Skip to content

Is my data secure?

Short answer: your investment data is yours, it’s protected with bank-grade encryption, and Metrifly is never able to touch your actual money. Here’s exactly what that means.

Metrifly is a tracker — it reads your trade history so it can calculate holdings, performance, and tax. It cannot buy, sell, or move money in your brokerage or exchange accounts.

How data gets in is up to you:

  • Direct link — for supported brokers and exchanges, you authorise a read-only connection. Some brokers use our integration partner SnapTrade (you sign in through their portal); others use a read-only API key you create at the exchange. Where API keys are used, Metrifly stores them encrypted and uses them only to import trades.
  • File and email import — upload a CSV or Excel export, forward contract-note emails, or upload statements.
  • Manual entry — type trades in by hand.

You can disconnect a linked broker at any time from Broker Connections.

Metrifly protects your data with bank-grade encryption — the same 256-bit standard (AES-256) used by banks and governments.

  • In transit: every connection to Metrifly is secured with TLS encryption, on every page and every request. Your data is encrypted the moment it leaves your device and stays encrypted all the way to our servers.
  • At rest: your portfolio data is encrypted at rest with AES-256 while it’s stored.

In plain terms: whether your data is moving or sitting still, it’s scrambled with the strongest commonly used encryption — unreadable to anyone who isn’t you.

Your account is secured with a password and, if you turn it on, two-factor authentication using an authenticator app. We recommend enabling it — see Manage your profile and security. You can also review your active sessions and sign out of every device at once.

Payments are handled by Stripe, a global payments provider. Your card details go straight to Stripe — Metrifly never sees or stores them.

  • Export anytime. Your trades, income, and tax reports export to Excel whenever you want — your data is never locked in.
  • Delete anytime. If you delete your account, your portfolios and all your data are removed immediately and permanently. There’s no waiting period, and it can’t be undone. See Manage your profile and security.
  • We don’t sell your data. You can read exactly how we handle it in our privacy policy.

Your data is stored in Australia, on established, reputable cloud infrastructure.

Security and privacy matter, and we’re happy to answer specifics. Contact support and we’ll get back to you.