Privacy Policy
Effective August 9, 2026 · Private beta
What we collect
Sign-in identity from Google (name, email, profile image) to authenticate you against the access allowlist. Portfolio content you create: theses, holdings, watchers, recommendations, settings, and trade logs. Broker connection data you provide: API keys, OAuth tokens, and endpoint configuration.
How credentials are stored
Broker API keys and tokens are encrypted at rest with AES-256-GCM before they touch the database. Application data lives in a MongoDB instance on Railway reachable only over the project's private network. Transport is TLS end to end.
Third parties
Brokerage requests go to the brokerage you connect (currently Alpaca) under its privacy policy. Basis stores only your API credentials, encrypted at rest. Market data requests are made server-side to quote providers and contain ticker symbols, not your identity.
What we do not do
No selling or sharing of personal data. No advertising, no trackers, no analytics scripts. The only cookies are the session cookies required for sign-in.
Retention and deletion
Data persists while your account has access. Disconnecting an integration deletes its stored credentials. For full deletion of your data, email the contact below and it will be removed from the live database.
Security caveat
This is a private beta run on commodity cloud infrastructure. Reasonable measures are in place (encryption at rest for secrets, allowlisted auth, private networking), but no system is breach-proof. Do not store credentials you cannot rotate.
Contact
Privacy questions or deletion requests: perthecther@gmail.com.