Privacy Policy

Effective: January 2026 · Version 2026-01

1. Information we collect

Account information: Name, email address, and password (stored as a one-way hash).

Brokerage credentials: API keys and tokens required to connect your brokerage account. These are stored encrypted at rest and are only used to execute trades on your behalf.

Usage data: Trade activity, setting changes, login events, and dashboard interactions.

Payment information: Billing details are processed and stored by our payment processor (Stripe). We do not store full card numbers.

2. How we use your information

We use your information to: operate and maintain the Service, execute trades within your defined parameters, process billing, communicate service updates, comply with legal obligations, and investigate fraud or security incidents.

3. Data sharing

We do not sell your personal information. We share data only with: your brokerage (as required to execute trades), Stripe (payment processing), and infrastructure providers (hosting, database) under confidentiality obligations. We may disclose information when required by law.

4. Brokerage access

Access to your brokerage account is limited to placing and monitoring trades within your configured parameters. We do not use this access for any other purpose. You can revoke access at any time by removing the API key from your brokerage account.

5. Data retention

We retain account data for the duration of your subscription plus 90 days after cancellation, then delete or anonymize it unless required by law to retain longer. Trade logs may be retained longer for compliance purposes.

6. Security

We use encryption in transit (TLS) and at rest for sensitive data. We perform regular security reviews. No system is perfectly secure; you are responsible for maintaining the security of your own account credentials.

7. Cookies and tracking

We use session cookies for authentication and minimal analytics to understand platform usage. We do not use cross-site advertising trackers. You can disable cookies in your browser, but this may affect Service functionality.

8. Your rights

You may request access to, correction of, or deletion of your personal data by contacting us. Deletion requests are fulfilled within 30 days, subject to legal retention requirements.

9. Children

The Service is not directed at persons under 18. We do not knowingly collect personal information from minors.

10. Changes to this policy

We may update this Privacy Policy. Material changes will be communicated by email or in-app notice before they take effect.

11. Contact

Privacy inquiries: privacy@autopilotoptions.com