The short version: this is a personal tool on one machine. It keeps the
least it can get away with, sells nothing, and shares nothing. There is no data team here.
There is a dog.
What is stored
An access token for your Alpaca account, granted by you through Alpaca's
authorization screen. This is what lets the software trade. It is stored on the operator's
machine in a file readable only by that account.
Your name and email, only if the operator entered them when inviting you, and only
so they can tell whose bot is whose.
Trading records โ the positions and trades made on your account, kept so the
dashboard can show you your own history.
A dashboard link token, stored as a one-way hash, so the software can tell a valid
link from an invalid one without holding the link itself.
What is not stored
No API keys. Authorization happens on Alpaca's page; no key is ever typed into or
transmitted to this software.
No passwords, for anything.
Not your watchlist. The symbols you choose are written to a watchlist in
your own Alpaca account and read back from there. No copy is kept here.
No analytics, no tracking, no cookies beyond a single sign-in cookie for the
operator's own admin page. Nothing is loaded from third-party servers.
Who it is shared with
Nobody. Nothing is sold, rented, or handed to advertisers, data brokers or anyone
else. The only third party involved is Alpaca itself, because that is where your account lives
and where orders are sent โ their handling of your data is governed by their own policy.
If you run Classic V2 or Turbo iRD, anonymized trade outcomes (market readings, % results
and timestamps โ never your account, balances, trade sizes or name) are pooled on this machine
with everyone else who runs those engines, to improve the shared engines.
Where it lives
On a single machine operated by one person. It is not replicated to a cloud service, and
there is no analytics pipeline. That also means the usual caveat: a personal machine is not a
hardened data centre, which is part of why the software deliberately holds as little as it
does, and why it can never move your funds.
Your control
Revoke any time from your Alpaca dashboard. Access stops immediately and the
stored token becomes useless.
Ask for deletion. Contact the operator and your invite record, token and stored
trading records will be removed.
Stop the bot yourself from your dashboard, without revoking access, if you just
want it to pause.
Children
This is not for anyone under 18, and is not directed at them.
Questions, or to request deletion: the person who invited you