Skip to main content
Retina uses public addresses and read-only data for portfolio tracking. Tracking a portfolio does not give Retina permission to move funds, approve tokens, place orders, or sign transactions.

Sign-in identity

You can sign in with email, Google, X, an EVM wallet, or a Solana wallet. Wallet sign-in uses an off-chain message that proves control of the address. The message cannot authorize a transaction or asset transfer. Your sign-in identity remains separate from the addresses you track. You can add public addresses you do not control, including cold wallets and vault addresses.

Payments are a separate action

Paying for or cancelling a plan is separate from tracking and sign-in. Retina presents a wallet transaction only after you explicitly start payment or cancellation from the plan page. Your wallet shows the transaction for approval. Retina never receives a seed phrase or private key. For billing, Retina stores the public payer address, order, payment reference or transaction identifier, paid-through date, and account entitlement needed to prove and manage access. Onchain payments are public. A routing service can also see the payment request it processes. The payment wallet does not become a tracked portfolio address unless you add it separately. An automatic EVM subscription uses a USDC allowance for its specific membership contract. Cancelling asks the wallet to remove that allowance. It does not grant Retina general wallet permissions.

Browser and account copies

Retina keeps the active working copy in browser storage. A signed-in portfolio is also saved to the account so snapshots can sync and restore on another browser or device. The browser copy supports fast local use. The account copy supports recovery, multi-device access, automatic captures, and notifications.

Cloud encryption

Saved portfolio objects are encrypted before they are written to private cloud object storage. Object names use opaque identifiers instead of wallet addresses. This is server-side application encryption. It is not end-to-end encryption. Retina’s Worker can decrypt the saved settings and portfolio data because automatic snapshots must run while your browser is closed.

Data providers

Retina sends the public address and request details needed to retrieve balances, positions, prices, yields, rewards, and market information. Providers can see requests made to their services. Retina uses a server proxy for providers that require protected credentials or server-side coordination. Portfolio provider routes require a signed-in account. Before a provider call leaves Retina, the Worker reads the account’s plan from D1 and atomically applies its daily data allowance. The browser cannot choose or raise that allowance. The public one-address preview uses a separate Turnstile check, short-lived cache, and global capacity limits. The portfolio is normalized into a combined view after provider results return.

Ask Retina

  • Private mode calculates from the selected snapshot in your browser.
  • Local AI runs the interpretation model on your device where supported.
  • Cloud AI sends your question and a compact set of relevant facts to Gemini.
Choose the mode that matches the question and your privacy preference.

Account deletion

Stop future renewals before deleting an account. Retina will not delete the account while its payment wallet can still renew a subscription. Deleting your Retina account revokes access immediately and schedules deletion of saved portfolio data, sign-in identities, and access grants. Data stored only in the current browser remains until you clear or replace it. Payment records are handled separately, because they are what a later dispute is settled from. Retina removes the payment identity straight away: wallet addresses, the details submitted at checkout, and the sender of any payment received. The amount, plan, date, and network remain as payment evidence and identify nobody. The blockchain transaction reference is kept for twelve months, so a payment can still be traced if you ask about it after the account is gone, and is removed after that. If a paid plan ends without being renewed, Retina keeps the data for 90 days and tells you before removing it. If Retina holds no way to reach you, neither an email address nor a linked messaging account, that message cannot be sent, so the data is kept for a year from the end of the plan and then removed. The ended-plan screen shows the same information to anyone who signs in during that time. Download a full backup first when you want a recoverable copy. Last verified: 8 September 2026.
Last modified on September 14, 2026