report by country and year.

Analysing Performance

Not in real time — Capitally is a tracker, not a trading platform. US stocks and ETFs, currencies and crypto refresh at most every 30 minutes during market hours; everything else is an end-of-day close, posted 15 minutes to 3 hours after that market shuts. Market data lists the delay per market.

Custom assets hold your last valuation forward until you enter a new one.

You set the price yourself. Add it as a custom asset — private equity, property, collectibles, a closed fund — and feed in valuations by hand, by paste, or by CSV, as often as you get them.

From there it behaves like a listed position: cost basis, TWR, MWR, FX attribution and yield-on-cost all compute the same way, and dividends, rent or expenses can be logged against it. Between valuations Capitally holds the last price forward, or interpolates if you prefer.

You set the valuations yourself — one value, a handful, or a full price series, in the asset's own currency (four ways to enter one). Capitally carries the last valuation forward until the next, so an asset revalued once a year still shows a value on every day in between.

Rent, maintenance and other costs record separately from valuations and feed into the return. Walkthroughs: Tracking Real Estate and Tracking Collectibles.

Not on individual metrics. A threshold alert — "ping me when AAPL crosses 200" — would need Capitally's servers to read your portfolio, and end-to-end encryption makes your data unreadable to us by design.

What you can schedule instead, in Settings → Notifications, is a recurring digest of your portfolio's performance, daily through monthly. It arrives as a push notification on an installed app rather than an email: your device does the calculation locally, which is the only way the encryption guarantee survives.

Committed Capital, Paid-In Capital, Unfunded Commitment, Funded Rate, DPI (Distributions to Paid-In), RVPI (Residual Value to Paid-In), TVPI (Total Value to Paid-In), and detailed cashflows including inflows, outflows, fees, and income. See Tracking Private Equity for how each metric is calculated and a full LP-fund lifecycle example.

TWR judges the strategy, MWR judges your result as an investor. Time-weighted return strips out when you added or withdrew money, which makes it the fair one to compare against a benchmark. Money-weighted return — also called IRR — includes your cashflow timing, so it tells you what the portfolio actually did for you.

Capitally computes both, plus ROI, for every account and for the whole portfolio, and any of them can be discounted by a benchmark for a real or excess return. Calculating returns has the worked examples.

All three, and three more besides: FIFO, LIFO, HICO (highest cost first), LOCO (lowest cost first), Manual specific-lot identification, and Average Cost Basis with Asset or Asset+Account pooling. Set the method per project, account, asset or position — the most specific wins — or let a built-in tax preset wire the one its jurisdiction requires.

Cost basis methods has a worked example for each, and covers picking individual lots when you sell.

No. Fifteen countries ship with a built-in tax preset — pick yours under Settings → Taxes, assign it to your accounts, and there is nothing to write.

When you do want to change something, the editor is visual: rules are built from point-and-click statements, and every built-in preset was written in that same editor. Programmable presets covers how it works.

If your country is missing or a preset gets something wrong, write to support@mycapitally.com.

Yes — the figures for all four, not the forms themselves. Built-in presets for fifteen countries sort gains, dividends and interest into tax groups named after your return's line items; the Taxes Due Report gives revenue, expense and tax per group. Personal allowances and loss carry-forwards are not applied — each preset's note says what it covers, in Settings → Taxes or the demo project.

Tax Presets covers what ships and how to build one for a country that isn't covered.

Leave the account without a tax preset and it drops out of the Taxes Due Report while still counting towards performance, income and net worth. Assign a 0% preset instead if you want contributions and withdrawals totalled there.

Three ship built in — Konto Emerytalne (IKE, IKZE, PPK, OIPE), 401k or IRA (before tax) and Roth 401(k) or Roth IRA (after tax). Contribution limits are not modelled; Tax presets covers cloning one for a partial shelter.

Yes. The Harvestable Tax metric shows the most tax you could save by closing loss-making positions — a column under Portfolio → Tax Due, and the Harvestable tax bookmark on the Taxable Income Report. To close specific lots rather than the FIFO ones, use Transaction lots to close on the Sell transaction; see cost basis methods.

Treat it as the opportunity, not the filing figure: wash sales are not modelled, and built-in presets apply no annual allowances or loss carry-forwards.

Give each residency period its own account. A tax preset is bound to one country, so the old country's preset runs on one account and the new country's on the other, and both feed the same Taxes Due Report. Move open positions across on the move date with a Convert / Move transaction — it forwards the cost basis rather than realising a gain.

Do not just reassign the preset on the existing account: it carries no date range and would re-evaluate the years before you left too.

Yes. A property is a position like any other, so IRR, TWR and ROI all run on it, and income, yield and yield-on-cost come from the Rent transactions booked against it. A mortgage is a separate position and stays out of the property's own IRR — keep both in one account and the account-level figure is your after-debt return.

Tracking Real Estate and Tracking Mortgage cover the setup; Calculating returns compares the three methods.

Tracking Options

Yes. Because Capitally models option prices rather than pulling them tick-by-tick from an exchange, you can create a custom asset, attach options to it, and have Capitally compute fair value and Greeks (delta, theta, gamma, vega, rho) from its price history. This works even for options not listed on any exchange.

Because Capitally models the price rather than quoting it — Black-Scholes-Merton and Barone-Adesi-Whaley, fed by historical volatility, an average dividend yield and a configurable risk-free rate. A broker quote also carries the bid-ask spread and intraday volatility. See Tracking Options.

Interactive Brokers, Schwab and Swissquote are natively supported today, including multi-leg trades, assignments, exercises and adjusted strikes. Any other broker works through the flexible importer against its CSV or XLS export, or by manual entry — tracking options covers both.

If your broker's format isn't supported yet, send a sample file to support@mycapitally.com and we'll prioritise it.

It estimates them from percentages you set — your broker's own figure is never imported. The Margin Requirement metric applies your percentage to the underlying's market value for a sold call, the strike for a sold put, and the market value of a shorted stock or crypto. Defaults are 25% on sold options and 50% on shorts, editable in Settings → Advanced tracking.

Brokers run risk-based models rather than flat percentages, so treat the number as your own estimate. See Tracking margin requirements.

Yes. Every option contract is a lot under its underlying asset, so Apple calls and puts sit in the same Lots tab as your Apple stock, each row carrying its strike, expiry, contract count and multiplier.

Greeks are per contract, not per portfolio — there is no blended delta-adjusted figure across stock and options. For the dedicated Options tab and automatic strategy grouping, see Tracking Options.

Yes. When a stock split occurs, Capitally automatically adjusts both the quantity and strike price of your option contracts to reflect the split. It will also properly handle both adjusted and unadjusted strike prices when importing transactions.

The Captain plan — it also covers private equity, value-based pricing, lot groups and unlimited projects. All plans start with a 14-day free trial, no credit card required. See the stock options feature page for what's tracked.

Yes — delta, gamma, theta, vega and rho on every contract you hold, as columns on one contract, a strategy, an underlying alongside its stock position, or the whole portfolio.

They come from a pricing model rather than an exchange feed, so they stay consistent over time and work on illiquid contracts and custom underlyings. Tracking Options covers the columns and the pricing inputs.

Privacy & Sharing

Your financial data is end-to-end encrypted on your device with AES-GCM, using a key derived from your password — Capitally itself cannot decrypt it, so a database breach yields unreadable blobs. We never connect to your broker or bank either: no Plaid, no Yodlee, no shared credentials.

We don't sell financial data or behavioural patterns, and product analytics never include the size or value of your holdings. The data safety guide has the full encryption model, EU hosting, and one-click export and deletion.

Yes — by exporting a slice rather than granting access. Select the positions, accounts or transactions you want and export them to CSV, Excel or Capitally's JSON, which carries the underlying assets and accounts with it and re-imports into an advisor's own Capitally project.

Live read-only sharing is on the roadmap. Until then you decide exactly what leaves the encrypted store, and in what format.

No. Capitally never connects to your bank or broker through Plaid, Yodlee, or any other open-banking aggregator — no shared password, no read-only API token, no third party in the data path. Data comes in by CSV or Excel upload, paste from a spreadsheet, or manual entry, with native presets for most major brokers.

That is a precision choice as much as a privacy one, and it means no background auto-sync. Is my data safe? explains both.

Yes. Capitally is built and operated under GDPR: servers and databases sit in EU data centres, and your portfolio data is end-to-end encrypted on your device with AES-GCM, so we cannot read it even if asked.

Export and permanent deletion are both one-click operations inside the app, with no email or support ticket required. Is my data safe? covers the encryption and hosting model; the Privacy Policy is the full legal text.

Yes. Your portfolio is encrypted on your device with AES-256 under a key derived from your password, and the keys never leave your devices — our servers only ever hold ciphertext, so a breached database yields unreadable blobs.

That is the difference between end-to-end encryption and the "bank-level encryption" most trackers advertise, where the provider holds the keys and can read your data. You pick the trade-off per project: User Password, a separate Project Password, or a server-derived Remote Key. Full spec in Is my data safe?

No. Your portfolio is encrypted on your device with a key we never receive, so our engineers, our infrastructure team, and anyone who breaches the database see ciphertext — which is also why a subpoena gets nothing readable.

What we do see is project metadata: the type of each change (transaction created, updated, deleted) and when it happened, which is what sync runs on. Amounts, instruments, account names and your own notes are encrypted before they leave the device. See Is my data safe?

In EU data centres — every Capitally server and database sits in European jurisdiction — and what lands there is ciphertext only. Your portfolio is encrypted on your device with a password-derived AES-GCM key before any sync, so the plaintext exists only in memory on your own browser or device.

The data safety guide lists the hosting providers and the server-side practices on top: TLS in transit, encryption at rest, need-to-know access, access logs.

You can reset it with Forgot your password?, but run it on the device you last used the project on — that is the only place the app can re-encrypt your projects to the new password. If a project has its own Project Password, there is no reset at all: the key is derived from it and our servers hold only ciphertext.

Account and login covers the reset flow, and is my data safe? explains the encryption modes and what to check before concluding the data is gone.

No. Server-side AI summaries, recommendations and "insights" need servers that can read your portfolio in plaintext, and ours can't — your data is end-to-end encrypted on your device. The absence is architectural, not a policy we could change tomorrow.

Everything the app computes — cost basis, IRR, TWR, dividend forecasts, options Greeks, tax calculations — runs locally against your decrypted data, so no cloud model ever sees your holdings. See the data safety guide for the encryption model.

Yes, for structural reasons rather than procedural ones. Your portfolio is end-to-end encrypted on your device with a key derived from your password, so a breach of our servers yields ciphertext; we never link to your broker or bank through Plaid or Yodlee; and every server sits in the EU under GDPR.

The gaps we can't close: a supply-chain attack replacing our own code, and someone reaching your device while you are signed in. Is my data safe? has the encryption spec, retention and export.

Not with two separate logins — Capitally is single-user today. A project's key is derived from your own password, so there is no invite flow, no second seat, no read-only role; sharing a login grants full read-and-write access.

If the other person only needs the numbers, export a filtered slice to CSV, Excel or PDF, or use Hide my numbers to show allocation without amounts. Projects covers multi-entity setups; shared access is on the roadmap.

Not natively — no built-in TOTP, SMS or email verification, and no passkey sign-in. Signing in with Google is the way to put a second factor in front of the account today: it inherits whatever multi-factor method your Google login enforces.

On an end-to-end encrypted product the layer below sign-in matters more. A Project Password derives the encryption key on your device from a secret only you hold, so reaching the account is not the same as reading the data. Account and login covers both.