Legal
Security
Last updated: September 7, 2026
The architecture, in one sentence
Position Ledgers has no database to breach, because it doesn't have a database — your brokerage data is parsed and stored entirely on your own device, and the product's core function makes zero network requests with it.
No server-side storage of your data
There is no Position Ledgers account, no login, and no server that holds a copy of your transactions, positions, or statements — for any user, ever. If our website or hosting were compromised tomorrow, there would be no brokerage data sitting there to expose, because none is ever sent to us. The only server-side code we run at all is described in "The one server-side component" below, and it doesn't touch your financial data either.
What's stored, and where
Everything the app remembers between visits lives in your browser's own on-device storage — IndexedDB for your transaction history and account data, and localStorage for a few small settings (your Tradier API token if you've entered one, your Pro license key if activated, your light/dark theme choice). None of it is synced anywhere or accessible to any other website. Clearing your browser's site data for the page, or using the app's own Clear Data button, removes it completely.
Backup files are sensitive — treat them that way
The Backup feature writes a plain, unencrypted JSON file containing your full imported transaction history to your own computer. It's not sent anywhere by us, but it is a real financial record once it's on your disk — the same way a downloaded brokerage statement PDF is. Store it somewhere you'd store any other sensitive financial document (an encrypted drive, a password manager's file storage, etc.), and be as careful with it as you would with a bank statement before, say, emailing it to yourself or uploading it to a general-purpose cloud drive.
The one server-side component
License activation (both the base product and the Pro upgrade) is the single exception to "no server." Payhip's license-verification API requires a secret credential that can't safely be embedded in a file you download and run — anyone could view the page source and extract it. So when you activate a license key, that key is sent to a small serverless function we run (on Netlify), which holds that one secret and forwards the check to Payhip on your behalf. The function:
- Receives only the license key you typed — nothing else about you or your data
- Stores nothing itself; it has no database. Device-count enforcement is tracked entirely by Payhip's own license record
- Returns a simple valid/invalid answer, which your browser remembers in localStorage so it doesn't need to re-check on every load
That's the complete extent of what leaves your browser for licensing purposes.
Optional third-party data paths
If you use the optional "Fetch Prices" feature with your own Tradier account, your
position symbols and Tradier API token are sent directly from your browser to Tradier's API
(api.tradier.com) — Position Ledgers has no server in that request path and never sees
either the token or the response. Your Tradier token stays in your browser's localStorage, under your
control, and is only ever sent to Tradier itself.
Reporting a security issue
If you believe you've found a security vulnerability in Position Ledgers or its supporting infrastructure, please email support@positionledgers.com with details before disclosing it publicly. We'll acknowledge and look into any genuine report.