This article explains how Scaryfolio handles Ghostfolio connections, iCloud synchronization, local data, purchases, widgets, and privacy features.
Direct Connection to Ghostfolio
Scaryfolio connects directly from each device to Ghostfolio Cloud or your self-hosted server. Portfolio data does not pass through a Scaryfolio server. Ghostfolio remains the authority for accounts, holdings, activities, watchlists, portfolio calculations, Base Currency, and Zen Mode.
iCloud Synchronization
Supported devices using the same Apple Account share one Scaryfolio connection through iCloud Keychain. Cash visibility, display, tab, sorting, chart, FIRE, accent color, tab-label, and allocation section settings also synchronize through iCloud. Synchronization may take time, especially after setting up a new device or restarting one.
One Apple Account has one shared connection. Connecting to a different Ghostfolio account replaces it on every device. Disconnect also affects every device using that Apple Account.
Data That Remains Local
- Portfolio and account data loaded from Ghostfolio
- Bearer tokens and local request or cache data
- Widget and Apple Watch display data
- Notification status
- Device-specific privacy choices and transient interface state
Authentication
Scaryfolio sends your Security Token directly to Ghostfolio to authenticate. Keep the Security Token and custom header values private. If you believe a credential has been exposed, replace it in Ghostfolio or your proxy service.
For self-hosted servers, use HTTPS where possible, keep Ghostfolio updated, protect custom headers as secrets, and rotate credentials if exposed. HTTP remains available for deployments that intentionally use it under the app's existing server policy.
Widgets, Spotlight, Shortcuts, and Notifications
Widgets display data previously loaded by Scaryfolio. Widget and Apple Watch widget content is marked as privacy-sensitive, so the operating system may redact it on supported surfaces or device states. Visible widgets, Spotlight results, Siri, Shortcuts, automations, and notifications may still display or speak financial values outside the main app. Remove or disable these surfaces when that exposure is not appropriate.
On Apple Watch, bearer tokens and financial widget caches are cleared when Watch access is revoked, the active connection changes, or you disconnect globally. The Watch widgets then show their unavailable placeholder until access and a connection are restored.
Third-Party Services
RevenueCat processes purchase entitlement information needed for Scaryfolio Pro and does not receive Ghostfolio portfolio data through Scaryfolio. Purchases are processed by Apple. Ghostfolio Cloud data is subject to Ghostfolio's privacy policy; self-hosted data is subject to your server configuration.
Privacy Blur
Scaryfolio can visually hide financial amounts. On iPhone, enable Shake to Hide Amounts in Settings > Privacy. On Mac, use the Privacy command or Command-Shift-H. This is a visual privacy feature and does not encrypt or delete data.
Disconnecting and App Removal
Disconnect removes the shared connection from every Scaryfolio device using the same Apple Account and clears locally displayed Scaryfolio data. If Disconnect reports an error, check your network and iCloud Keychain availability, then try again.
Deleting one installation removes its local app data according to Apple's normal behavior, but synchronized Keychain and preference values may remain in iCloud and restore after reinstall. Use Disconnect before deletion when you intend to remove the shared Scaryfolio connection.
Your Control
- You choose Ghostfolio Cloud or a self-hosted server.
- You can replace the shared connection after successful authentication.
- You can disconnect every device from Settings.
- You can remove widgets and avoid financial Shortcuts or notifications.
- Your source investment data remains in Ghostfolio, not Scaryfolio.