Privacy Policy

Effective date: February 1, 2026 · Last updated: August 21, 2026

1. Information We Collect

TradeAiFi, Inc. ("TradeAiFi," "we," "us") collects the following categories of data:

  • Account Information: Name, email address, phone number (for SMS alerts), and a salted+hashed password (we never store the plaintext).
  • Authentication Data: Session tokens, device fingerprints used to detect account takeover attempts, and (for SSO users) the OAuth subject identifier returned by Google.
  • Financial Account Data: Brokerage account identifiers, API tokens (encrypted at rest), positions, balances, order history, and trade confirmations retrieved on your behalf from connected brokers (Tradier, SnapTrade, etc.). We never store full bank account or card numbers.
  • Trading Activity: Watchlists, trade journal entries, strategy configurations, signal subscriptions, AI signal interactions, and (in Alpha Auto mode) automated order intent recorded prior to broker execution.
  • Payment Information: Processed and stored by Stripe, Inc. We receive only the last 4 digits of your card and your billing region. Full card numbers never touch our servers.
  • Device & Diagnostic Data: Browser type, IP address, device model, OS, app version, crash reports, and performance metrics used to debug and improve the service.
  • Voluntary Submissions: Support messages, survey responses, and feedback you choose to send us.

We do NOT collect: precise location, biometric identifiers, contacts, photos, microphone, calendar, SMS contents, or any sensitive personal data beyond what's listed above.

2. How We Use Your Information

  • Provide, maintain, and improve TradeAiFi platform features including AI signals, portfolio analytics, automated trading, and broker integrations.
  • Process subscription billing, handle refunds, send receipts, and reconcile broker commissions with your accounts.
  • Generate trade ideas and signals using large-language-model (LLM) reasoning — see Section 5 for the privacy boundary.
  • Send transactional notifications (signal alerts, trade confirmations, security alerts) via email, push, and SMS based on your preferences.
  • Detect, prevent, and respond to fraud, account takeover, abuse, and security incidents.
  • Meet our legal and regulatory obligations including 17 CFR 240.17a-4 financial recordkeeping where applicable.
  • Communicate about products, services, and promotional offers, only with your explicit opt-in.

3. Data Security

We implement defense-in-depth security:

  • TLS 1.2+ for all data in transit between your device and our servers.
  • AES-256 encryption at rest for brokerage API tokens and OAuth refresh tokens.
  • bcrypt password hashing with per-user salts; passwords are never stored in plaintext nor logged.
  • Short-lived session tokens with rotating refresh; password changes invalidate all prior sessions.
  • Rate-limited and IP-bounded authentication endpoints to prevent credential stuffing.
  • LLM prompt sanitization that strips proprietary scoring math and account identifiers before any third-party AI call.
  • Continuous security monitoring and regular third-party penetration testing.

No system is unbreachable. In the event of a data breach affecting your information, we will notify you within 72 hours per applicable law.

4. Data Sharing & Service Providers

We do not sell your personal data. We share information only with the following categories, under binding data processing agreements:

  • Brokerage partners (Tradier, SnapTrade, Alpaca, tastytrade): Only to execute trades and retrieve account data you explicitly authorize.
  • Payments (Stripe): Subscription billing.
  • AI processing (Anthropic Claude, OpenAI, Google Gemini): Anonymized prompts only — see Section 5.
  • Communications (Resend, Twilio, OneSignal/FCM): Transactional emails, SMS, and push notifications.
  • Cloud infrastructure (MongoDB Atlas, Emergent Cloud): Hosting and data storage.
  • Legal & safety: When required by valid legal process, subpoena, or to protect TradeAiFi or users from harm.
  • Aggregated leaderboard data: Pseudonymized performance stats may be visible to other users if you opt into public leaderboards. You always control what's shared.

4.b SMS / Text-Message Communications

When you opt into TradeAiFi SMS alerts inside your account's Notifications settings, the following is true of your data:

  • Strictly transactional. SMS is used only to send you trade-alert lifecycle events (entries, target hits, stop-losses), security codes, and account notifications. No marketing.
  • No third-party sharing. Your phone number and SMS opt-in data are never sold, rented, or shared with third parties for marketing purposes. The only third party that receives this data is our SMS provider Twilio, which processes messages under a binding data-processing agreement and is contractually prohibited from using your data for any purpose other than delivering messages you have requested.
  • Consent records. When you opt in, we log the timestamp, IP address, and the exact consent-checkbox copy shown to you. This record is retained for the life of your account plus seven (7) years to comply with TCPA recordkeeping rules.
  • Frequency & rates. Message frequency varies based on market conditions and your configured watchlist (typically 0–15/day for active traders). Standard message and data rates may apply per your carrier's plan.
  • Opt out at any time. Reply STOP to any TradeAiFi SMS, or toggle SMS off in your Notifications settings. Reply HELP for support information.
  • Eligibility. You must be 18 or older and the authorized user of the phone number provided.

Full SMS program terms live in our Terms of Service §11. Questions: support@tradeaifi.com.

5. AI / LLM Data Processing

TradeAiFi uses large language models (Anthropic Claude, OpenAI GPT, Google Gemini) to generate signals, reasoning, and trade ideas. Before any prompt leaves our servers, our Prompt Sanitizer module removes:

  • Account identifiers, email addresses, phone numbers
  • Brokerage account numbers and balances
  • Proprietary internal scoring math, GEX thresholds, and IV-spread algorithms
  • Other users' positions or activity

LLM providers may process your sanitized input under their respective data policies. We do not allow LLM providers to use your data to train their public models. See:

  • Anthropic: anthropic.com/legal/privacy
  • OpenAI: openai.com/policies/privacy-policy
  • Google: policies.google.com/privacy

6. Your Rights (GDPR & CCPA)

Regardless of where you live, you have the right to:

  • Access: Request a copy of every data point we hold on you.
  • Correct: Update inaccurate or incomplete data.
  • Delete: Permanently delete your account and all associated data via Settings → Danger Zone → Delete my account. Deletion completes within 30 days; certain financial transaction records may be retained for up to 7 years where required by 17 CFR 240.17a-4 or equivalent.
  • Port: Export your trading history, journal entries, and account data in machine-readable JSON.
  • Object & restrict: Stop us from processing your data for any purpose other than legal obligations.
  • Opt out of "sale" (CCPA): We do not sell personal information. If we ever change this, you'll see a "Do Not Sell My Personal Information" link in the footer.
  • Withdraw consent: For optional marketing communications, at any time via Settings → Notifications.

To exercise these rights, email privacy@tradeaifi.com or use the in-app self-service controls. We respond within 30 days. EU/UK users may also file complaints with their supervisory authority.

7. Cookies & Tracking

We use only essential cookies for authentication, session management, and CSRF protection. We do not use third-party advertising trackers, fingerprinting beacons, or cross-site behavioral profiling. Server-side analytics are aggregated and never combined with personally-identifying information.

8. Data Retention

We retain your data as follows:

  • Active accounts: Indefinitely, while you continue to use the service.
  • Deleted accounts: Personal data is purged within 30 days of deletion request.
  • Financial transaction records: Up to 7 years post-deletion where required by 17 CFR 240.17a-4 or equivalent.
  • Audit logs: Retained for fraud detection but anonymized within 30 days of account deletion.
  • Backups: Encrypted backups expire within 90 days.

9. Children's Privacy (COPPA)

TradeAiFi is intended for users aged 18 and older. We do not knowingly collect personal information from anyone under 13. If you believe we have inadvertently collected data from a minor, contact us at privacy@tradeaifi.com and we will delete it immediately.

10. International Transfers

If you access TradeAiFi from outside the United States, your information may be transferred to and processed in the U.S. We rely on Standard Contractual Clauses or equivalent transfer mechanisms approved by the European Commission for EU/UK data subjects.

11. Changes to This Policy

We may update this policy as the service evolves. Material changes will be announced via in-app notification or email at least 30 days before they take effect. Continued use after a change indicates acceptance of the updated terms.

12. Contact

TradeAiFi, Inc.
Privacy inquiries: privacy@tradeaifi.com
Support: support@tradeaifi.com
Data Protection Officer (EU/UK matters): dpo@tradeaifi.com

Investment Risk Disclosure

TradeAiFi provides software, AI-generated analytics, and trade idea workflows. TradeAiFi is not a registered broker-dealer or investment advisor and does not provide personalized investment advice. All signals, trade ideas, and portfolio suggestions are informational, generated by automated systems, and may be incorrect or incomplete. Trading securities and cryptocurrencies involves substantial risk including possible total loss of principal. Past performance does not guarantee future results. You are solely responsible for your own investment decisions. Consult a licensed financial professional before trading.

Not financial advice — for educational purposes. Trade at your own risk. Learn more