Wallet Connect would have brought a different risk class into the app
The exchange sync Folanza offers works with read rights the exchange itself enforces technically — the API key simply can't do more than read. Wallet Connect protocols are built differently: they come from a world where users constantly approve signature requests from unfamiliar dApps, and where a "read-only" request can look almost identical to one that actually grants access to funds. I don't want to put anyone through that risk of confusion inside Folanza. A portfolio tracker should show your holdings, not become another place where you click to approve things.
On-chain tracking would have meant knowing my users' wallet addresses
Technically, I could query public wallet addresses anonymously through a blockchain indexer without tying them to a name. But that's not really the point — the point is what this feature opens up structurally. The moment Folanza accepts wallet addresses, I know which addresses belong to my users, even if I don't know anything else about them. That's an attack surface and a trust promise I don't want to take on, just for the convenience of not having to enter an address yourself.
What that costs
Honestly: convenience. If you want to pull your holdings straight from the chain or a wallet, you have to enter them in Folanza manually or import them via a file. That's one more step than "connect wallet," and I don't want to downplay it. I offer opt-in sync for exchanges with their own read APIs, because there the risk class is different — for anything tied directly to your wallet or the chain, the path stays deliberately manual.
This is a deliberate choice
I'm not closing this gap later just because it becomes technically easier — it stays, because the risk class stays the same no matter how convenient the implementation gets. Folanza would rather keep growing along the paths that fit its core promise: file import, encrypted cloud backup, read-only sync with hard guardrails. A wallet address you don't give me, I can't know either — and that's exactly how it should stay.