What we collect, why, and the lines we never cross — including how advertising attribution works and how to erase everything.
Last updated: June 2026
Account data (email, name, hashed password), subscription/billing data processed by Stripe (we never store card numbers), broker API keys you connect (encrypted with AES-256-GCM, marked trade-only), trading activity generated on your behalf (orders, positions, equity), and usage analytics (pages viewed, device type, country, referral source and advertising click identifiers such as fbclid/gclid/ttclid when you arrive from an ad).
To operate the service (execute and display your trading activity), bill your subscription, secure your account, improve the product, and measure advertising performance. We use advertising pixels (Meta, Google, TikTok) to attribute sign-ups to campaigns; these providers may set cookies subject to their own policies.
We never sell your personal data. We never store broker keys in plaintext, never request withdrawal-enabled keys, and the AI decision layer never receives your credentials.
Account data is retained while your account is active. You can delete your account and all associated data at any time — see Data Deletion. Trade records may be retained where required for legal/audit obligations, in anonymized form where possible.
Broker keys are encrypted at rest (AES-256-GCM) and only decrypted in-memory at order time inside our private trading engine. All traffic is encrypted in transit. Internal services authenticate each other with signed requests.
Depending on your jurisdiction (GDPR/CCPA), you may have rights to access, correct, export, or erase your personal data, and to object to processing. Exercise them from your account (Data Deletion) or by contacting support.