Security

Your portfolio data and API keys never leave your device

Most portfolio apps send your data to a server. David doesn’t. Your portfolio data and broker API keys are stored locally on your iPhone — David Owl has no server that knows your portfolio or sees your positions.

What “client-side” means

Client-side means that processing and storage happen on your device, not in the cloud. Your portfolio data and broker API keys stay on your device and never go to our servers. David Owl simply has no place where your balances or keys are stored centrally — that information stays with you.

What David Owl doesn’t have

David Owl has no central database containing users’ portfolio data. That is a deliberate architectural choice, not an accident. Where cloud-based trackers keep all their users’ data in one place, David has no central storage that can be hacked — no “honeypot” for attackers to target. As security journalist Brian Krebs puts it: “Data you don’t have can’t be stolen.”

How your API keys are protected

Broker API keys are stored in the iOS Keychain, secured by the Secure Enclave — a separate, hardware-protected chip in your iPhone designed specifically to protect sensitive keys. The key stays on your device and never goes to a David server. Tip: never grant a broker key the right to withdraw funds, and enable 2FA on your broker account.

Syncing between devices

Do you use David on multiple devices? Your fund configurations — the settings of your funds — sync via your own iCloud. That runs over Apple’s infrastructure, not David’s. Your portfolio data and API keys remain device-only and do not sync.

What the minimal backend does

David has a small backend, but it never touches your portfolio data. It only does what is strictly necessary: logging in, verifying purchases (in-app purchases) and tracking loyalty. These functions are completely separate from your positions, balances and keys — those stay on your device.