Most portfolio trackers ask for the same thing first: a read-only API key, or a wallet to connect. It is the fastest way to fill a dashboard, and it hands the service a live map of what you hold and where. A private tracker is one that is useful without that map. These six questions tell one from the other — ask them of any tracker, Perly included.
A read-only key cannot withdraw, but it reads every balance, deposit and trade on the account for as long as it exists, and it sits on somebody else's server the whole time. Keys leak in breaches, and read-only is only as good as the exchange's permissions and the care taken creating the key. The alternative costs a few minutes: download your history as a CSV from the exchange — here is how on Binance — and import the file. Nothing stays connected.
A seed phrase or a private key belongs in no tracker, ever. Watching a public address is milder but not neutral: the service now links that address to your account, and on a public chain an address shows its whole history to anyone who has it. A tracker should work without either. You record what you did; the address stays yours to reveal or not.
On most services encrypted means encrypted on the disk and on the wire. The company still holds the key, and the plaintext is read whenever its software, its staff or a court order asks. The question that matters is where the key lives. If amounts are encrypted in your browser, under a password the company never receives, its database holds ciphertext it cannot open — and so does anybody who steals the database. The price is real and worth knowing up front: a lost password cannot be reset for you.
A card on file brings a merchant of record with it, then billing addresses and identity checks the tracker itself never needed. A payment in bitcoin or a stablecoin, made once on-chain, tells it that a payment arrived and little else.
A ledger kept for years should not go behind a paywall the month you stop. Check that a lapsed account can still read, export and delete everything it recorded, and that the export is complete rather than a summary.
Privacy claims cost nothing to make. Look for a privacy policy that lists what is stored, and a security page that says what is not encrypted as well as what is. A tracker that states its own limits is usually telling you the rest straight too.
The most private ledger is one that never leaves your machine: a desktop app or a spreadsheet. It is also the one you back up, sync and keep running yourself, and it watches nothing while the laptop is closed — no alerts, no ledger on your phone. A tracker that encrypts in the browser sits between the two: the server stores and syncs what it cannot read, and runs alerts on the little it has to read.
Perly is built for Bitcoin and tracks other coins too, with average cost basis, PnL and ROI recomputed from your full history — the arithmetic is here. See the application.
Yes. A tracker that takes manual entries and CSV exports needs no exchange connection at all. Perly is one: it has no field for an API key, and imports the CSV history an exchange lets you download.
It cannot withdraw funds, but it reads every balance and trade for as long as it exists, and it is stored on the tracker's servers, where a breach exposes it. A CSV export gives the tracker the same history once, with nothing left connected.
Most can: the amounts sit readable on their servers. Only a tracker that encrypts in your browser, with a key it never receives, cannot. Perly encrypts amounts, prices and notes that way, on by default.
A ledger that never leaves your own machine — at the cost of backups, sync and alerts you run yourself. After that, a tracker that encrypts in the browser, asks for no API key and no wallet, and takes payment in crypto.
An e-mail address and a password, or a Google or X sign-in. No name, no ID and no card.
© 2026 Perly. All rights reserved.