Template — not yet legal advice. Review with counsel and tailor to your jurisdiction (GDPR, CCPA/CPRA, etc.) before launch.
| Data | Why |
|---|---|
| Email + password hash | Account & authentication |
| Encrypted broker/API credentials | To fetch quotes / place orders you authorize (AES-256-GCM at rest) |
| Trading activity, signals, settings | Core functionality |
| Audit/log events, IP | Security & compliance |
To operate the Service, secure accounts, and improve functionality. We do not sell personal data.
We share the minimum necessary with: Anthropic (AI), Alpaca (market data/brokerage), Google / Microsoft / Meta (optional email & messaging integrations you enable), Neon (database), Railway (hosting). Each has its own privacy terms.
Data is stored in our database (Neon) and processed on Railway. Secrets are encrypted at rest. We retain data while your account is active and prune operational data on a rolling basis.
Subject to applicable law, you may request access, export, correction, or deletion
of your personal data, and withdraw consent. Account deletion purges your personal data (audit
records may be retained or anonymized as required for security/compliance). Contact
[operator contact email].
The app uses browser local storage and a service worker (PWA) for preferences and offline shell — not third-party advertising trackers.
We may update this policy; material changes will be surfaced in-app.