Security & Data Handling
Zyvo is a portfolio tracker, which means it sees your financial data even when it doesn't hold your money. Here's what that access actually amounts to, in plain terms.
Broker connections are read-only
When you connect a broker, Zyvo requests read-only access to your holdings and transaction history through SnapTrade — never trading permissions, and never your broker password. Zyvo cannot place a trade, move money, or change anything in your brokerage account. Disconnecting a broker at any time revokes that access immediately.
You don't need to connect a broker at all. CSV import covers every broker, with no account linking, if you'd rather keep that separate.
Where your data lives
Zyvo's database and authentication run on Supabase, a hosted PostgreSQL platform. Your account credentials, transactions, and portfolio data are stored there, encrypted in transit (HTTPS/TLS) between your browser and Zyvo's servers.
Zyvo's database is hosted in AWS's Paris region (eu-west-3) — inside the EU. If EU data residency matters for your own compliance needs, this is confirmed, not a general assurance: ask us if you need it in writing.
Deleting your data
Account deletion is self-service and immediate, not a support-ticket request. See Delete My Account for exactly what gets removed — in short, everything except billing records legally required to be kept.
What Zyvo does not do
- Never sees or stores your broker password — broker authentication happens through SnapTrade, not Zyvo directly.
- Never has the ability to place trades, withdraw funds, or modify your brokerage account.
- Doesn't sell your data. Zyvo products don't run ads and don't share your portfolio data with advertisers.