Privacy Policy

Your portfolio is encrypted on your device before synchronisation. We cannot read its contents.

Last updated: 31 August 2026

The short version

Your holdings, prices, dates, watchlist and questionnaire answers are encrypted on your iPhone with a key that never leaves your device. Raqib stores only the encrypted result and cannot read it. Your name and email are stored normally, because we need them to sign you in.

What we store, and whether we can read it

  • Your portfolio — holdings, share counts, prices, dates, watchlist and questionnaire answers — is encrypted on your device. We store only the encrypted result and cannot read it. Neither can our database administrators, our hosting provider, or anyone who obtained a copy of our database.
  • Portfolio value, gains, dividend estimates and projections are calculated on your device and are never sent to us.
  • Imported statements — CSV, PDF, photo or scan — are processed entirely on your device. The original file, its filename and its extracted text are never uploaded and never stored on our servers.
  • Your account — your name and email address — is stored so we can sign you in and send verification codes. This is not end-to-end encrypted, because we need your email address to deliver those codes.
  • A device identifier — a random value the app generates on your iPhone and keeps in the device keychain. It is sent with your requests so that we can keep you signed in, recognise a device you have already verified, and end a session. It is not Apple’s advertising identifier, we never share it, and it is removed when you delete your account.
  • Optional details, if you choose to give them — a first and last name, a date of birth, and a phone number. Every one of them is optional: the app works exactly the same without them, nothing asks you for them twice, and you can clear any of them at any time from the account screen. Unlike your portfolio they are stored in readable form, because the point of them is that we can use them. We do not verify your phone number and we do not send you messages on it today.
  • Product-interaction analytics — a fixed list of non-financial events, such as completing sign-up, verifying your email, signing in, or saving your encrypted portfolio. These records cannot contain your holdings, tickers, amounts, watchlist, questionnaire answers or imported content; that restriction is enforced in code, not by policy alone. They are stored against a pseudonym rather than your account name, but we hold the key that produces that pseudonym, so we treat this data as linked to you rather than claiming it is anonymous.

Why we use each item, and how long we keep it

  • Your name and email address are used to run the app itself: to create and sign in to your account, to send verification codes, to reset a password, and to greet you by name. We keep them for as long as your account exists, and they are removed when you delete it.
  • Your encrypted portfolio is used only to synchronise it between your own devices and to restore it when you sign in again. We keep it for as long as your account exists, and it is removed when you delete it.
  • The device identifier is used to run the app securely: to keep a session alive, to recognise a device you have already verified, and to end a session. It is kept while that session or verified device exists, and it is removed when you delete your account.
  • Product-interaction analytics are used only to understand how Raqib is used in aggregate — how many people signed up, how many are active, which app versions are in use. Detailed records are deleted after 35 days; only aggregate counts remain after that.
  • None of it is used for advertising, for building a profile of you, or for tracking you across other companies’ apps or websites, and none of it is sold or shared for those purposes.

What we do not do

  • We do not have a master key, a support key, or an administrator back door to your portfolio.
  • We do not sell or share your personal data.
  • We do not allow support staff or administrators to view your portfolio, its value, your watchlist, your questionnaire answers or your imported documents. What an administrator can look up about you is your account details — your name, your email address, when you joined, when your account was last active, and, when a support request needs it, the optional details you chose to give us — and that boundary is set by the database, not by a rule we ask staff to follow.
  • We do not include third-party advertising or tracking software in the app.

Recovery — please read this part

Because your portfolio is encrypted with a key only you hold, if you lose every device you use Raqib on and your recovery code, your encrypted portfolio cannot be recovered by anyone, including us. Keep your recovery code somewhere safe and offline.

There is no Raqib master key and no administrator recovery path. Support cannot unlock your portfolio, because Raqib never has the key. Resetting your account password does not affect your encryption key or your portfolio.

Analytics and retention

  • Analytics events are limited to a fixed list of generic, non-financial facts, such as “the app was opened” or “an import succeeded”.
  • Where we count how many distinct people were active, we use a pseudonym derived on our server from your account identifier using a secret key. It is never returned by any interface, and the internal dashboard cannot read the underlying event records at all — but we hold that key, so we do not claim the data is anonymous. We treat it as linked to you.
  • Detailed event records are deleted after 35 days. What remains after that is aggregate counts only.
  • Where we show a breakdown internally, groups smaller than 20 people are withheld so a small group cannot be identified.

How we protect it

  • Your portfolio is encrypted on your device with AES-256-GCM before any of it is sent, using a key derived on your device that we never receive.
  • Everything the app sends travels over HTTPS.
  • Your password is never stored in readable form. We keep only a scrypt hash of it, with parameters chosen against current OWASP guidance.
  • Sign-in tokens are stored as hashes rather than in readable form, sessions expire, and the device identifier lets us require a fresh verification code on a device we have not seen before.
  • Our database enforces least privilege itself: the role behind our usage dashboard has no permission to read the tables holding encrypted portfolios, recovery material or account records, so those queries are refused by the database rather than only by our code. Looking up account details for support uses a second, separately restricted role: it can read your name and email address, and it still cannot reach a portfolio, a vault, a password or a recovery code.

This website

Everything above is about the Raqib app. This website is separate, and it is not silent: serving any page leaves a technical trace, and we would rather describe it than imply there is none.

  • This site is hosted on Cloudflare Pages. To serve and protect it, Cloudflare processes limited technical information on our behalf — your IP address, request metadata such as the page requested, the time, your browser and device type and an approximate location derived from the IP address, together with security logs used to block abuse. We use this only to keep the site available and defend it; we do not use it to build a profile of you, and we do not combine it with your Raqib account.
  • The site sets no cookies, runs no analytics, embeds no advertising or tracking software, and loads nothing from any third-party origin. Your language and theme choices are kept in your own browser and are never sent to us.
  • If you write to one of our published addresses, we receive and process your message, your email address and whatever you choose to include, for the sole purpose of answering you. Email reaches us through Cloudflare Email Routing and our mail provider. We keep correspondence only for as long as the enquiry and any follow-up need it.
  • Please do not email us screenshots of your holdings or your account password. We do not need them, and an email is not encrypted the way your portfolio is.

Deleting your account

You can delete your account from inside the app at any time: open Settings, scroll to the Account section and choose “Delete Account”. You confirm with your password and a verification code we email you. Step-by-step instructions, including how to export a copy first, are on the Delete Account page.

  • Deletion is immediate, not scheduled. Your account record — your name, your email address and any optional details you gave us — your encrypted portfolio, your recovery information, your sessions and your verified devices are removed together in a single database transaction.
  • The record that a deletion happened is kept without your identity attached, so we can account for the event without retaining who it was.
  • Pseudonymous analytics events age out on their normal 35-day schedule. Aggregate counts that were already tallied — for example that one account was deleted on a given day — do not identify you and are not removed.
  • If you have lost access to your device and cannot delete the account yourself, write to us from the email address on the account and we will close it for you. We will never ask you for your password or your recovery code.

Honest limits

  • A device that has been compromised — by malware, or by tampering with the operating system — could read your portfolio while it is decrypted on that device. Our guarantee is that our servers and our staff cannot read it, not that a compromised phone is immune.
  • Your name and email address are stored in readable form, because sign-in and verification codes require them. So are the optional details above, if you gave them.
  • Someone with access to our database can see that an account exists, that it has an encrypted portfolio, roughly how large that encrypted block is, and when it last changed — but never what it contains.
  • We describe our own security work honestly. We do not hold a security certification and we have not been independently audited.

Contacting us about privacy

Privacy enquiries

privacy@myraqib.com

Questions about this policy, or a request concerning your data.

General support

support@myraqib.com

Help with the app or your account.