Skip to content

Why a Portfolio App Needs Its Own Lock

6 min read · Verified September 2026

A device passcode protects your phone while it is locked. An app lock protects your portfolio while the phone is unlocked and in someone else's hands. It guards the display of information, not the assets: a read-only tracker holds no ability to move funds regardless of who opens it.

The usual objection is reasonable. The phone has a passcode, the passcode is good, so why lock an app that cannot move money anyway?

Because the passcode covers a scenario that mostly does not happen, and leaves uncovered the one that does. Almost nobody's portfolio is exposed by a stranger cracking a locked handset. It is exposed on an unlocked handset, held by someone who was standing next to you thirty seconds ago.

What does an app lock add over a device passcode?

A device passcode is a boundary at the door. Once crossed, everything inside is open, and it stays open for as long as the session lasts. That model assumes the person holding the unlocked phone is you.

Consider how often it is not. You hand the phone to a friend to show a photo and they swipe. A colleague glances across during a meeting while the phone sits face-up on the table. You pass it to a shop assistant, a mechanic, a family member who wants to look something up. A partner picks it up in the evening. At the sharper end, the dominant pattern in urban phone theft is now snatching a device that is already unlocked and in use, then keeping it awake, which makes the passcode irrelevant from the first second.

An app lock reintroduces a boundary inside the unlocked session. The phone opens; the portfolio does not. That is a small, specific gain, and it happens to cover precisely the situations where portfolios actually get seen.

Face or fingerprint on open, set once, enforced on that device only.

Who is this actually protecting you from?

Worth being concrete, because the answer changes what settings you bother with.

Shoulder surfing. The most common by far and the least dramatic. Someone sees a six-figure total on a screen you were not thinking about. The consequence is rarely theft and often something more awkward and more lasting: a colleague, a relative or an acquaintance now knows a fact about your finances you did not choose to share.

The handed-over phone. A distinct problem, because the person is holding the device with your permission and swiping is not a hostile act. An app lock is the only thing that draws a line here, since you cannot supervise every tap without being strange about it.

Shared and household devices. A tablet that lives on the sofa is a different risk profile from a phone in your pocket. Keeping one portfolio across devices covers running both, and the tablet is the one that most needs the lock.

A snatched or lost device. Here the app lock buys you time rather than safety. Time is the thing you need: enough to sign out of the session remotely, delete API keys at the exchanges, and change passwords. How to revoke an API key covers doing that quickly and in the right order.

Notice what is absent from that list. An app lock does nothing against a compromised device, where malware runs beneath the app and reads the screen regardless. It does nothing against a breach at the company holding your data. It is a defence against people in your physical vicinity, which is a real category and a narrow one.

Where do biometrics fall short?

Face and fingerprint unlock are convenient enough that they get used, which is most of their value. They are not strong authentication, and the gaps are worth knowing.

A face can be presented without your cooperation. Holding a phone up to a sleeping or unwilling person defeats face unlock unless attention detection is enabled, and attention detection is a setting many people switch off because it is fussy. A fingerprint has the same property with a hand.

Enrolment is broader than people remember. Whatever faces and fingerprints the device has registered will satisfy the app lock, so the partner's face added for convenience two years ago passes it today. Open your device's biometric settings and read the list; almost everyone finds something they had forgotten.

The fallback is usually the weakest link. When biometrics fail, most app locks fall through to the device passcode, which means the app lock inherits whatever strength that passcode has and whatever exposure it has already suffered. If someone has watched you enter a four-digit code on a train, both layers are gone at once. Where an app offers a separate secret for its lock, that separation is worth more than the biometric convenience on top of it.

There is a legal dimension that varies by country. Courts in some jurisdictions have treated compelled fingerprint or face unlock differently from compelled disclosure of a passcode, and the position is unsettled and changing. If that matters to your situation, look up where your own jurisdiction currently stands rather than assuming.

What does an app lock not protect?

The assets. This is the part to be unambiguous about, because a lock icon invites people to believe more than it delivers.

A portfolio tracker connected read-only holds no private keys and no withdrawal permission. Somebody who defeats the app lock sees numbers. They cannot sell your position, move a coin, or withdraw anything, because the exchange rejects those requests regardless of who is holding the phone. Is it safe to connect an exchange covers why the enforcement sits at the exchange rather than in the app.

What they gain is information, and information about a crypto balance has value to the wrong person. It supports tailored phishing, it identifies you as worth a social-engineering attempt, and in rare and serious cases it identifies you as worth coercing. What a tracker can see sets out the full extent of what is visible.

So the honest description is that an app lock protects the display of information, not the holdings. That is still worth having, and it is worth pairing with the other places the same information leaks:

  1. Turn the app lock on, on every device you sign in on, including tablets.
  2. Audit enrolled biometrics in device settings and remove faces and fingerprints that are not yours.
  3. Set notification previews to appear only when unlocked, at the operating system level. An alert that renders your portfolio value on a lock screen defeats everything above it.
  4. Decide where the Portfolio widget lives. Widgets render without opening the app, so a balance widget on a lock screen is a balance shown to anyone who wakes the phone. Price and news widgets carry no personal data; crypto widgets covers what each one shows.
  5. Shorten the screen auto-lock to thirty seconds or a minute. It is the cheapest control on this list and the one people never touch.

Do it in the first minute on any new device, before the portfolio is even populated. Restoring on a new phone covers the rest of that sequence, and the app lock is the item most reliably postponed into never.

Common questions

No, because they cover different moments. A passcode protects a phone nobody has unlocked. An app lock protects a phone that is unlocked and in someone's hands, which describes almost every situation where a portfolio is actually seen by the wrong person.

Not through a read-only tracker. It holds no withdrawal permission and no private keys, so there is no path from the app to your funds. What they gain is knowledge of what you hold, which is a targeting risk rather than a theft.

No, and it should not. Biometric enrolment belongs to one handset, so a lock that followed your account onto another device would be meaningless there. Set it separately on every device you sign in on, including tablets.

Yes, and people forget this constantly. An app lock validates against whatever biometrics the device has enrolled, so a partner's face or a child's fingerprint added for convenience passes your app lock too. Check the enrolled list in your device settings.

Effectively, yes. A widget renders on the home or lock screen without opening the app, so a Portfolio widget showing your total is visible to anyone who wakes the phone. Keep price and news widgets there if you like, and think carefully before putting your balance on a lock screen.

It depends on the threat. A PIN resists someone holding the phone up to your face; a biometric resists someone who watched you type. Most app locks fall back to the device passcode when biometrics fail, which means the lock is only as strong as a passcode somebody may already have seen you enter.

Biometric app lock, read-only connections and no ability to move funds. Set it up in the first minute.

Keep reading

← All guides