Security
Updated 09/24/2026
This page describes how Gradually (the "service") protects your account and the data you enter. For what the service collects and why, see the privacy notice.
Invest529 login
- The service uses the read-only aggregator credential that you create on invest529.com. That credential can read balances only. It cannot be used to move money.
- The service never asks for the password you use to manage your Invest529 account.
- Your login is sent to the service only for a sync. It is held in memory while the sync runs, and then it is discarded. It is never written to the database or to log files.
- If you select "Remember on this device", your login is encrypted and stored in that browser only. The browser holds the key, and the key cannot be copied out of the browser. While your login is stored, the service syncs each time you open it on that device, unless you turn off "Sync when the app opens" in Settings. To remove the stored copy, turn off "Remember on this device" on the Accounts tab, or clear the site data for that browser.
- Connecting an Invest529 account is optional. You can enter balances by hand for any plan or account instead.
The service is not affiliated with Virginia529, Invest529, or Commonwealth Savers.
Sign-in
- You sign in with a link sent to your email address. The service stores no password of its own.
- A sign-in link can be used once.
Encryption
- All traffic between your browser and the service uses HTTPS. The service tells browsers to refuse an unencrypted connection.
- The database host encrypts all stored data at rest.
- Names and labels have a second layer of encryption. The service encrypts beneficiary names and nicknames, account names, login nicknames, and the names of custom glidepaths and scenarios before it stores them. The key that opens them is not kept in the database, so a copy of the database alone does not reveal them.
- Balances, dates, allocations, and your email address do not have this second layer. The service needs them in readable form to calculate totals and to send sign-in links. Encryption at rest protects them.
Tracking and third parties
- The service shows no ads and uses no third-party analytics or tracking scripts.
- Pages load no scripts, fonts, or images from other sites. Your browser connects only to the service.
- Your data is not sold or rented.
- The service runs on Vercel, which hosts the application, and Supabase, which provides the database and sign-in. Your data is stored in the United States. The privacy notice lists every provider that processes data.
Account deletion
- You can delete your account at any time from Settings. Deletion is immediate and cannot be undone.
- Deletion removes your beneficiaries, balances, planning settings, and saved glidepaths, together with the key for your encrypted names. The privacy notice lists what deletion removes.
Reporting a security issue
- To report a security issue in the service, email hello@gradually.io. Include the steps that show the issue.
- Do not access, change, or delete data that belongs to another person. Do not run tests that slow or interrupt the service.
- The same contact is published at /.well-known/security.txt.
