← Back to home

Security

Last updated 2026-09-25

Security isn’t a feature bolted on — it’s why Crypto Widgets has no accounts, only reads, and keeps your keys in your Keychain.

Read-only by design

The app only reads balances. It never places trades, deposits or withdrawals — and with read-only keys, it couldn’t.

Keys in your Keychain

API keys live in the Apple Keychain, optionally your end-to-end encrypted iCloud Keychain. They never reach our servers.

No account, no database

There are no user accounts and no portfolio database on our side — nothing central to breach.

How exchange connections work

You create an API key on your exchange — with read-only permission — and paste it into the app. Balance requests are signed on your device and sent directly to the exchange. Delete the key in the app, or revoke it on the exchange, at any time.

How wallet tracking works

Wallets are tracked with their public address only. The app never asks for a private key, a seed or a recovery phrase — and you should never give those to any app.

What we never do

We never place trades, deposits or withdrawals.

We never receive or store your API keys or your portfolio.

We never sell or share your data.

Reporting an issue

Found a vulnerability? We’d like to hear from you. Email hello@crypto-widgets.app and we’ll respond promptly.