Privacy Policy

Last updated July 6, 2026

This Privacy Policy explains what information Stock Rankingscollects, how it's used, and the choices you have. The Service is currently in active development with limited access (see our Terms of Service).

Information we collect

  • Account information: email address and a hashed password (or OAuth identity), plan and subscription status.
  • Portfolio & holdings data: positions, transactions, and valuations you connect via portfolio tracker sync, manual entry, or CSV import.
  • Brokerage credentials: if you connect Alpaca, your API keys are encrypted at rest (AES-256-GCM) and used only to call the Alpaca API on your behalf.
  • Third-party sync credentials: authentication tokens for your connected portfolio tracker, encrypted at rest, used only to sync your portfolio.
  • Billing information: handled directly by Stripe; we store your subscription status and Stripe customer/subscription IDs, not your card number.
  • Usage & diagnostic data: basic application logs (errors, request metadata) used for operating and debugging the Service.

How we use information

To operate the Service (sync your portfolio, run the features you use), to process billing, to communicate with you about your account (email verification, password reset, billing receipts), and to maintain and improve reliability.

AI features & third-party providers

When you use the AI Council or the automated Alpaca manager, relevant portfolio data is sent to the AI provider configured for your account (for example OpenRouter, or a locally run model) to generate a response; automated trading calls are sent to Alpaca's brokerage API. If you connect an AI assistant via MCP, the portfolio data returned by its scoped tools is delivered to that assistant (and its AI provider) under an OAuth grant you authorize and can revoke; its write access is limited to a small sanctioned tool set, and every write is logged as a reviewable activity event. We use Stripe for billing and an email provider to send transactional email. We don't sell your data to anyone.

Data security

Sensitive credentials (portfolio tracker sync tokens, Alpaca keys) are encrypted at rest. The Service is a single-tenant, private deployment — your data isn't pooled with other customers' data beyond the underlying database.

Data retention & deletion

We retain your data for as long as your account is active. You can request deletion of your account and associated data by contacting us.

Children's privacy

The Service isn't directed at, or intended for use by, anyone under 18.

Changes to this policy

We may update this Policy as the Service evolves; we'll update the "last updated" date above when we do.

Contact

Questions about this Policy: support@dataconnector-pro.com.