Last updated: May 2026
Worthmap is built for globally-mobile investors who need to trust a platform with their full financial picture. This page explains how we protect your data, what we collect, and how to reach us if you discover a security issue.
Worthmap collects only what is necessary to operate the platform:
localStorage and is never sent to our servers unless you opt into cloud sync.Free-tier financial data is stored locally on your device. We do not have access to your portfolio numbers unless you explicitly enable cloud backup.
All connections to Worthmap use HTTPS with TLS 1.3. Our infrastructure is served through Cloudflare, which enforces modern cipher suites and provides DDoS protection as a default layer.
Pro-account cloud backups are encrypted before leaving your device using AES-256. Keys are derived from your account credentials; Worthmap staff cannot decrypt your stored portfolio values.
Worthmap does not sell, rent, or trade your personal data or financial data to third parties for any purpose — including advertising, analytics resale, or marketing. This is a foundational product principle, not just a legal clause.
We use a small number of third-party services (hosting, error monitoring, analytics) bound by data-processing agreements that prohibit them from using your data for their own purposes. A full list is available in our Privacy Policy.
The strongest security measure is one you control. We recommend:
Worthmap uses a minimal set of cookies:
We do not use advertising cookies or sell cookie data. For full details see our Privacy Policy §7.
If you believe you have found a security vulnerability in Worthmap, please email us before disclosing it publicly:
Security email: [email protected]
For general support or privacy questions: [email protected]
We welcome security researchers who responsibly help us keep Worthmap safe. If you find a vulnerability:
Researchers who responsibly disclose valid vulnerabilities will be credited in our security changelog (with your permission).