← Back to perly.io
Perly

Private crypto portfolio tracker without API keys: six questions to ask

Most portfolio trackers ask for the same thing first: a read-only API key, or a wallet to connect. It is the fastest way to fill a dashboard, and it hands the service a live map of what you hold and where. A private tracker is one that is useful without that map. These six questions tell one from the other — ask them of any tracker, Perly included.

1. Does it need an exchange API key?

A read-only key cannot withdraw, but it reads every balance, deposit and trade on the account for as long as it exists, and it sits on somebody else's server the whole time. Keys leak in breaches, and read-only is only as good as the exchange's permissions and the care taken creating the key. The alternative costs a few minutes: download your history as a CSV from the exchange — here is how on Binance — and import the file. Nothing stays connected.

2. Does it want your wallet, or your addresses?

A seed phrase or a private key belongs in no tracker, ever. Watching a public address is milder but not neutral: the service now links that address to your account, and on a public chain an address shows its whole history to anyone who has it. A tracker should work without either. You record what you did; the address stays yours to reveal or not.

3. Can the company read your amounts?

On most services encrypted means encrypted on the disk and on the wire. The company still holds the key, and the plaintext is read whenever its software, its staff or a court order asks. The question that matters is where the key lives. If amounts are encrypted in your browser, under a password the company never receives, its database holds ciphertext it cannot open — and so does anybody who steals the database. The price is real and worth knowing up front: a lost password cannot be reset for you.

4. What does paying tell it about you?

A card on file brings a merchant of record with it, then billing addresses and identity checks the tracker itself never needed. A payment in bitcoin or a stablecoin, made once on-chain, tells it that a payment arrived and little else.

5. What happens when you stop paying?

A ledger kept for years should not go behind a paywall the month you stop. Check that a lapsed account can still read, export and delete everything it recorded, and that the export is complete rather than a summary.

6. Can you check any of it?

Privacy claims cost nothing to make. Look for a privacy policy that lists what is stored, and a security page that says what is not encrypted as well as what is. A tracker that states its own limits is usually telling you the rest straight too.

Local apps, spreadsheets and the trade-off

The most private ledger is one that never leaves your machine: a desktop app or a spreadsheet. It is also the one you back up, sync and keep running yourself, and it watches nothing while the laptop is closed — no alerts, no ledger on your phone. A tracker that encrypts in the browser sits between the two: the server stores and syncs what it cannot read, and runs alerts on the little it has to read.

How Perly answers the six

  • API keys: none. There is no field for one. History comes in from a CSV export, shown row by row, and nothing is written until you confirm it.
  • Wallets: never a seed phrase or a private key. Watching a public address is something you switch on, and the address is then stored — the Privacy Policy says so.
  • Amounts: encrypted in your browser, on by default for a new account — amounts, prices, fees, notes, tags and descriptions. Portfolio names, each entry's coin and time, and the alerts and plans you set stay readable, because the server needs them to work. A lost password cannot be recovered by us.
  • Payment: crypto only — bitcoin or a stablecoin. There is no card form anywhere.
  • Stopping: when the free days or a paid year end, the account still reads, exports and deletes everything it recorded.
  • Checking: the Security page and the Privacy Policy say what is stored and what is not encrypted.

Perly is built for Bitcoin and tracks other coins too, with average cost basis, PnL and ROI recomputed from your full history — the arithmetic is here. See the application.

Short answers

Is there a crypto portfolio tracker that does not need API keys?

Yes. A tracker that takes manual entries and CSV exports needs no exchange connection at all. Perly is one: it has no field for an API key, and imports the CSV history an exchange lets you download.

Is it safe to give a portfolio tracker a read-only API key?

It cannot withdraw funds, but it reads every balance and trade for as long as it exists, and it is stored on the tracker's servers, where a breach exposes it. A CSV export gives the tracker the same history once, with nothing left connected.

Can a portfolio tracker see how much crypto I hold?

Most can: the amounts sit readable on their servers. Only a tracker that encrypts in your browser, with a key it never receives, cannot. Perly encrypts amounts, prices and notes that way, on by default.

What is the most private way to track a Bitcoin portfolio?

A ledger that never leaves your own machine — at the cost of backups, sync and alerts you run yourself. After that, a tracker that encrypts in the browser, asks for no API key and no wallet, and takes payment in crypto.

What does Perly need from me to sign up?

An e-mail address and a password, or a Google or X sign-in. No name, no ID and no card.

← Back to perly.io

© 2026 Perly. All rights reserved.