Skip to main content

Overview

Storehouses is built with security and privacy as core principles. Your portfolio contains sensitive information about valuable assets, and we take protecting that data seriously. This guide covers security best practices, privacy features, and how to keep your account secure.

Privacy First

Storehouses is designed from the ground up to protect your privacy. We don’t require identity verification, don’t collect phone numbers, and never sell your data.

Account Security Best Practices

Strong Passwords

Your password is the first line of defense for your account.

Password Requirements

Storehouses requires passwords that meet these minimum standards:
  • At least 12 characters
  • One uppercase letter
  • One lowercase letter
  • One number
  • One special character (required)
Best practices for passwords:

Use Unique Passwords

Never reuse passwords across different services. If one service is compromised, unique passwords protect your other accounts.

Password Manager

Use a password manager like 1Password, Bitwarden, or LastPass to generate and store complex passwords securely.

Long & Complex

Longer passwords are exponentially more secure. Consider passphrases: 4-5 random words (e.g., “correct-horse-battery-staple”).

Change Regularly

Change your password periodically, especially if you suspect compromise or after using public computers.
Popular password managers that work great with Storehouses:
  • 1Password - Cross-platform with family sharing
  • Bitwarden - Open-source and free tier available
  • LastPass - User-friendly with browser extensions
  • Dashlane - Includes VPN and dark web monitoring
  • Apple Keychain - Built-in for Apple users

Email Security

Email Verification

Storehouses requires email verification to ensure account security:
1

Registration

When you sign up, a verification email is sent
2

Check Inbox

Look for verification email from Storehouses
3

Click Link

Click the verification link in the email
4

Account Activated

Your account is verified and fully activated
Verification links expire after 24 hours. Request a new verification email if yours has expired.

Email as Your Identity

Your email address is your primary identifier:
  • Used for login authentication
  • Receives security notifications
  • Required for password resets
  • Cannot be changed without verification

Email Best Practices

  • Use a secure email provider (Gmail, ProtonMail, Outlook, etc.)
  • Enable two-factor authentication on your email account
  • Never share your email password
  • Use a dedicated email for financial accounts
  • Regularly check for suspicious activity

Changing Your Email

When changing your email address:
1

Go to Account Settings

Navigate to your account settings
2

Update Email

Enter your new email address
3

Verify New Email

Check the new email inbox for verification link
4

Confirm Change

Click verification link to complete the change
5

Old Email Notified

Your old email receives notification of the change
If you receive an email notification about an email change you didn’t initiate, contact support immediately to secure your account.

Password Management

Changing Your Password

Regularly update your password to maintain security:
1

Navigate to Settings

2

Find Password Section

Locate “Change Password” section
3

Enter Current Password

Provide your existing password for verification
4

Enter New Password

Create a new password meeting security requirements
5

Confirm

Re-enter new password to confirm
6

Save

Click “Update Password”
After changing your password, you’ll be logged out of all devices and need to sign in again with the new password.

Password Reset Process

If you forget your password:
1

Go to Login

2

Click Forgot Password

Select “Forgot Password” link
3

Enter Email

Provide your account email address
4

Check Email

Look for password reset email from Storehouses
5

Click Reset Link

Click the secure reset link in the email
6

Create New Password

Enter and confirm your new password
7

Sign In

Log in with your new password
Password reset links expire after 1 hour for security. If your link has expired, request a new one.

What If I Don’t Receive Reset Email?

Password reset emails may be filtered to spam or junk folders. Check there first.
Ensure you’re entering the correct email address associated with your Storehouses account.
Email delivery can sometimes take a few minutes. Wait 5-10 minutes before requesting another reset.
If you still don’t receive the reset email, contact support for assistance.

Session Management

Active Sessions

Storehouses tracks active sessions across your devices for security monitoring:
string
Sessions remain active for 30 days of inactivity
string
Inactive sessions automatically expire after 30 days
string
You can manually sign out of any session at any time

Viewing Active Sessions

See where you’re logged in:
1

Go to Account Settings

Navigate to your account settings
2

Find Sessions

Locate “Active Sessions” or “Devices” section
3

Review List

See all active sessions with:
  • Device type (mobile, desktop, tablet)
  • Browser/app used
  • Last active timestamp
  • IP address (optional)

Signing Out of Sessions

Sign Out of One Device

Select a specific session and click “Sign Out” to log out that device only

Sign Out of All Devices

Click “Sign Out Everywhere” to log out of all sessions except your current one
If you see unfamiliar sessions, sign out of all devices immediately, change your password, and contact support.

Two-Factor Authentication (MFA)

Pro and Lifetime users can enable two-factor authentication for an extra layer of account security.

Setting Up MFA

1

Go to Account Settings

Navigate to storehouses.app/account and click the Security tab.
2

Enable Two-Factor Authentication

Click “Enable MFA” in the security section.
3

Scan QR Code

Use an authenticator app (Google Authenticator, Authy, 1Password, etc.) to scan the QR code.
4

Enter Verification Code

Enter the 6-digit code from your authenticator app to confirm setup.
Once enabled, you’ll need to enter a code from your authenticator app each time you log in.
If your estate manager’s firm enforces MFA, you have a 7-day grace period to enable it after connecting with them.

Disabling MFA

To disable MFA, go to Account Settings → Security and click “Disable MFA.” You’ll need to enter a current verification code to confirm.

Login Activity

Storehouses tracks all login activity for your account. View your login history from the Security tab in Account Settings. Each entry shows:
  • Timestamp — When the login occurred
  • Device & browser — What was used to log in
  • IP address — Partially masked for privacy
  • New device indicator — Flags logins from devices you haven’t used before
Login events tracked include: successful logins, failed attempts, logouts, MFA challenges, and password resets.

Data Encryption

End-to-End Encryption

Pro & Lifetime Feature

Storehouses offers client-side end-to-end encryption (E2EE) for Pro and Lifetime users. Your data is encrypted on your device using AES-256-GCM before being sent to our servers — we never see your unencrypted data.
How it works:
1

Data Encrypted on Device

Your portfolio data is encrypted in your browser using a key derived from your password
2

Encrypted Data Sent to Server

Only encrypted blobs are transmitted and stored — our servers never see plaintext
3

Decrypted on Access

Data is decrypted in your browser when you access it
4

Zero-Knowledge

Storehouses servers have no way to decrypt your data, even if compelled
Key features:
  • Recovery key — A backup key shown at setup for account recovery if you forget your password
  • Heir access — Securely share decryption access with designated heirs via asymmetric key exchange
  • Firm access — Grant estate managers decryption access without sharing your password
  • Key rotation — Rotate your encryption key at any time for additional security
Learn more about End-to-End Encryption →

Transport Encryption

All data transmitted between your device and Storehouses is encrypted:

TLS/SSL Encryption

  • All connections use HTTPS with TLS 1.3
  • 256-bit encryption for data in transit
  • Modern cipher suites for maximum security
  • Certificate pinning for mobile apps

Database Encryption

Your portfolio data is encrypted at rest:
string
AES-256 encryption for all stored data
string
Encryption keys managed by secure key management systems
string
All database backups are also encrypted

Privacy & Data Collection

What Storehouses Collects

Minimal Data Collection

Storehouses only collects data necessary for service functionality:
  • Email address - For authentication and account recovery
  • Password hash - Securely hashed, never stored in plain text
  • Portfolio data - Items, collections, locations you create
  • Usage analytics - Anonymous feature usage for product improvement
  • Billing information - Processed and stored by Stripe, not Storehouses

What Storehouses Doesn’t Collect

Privacy by Design

Storehouses intentionally does NOT collect:
  • Phone numbers - Not required for any feature
  • Identity verification - No KYC or ID documents
  • Social security numbers - Never requested
  • Physical addresses - Optional for location tracking only
  • Browsing history - No tracking across other websites
  • Third-party cookies - No advertising or tracking cookies
Your privacy is paramount. Storehouses doesn’t sell your data, share it with advertisers, or use it for any purpose other than providing the service you signed up for.

No Identity Verification Required

Unlike financial platforms, Storehouses:
  • Doesn’t require government ID
  • Doesn’t perform KYC (Know Your Customer) checks
  • Doesn’t verify your identity
  • Doesn’t ask for proof of residence
  • Allows pseudonymous usage (any email works)

Why No Identity Verification?

Storehouses is a portfolio management tool, not a financial institution. You’re tracking assets you already own. We believe requiring identity verification would be invasive and unnecessary for the service we provide.

Data Protection & Privacy Regulations

GDPR Compliance (EU Users)

Storehouses complies with the General Data Protection Regulation (GDPR) for European users:

Right to Access

You can export all your data at any time in CSV or PDF format

Right to Erasure

You can delete your account and all associated data permanently

Right to Rectification

You can edit, update, or correct your data at any time

Right to Portability

Export your data in standard formats for migration to other services

Data Minimization

We only collect data necessary for service functionality

Consent

Clear consent for data collection and processing

CCPA Compliance (California Users)

For California residents, Storehouses complies with the California Consumer Privacy Act (CCPA):
  • Right to know what data is collected
  • Right to delete personal information
  • Right to opt-out of data sales (we don’t sell data)
  • Right to non-discrimination for exercising privacy rights

Data Retention

string
Data retained as long as your account is active
string
Data permanently deleted within 30 days of account deletion
string
Backup data purged within 90 days of account deletion

Heir Access Security (Pro)

Secure Emergency Access

Heir Access allows designated beneficiaries to access your portfolio in emergencies:

Security Features

  • Time-delayed activation (24-72 hours)
  • Email verification for heirs
  • Notification sent to you when access is requested
  • You can cancel access requests
  • Read-only access for heirs (cannot modify)
  • Automatic expiration after set period
Learn more about Heir Access →

Best Practices for Heir Access

1

Choose Trusted Heirs

Only designate people you completely trust
2

Inform Your Heirs

Tell your heirs about the system and how to use it
3

Set Appropriate Delays

Configure time delays that balance security and accessibility
4

Review Periodically

Check and update heir designations regularly

Sharing Security

Secure Portfolio Sharing

When sharing your portfolio with advisors or family:

Share Link Security

  • Unique, hard-to-guess URLs
  • Optional password protection
  • Configurable expiration dates
  • Revocable at any time
  • Read-only access (recipients cannot edit)
  • Track when links are accessed
Anyone with a share link can view your portfolio. Only share links with trusted individuals and use password protection for sensitive portfolios.
Learn more about Portfolio Sharing →

Suspicious Activity Monitoring

Account Security Notifications

Storehouses automatically monitors for suspicious activity and notifies you:

Login from New Device

Email notification when you log in from a device not previously used

Password Changes

Immediate notification when your password is changed

Email Changes

Notification to old email when email address is updated

Failed Login Attempts

Alerts after multiple failed login attempts
If you receive a security notification for activity you didn’t perform, take immediate action:
  1. Change your password immediately
  2. Sign out of all devices
  3. Contact support immediately

Security Incident Response

If Your Account Is Compromised

If you suspect your account has been compromised:
1

Change Password Immediately

Use password reset to create a new, strong password
2

Sign Out All Devices

Log out of all sessions from account settings
3

Review Account Activity

Check for unauthorized changes to items, collections, or settings
4

Update Email

If your email was compromised, update to a new, secure email address
5

Contact Support

Contact support immediately with details of the compromise
6

Review Payment Methods

Check billing settings for unauthorized payment changes

Storehouses Security Team

In case of security concerns:

Report Security Issues

Report urgent security issues via dashboard support for immediate assistance

Third-Party Security

Stripe Payment Security

Payment processing is handled by Stripe:

Stripe Security

  • PCI DSS Level 1 certified (highest security standard)
  • Credit card data never touches Storehouses servers
  • Tokenized payment methods
  • 3D Secure authentication
  • Fraud detection and prevention
  • SOC 1 and SOC 2 compliance

Supabase Data Security

Storehouses uses Supabase for database and authentication:

Supabase Security

  • PostgreSQL with row-level security
  • Automatic backups with encryption
  • ISO 27001 compliant infrastructure
  • SOC 2 Type II certified
  • Regular security audits

Security Best Practices Summary

Your Security Checklist

  • Use a strong, unique password with a password manager
  • Enable 2FA on your email account
  • Regularly review active sessions
  • Keep your email address secure and up-to-date
  • Export your data regularly as a backup
  • Only share portfolio links with trusted individuals
  • Review heir access settings periodically
  • Monitor email for security notifications
  • Sign out of public or shared computers
  • Report suspicious activity immediately

Security FAQs

Yes. Pro and Lifetime users can enable TOTP-based two-factor authentication from Account Settings → Security. Use any authenticator app (Google Authenticator, Authy, 1Password, etc.) to set it up. We also recommend enabling 2FA on your email account for additional security.
Your data is encrypted in transit (TLS 1.3) and at rest (AES-256). We use industry-standard security practices and regularly audit our security measures.
Storehouses employees can only access your data when necessary for support requests or system maintenance. All access is logged and audited. With end-to-end encryption enabled, even Storehouses staff cannot read your encrypted data.
In the unlikely event Storehouses ceases operations, we’ll provide advance notice and allow all users to export their complete portfolio data before service termination.
Storehouses is not currently open source, but we’re considering open-sourcing parts of the platform in the future to improve transparency and community contributions.

Additional Resources

Privacy Policy

Read our complete privacy policy

Terms of Service

Review our terms of service

Data Processing Agreement

For GDPR compliance and enterprise users

Contact Support

Questions about security? Contact our team

Next Steps

Account Settings

Manage your account and privacy settings

Export Your Data

Create backups of your portfolio

Heir Access Setup

Configure emergency access for beneficiaries

Sharing Best Practices

Learn how to securely share your portfolio