Zyvo ← Back to Zyvo
Security

Security & Data Handling

Zyvo is a portfolio tracker, which means it sees your financial data even when it doesn't hold your money. Here's what that access actually amounts to, in plain terms.

Broker connections are read-only

When you connect a broker, Zyvo requests read-only access to your holdings and transaction history through SnapTrade — never trading permissions, and never your broker password. Zyvo cannot place a trade, move money, or change anything in your brokerage account. Disconnecting a broker at any time revokes that access immediately.

You don't need to connect a broker at all. CSV import covers every broker, with no account linking, if you'd rather keep that separate.

Where your data lives

Zyvo's database and authentication run on Supabase, a hosted PostgreSQL platform. Your account credentials, transactions, and portfolio data are stored there, encrypted in transit (HTTPS/TLS) between your browser and Zyvo's servers.

Zyvo's database is hosted in AWS's Paris region (eu-west-3) — inside the EU. If EU data residency matters for your own compliance needs, this is confirmed, not a general assurance: ask us if you need it in writing.

Deleting your data

Account deletion is self-service and immediate, not a support-ticket request. See Delete My Account for exactly what gets removed — in short, everything except billing records legally required to be kept.

What Zyvo does not do


Found something that looks wrong, or have a question this page doesn't answer? Get in touch — we read every message.