← Cedar Charts

Security

Updated September 19, 2026

Cedar Charts is made by Cedar Dynamics LLC. This page explains how we protect your data, with particular attention to the brokerage connection in Cedar Pro. The full policies behind it (information security, data handling, access control, incident response, vendors) are maintained in our repository and available to partners on request.

The short version: we designed the brokerage feature so our servers never hold your holdings. The key that fetches them lives only on your iPhone, the data is fetched fresh each time and kept in memory, and nothing about your portfolio is written to our database or logs.

How a brokerage connection works

  1. You tap Connect in the Portfolio tab. Our server asks Plaid for a one-time Link token.
  2. Plaid's own interface opens on your phone. You sign in to your brokerage there. Your username, password and any security code go to Plaid and your brokerage only. They never pass through the Cedar Charts app or our servers.
  3. Plaid hands back an access key. Our server exchanges it and returns it to your phone, where it is stored in the iOS Keychain, encrypted by the device's Secure Enclave, restricted to that device, and not synced to iCloud.
  4. Each time you open the Portfolio tab, your phone sends the key to our server, which fetches your holdings from Plaid, matches them to the companies we cover, and returns them. The server keeps nothing between requests; responses are marked no-store.
  5. Tap Remove and we revoke the connection at Plaid and delete the key from your device. You can also revoke access at my.plaid.com.

What we fetch, and what we don't

We fetchWe never request
Investment account name and type, last digits of the account number, balanceFull account or routing numbers
Each position: security, quantity, price, value, cost basisTransactions or trade history
Your name, address, or other identity details from the brokerage
The ability to trade or move money (Plaid does not offer this to us and we would not use it)

Where data lives

PlaceWhatHow long
Your iPhone KeychainThe Plaid access key and the name of your brokerageUntil you remove the connection
Your iPhone, in memoryYour holdings while the Portfolio tab is openUntil the app closes or refreshes
Our serversNothing. There is no brokerage table, cache, or log of holdingsThe milliseconds of each request
PlaidPer the Plaid End User Privacy PolicyUntil the connection is removed

Controls behind the app

Your controls

Reporting a vulnerability

If you find a security problem, email [email protected]. We acknowledge reports within three business days and will not take action against good-faith research. Details are in security.txt.

Service providers

Plaid (brokerage connections), Apple (App Store, Sign in with Apple, Keychain), Clerk (sign-in), RevenueCat (subscriptions), Railway (hosting), Cloudflare (site and DNS), PostHog (anonymous product analytics that never receive holdings). Full detail is in the privacy policy.

Contact

[email protected] · [email protected]