Basis

Privacy Policy

Effective August 9, 2026 · Private beta

What we collect

Sign-in identity from Google (name, email, profile image) to authenticate you against the access allowlist. Portfolio content you create: theses, holdings, watchers, recommendations, settings, and trade logs. Broker connection data you provide: API keys, OAuth tokens, and endpoint configuration.

How credentials are stored

Broker API keys and tokens are encrypted at rest with AES-256-GCM before they touch the database. Application data lives in a MongoDB instance on Railway reachable only over the project's private network. Transport is TLS end to end.

Third parties

Brokerage requests go to the brokerage you connect (currently Alpaca) under its privacy policy. Basis stores only your API credentials, encrypted at rest. Market data requests are made server-side to quote providers and contain ticker symbols, not your identity.

What we do not do

No selling or sharing of personal data. No advertising, no trackers, no analytics scripts. The only cookies are the session cookies required for sign-in.

Retention and deletion

Data persists while your account has access. Disconnecting an integration deletes its stored credentials. For full deletion of your data, email the contact below and it will be removed from the live database.

Security caveat

This is a private beta run on commodity cloud infrastructure. Reasonable measures are in place (encryption at rest for secrets, allowlisted auth, private networking), but no system is breach-proof. Do not store credentials you cannot rotate.

Contact

Privacy questions or deletion requests: perthecther@gmail.com.

Terms of Service · Home