Read-only
Worthly reads. Its code contains no call that places an order, withdraws or moves money anywhere.
The key permissions are set on the platform when you create the key, so we ask for read-only keys and say how to make one. If a read-only key ever leaked, what is at stake is privacy, not your funds.
Keys are encrypted
Exchange credentials are encrypted before they are written to the database, with authenticated encryption. The master key is not stored in the database; it lives in the server environment.
Each time a stored credential is decrypted, the event is written to an audit log. Database backups are encrypted too, and your data export never contains your keys.
Your positions are yours
They are never shared, sold or released, not even anonymised. There are no ads and no ad trackers on the product.
Worthly is closed source and copyrighted. That means you cannot audit the code yourself, so the trust has to rest on what is written here, on how the product is built, and on the person behind it.
Your account
Passwords need at least 8 characters, an uppercase letter and a digit, and are stored only as a slow argon2 hash. An account exists only after you enter a 6-digit code mailed to your address (valid 15 minutes, 5 tries). You must verify your email before connecting a platform.
Sign-in attempts are rate-limited per account, and the login does not reveal whether an email is registered.
Sessions
Access tokens last 60 minutes. A longer-lived refresh token (30 days) is replaced every time it is used, and signing out revokes it. Resetting your password ends your other sessions, and signing out clears the offline copy of your data from the device.
Two-factor sign-in
Optional, and worth switching on. Any authenticator app works (time-based one-time codes). Turning it on or off asks for your password again. You get 10 recovery codes, shown once and stored only as hashes.
Your data, your exit
You can download everything of yours as a file, and delete your account, from inside the app. Deletion needs a 6-digit code mailed to you, then removes your account and the data attached to it.
One thing is kept: a short audit trail saying that some credential was decrypted at some time. After deletion it is no longer linked to anyone, and it ages out after 180 days.