Skip to main content
Skip to content

Privacy Policy

Last updated · 2026-04-12

§ 01 · Information we collect

AlphaDesk collects information necessary to provide our trading terminal service. This includes:

  • Account information. Username, email address, and hashed password credentials.
  • API credentials. Brokerage API keys (e.g., Alpaca) that you provide for trade execution. These are stored encrypted at rest.
  • Usage data. Trading activity, strategy configurations, and platform interaction logs.
  • Technical data. IP address, browser type, and device information collected automatically via server logs.

§ 02 · How we use your information

  • To authenticate and authorize access to the platform.
  • To execute trades and manage positions on your behalf through connected brokerage accounts.
  • To provide AI-powered analysis using configured AI services. Market data and strategy parameters may be sent to the configured provider for analysis. Every prompt is automatically scrubbed before transmission: usernames, client order IDs, broker order IDs, email addresses, and IP addresses are replaced with tokens such as <USER>, <ORDER_ID>, and <IP>. Where available we additionally rely on the provider’s zero-retention Enterprise plan so prompts and responses are not used for model training and are not retained beyond the live inference window.
  • To improve platform performance and reliability.
  • To communicate important service updates.

§ 03 · Data storage and security

Your data is stored on secure servers. We use industry-standard encryption for data in transit (TLS) and at rest. API keys are encrypted using AES-256 before storage. Access to production systems is restricted and audited.

§ 04 · Cookies

AlphaDesk uses essential cookies for authentication (session tokens). We do not use third-party tracking cookies or advertising cookies. Authentication cookies are HttpOnly and Secure.

§ 05 · Sub-processors

We engage the following sub-processors to deliver the service. Every entry below is a processor under GDPR Art. 28 / CCPA “service provider” terminology:

  • Alpaca Markets. Brokerage services for trade execution; receives symbol, quantity, side, order type, and limit / stop prices for orders you route through the platform. Subject to Alpaca’s privacy policy.
  • AI provider. AI analysis services. Prompts are PII-scrubbed before transmission (see section 02). Subject to the provider’s privacy policy.
  • Polygon.io. Market-data provider for real-time and historical equities / options quotes, trades, and aggregates. Receives symbol queries and request metadata only; no account identifiers leave the platform. Subject to Polygon’s privacy policy.
  • Financial Modeling Prep (FMP). Fundamentals, earnings calendar, and screener data. Receives symbol queries only; no account identifiers leave the platform. Subject to FMP’s privacy policy.

§ 06 · Your rights

You can exercise the following rights directly from the platform or by emailing [email protected]:

  • Access / portability (GDPR Art. 20). Authenticated users can call POST /api/v1/user/export to download a JSON bundle of every record AlphaDesk holds about them — trades, positions, watchlists, alerts, audit entries, and account settings.
  • Erasure (GDPR Art. 17). GET /api/v1/user/erase/preview shows the row counts that would be deleted; POST /api/v1/user/eraseperforms the cascade after password re-authentication. Records required by SEC 17a-4 minimum retention remain but are flagged as retained for compliance.
  • Request correction of personal data by emailing the address above.
  • Revoke API key access at any time through your brokerage provider.

§ 07 · Data retention

We retain account data for as long as your account is active. Trading history and analytics data are retained for regulatory compliance purposes. Upon account deletion, personal data is removed within 30 days, except where retention is required by law.

§ 08 · Children's privacy

AlphaDesk is not intended for users under 18. We do not knowingly collect data from minors.

§ 09 · GDPR compliance

If you are in the EU/EEA, you have rights under GDPR including access, rectification, erasure, and portability. Contact [email protected] to exercise these rights.

§ 10 · CCPA compliance

California residents have additional rights under CCPA. Contact us for data access or deletion requests.

§ 11 · Data breach notification

In the event of a data breach, we will notify affected users within 72 hours as required by applicable law.

§ 12 · International data transfers

Data may be processed in the United States. By using AlphaDesk, you consent to data transfer to the US.

§ 13 · Contact

For privacy-related inquiries, contact us at [email protected].

© 2026 AlphaDesk Labs · Not a broker-dealerα · Operator-grade execution