1. Scope and contact
This Policy covers information processed by CustomTrading.ai. Brokerage firms, sign-in providers, and websites you visit through external links have their own privacy practices and responsibilities. Authorizing a connection does not replace the broker’s privacy policy or customer agreements.
Questions and privacy requests can be sent to accounts@customtrading.ai. Our Terms of Use describe the conditions for using the Service.
2. Information we collect
The information involved depends on the features you use. We receive information from you, from providers you authorize, and through the operation of the Service.
- Account and profile information
- Your name, email address, default brokerage-connection email, account identifier, verification status, and account creation or update dates. Google or Apple sign-in supplies identity-verification information, such as an email address, name when available, and a sign-in token. An Apple private relay address may be used when you choose to hide your email.
- Authentication information
- Salted password hashes for password-based access; hashed session, verification, and recovery tokens; and related expiration and usage records. We process the password you enter to authenticate you, but do not store it as readable text.
- Brokerage-connection information
- The broker name, connection email and status, authorization scope, provider-issued access credentials, expiration times, verification timestamps, and account references returned by an authorized provider. Depending on the provider and permissions you grant, account references may include account numbers and associated provider-issued identifiers. These references are stored with the encrypted authorization credentials.
- Strategies and signal activity
- Strategy names; selected securities, exchanges, and sectors; screening criteria; entry and exit conditions; time-zone and timing settings; alert and action preferences; and evaluation inputs and results. Saved signal records include the security, direction, price, event time, and reasons for a signal.
- Technical and service information
- Our hosting and service providers process information needed to deliver and protect requests, such as IP addresses, browser or device information, request times and paths, and diagnostic or security information. Cookies used for sessions and authorization are described below.
- Communications
- The contact details, request contents, and attachments you choose to send us, and information needed to deliver account verification, password recovery, and service messages.
Our current brokerage-connection features do not retrieve balances, holdings, transaction histories, or tax documents. We do not ask for your brokerage login password, Social Security number, or government identification to establish a brokerage connection. Please do not include those details in support messages.
3. How we use information
- Create and maintain accounts, authenticate users, verify email addresses, and recover account access.
- Save your strategies and preferences, retrieve permitted market data, run requested evaluations, and display signal history.
- Establish, verify, refresh, and troubleshoot brokerage connections that you authorize.
- Provide support, communicate about your account, diagnose errors, and maintain the Service.
- Protect accounts and systems, investigate abuse, enforce our Terms, and comply with applicable legal obligations.
We use brokerage access information to provide your connected features. We do not use that information to make discretionary investment decisions or place live trades. We do not sell personal information or share it for cross-context behavioral advertising, and we do not use brokerage account information for advertising.
4. Brokerage authorization and revocation
When you connect a supported brokerage, authentication and authorization follow the broker’s approved process. We receive provider-issued credentials, such as access and refresh tokens, that allow our server to verify the account connection and, where supported, renew access while authorization remains valid. Market scans and price history come from EODHD. We do not receive or store your brokerage login password.
Market scans do not use your brokerage authorization. Requests to a connected brokerage are limited to its account-connection features and include the credentials required to authorize them. The broker can associate those requests with the authorization it issued. Review the permissions presented by the broker; they may be broader than the information our current features retrieve.
To stop future authorized access, revoke CustomTrading.ai in your broker’s connected-app or authorization settings. Signing out of our website does not revoke that permission. You can also request removal of stored connection information by emailing accounts@customtrading.ai. Revocation stops future access under that authorization but does not automatically erase information already stored. Retention and deletion are addressed below.
5. When information is disclosed
Information is disclosed as needed for the following purposes:
- Hosting and operations. Infrastructure providers, including Cloudflare, process website requests and store application records to deliver, maintain, and secure the Service.
- Account email. Resend processes recipient addresses, message contents, and delivery information for account emails. Verification and password-recovery messages contain the links needed to complete those actions.
- Sign-in providers. Google and Apple process information needed for their sign-in services. Google’s sign-in component can load on sign-in and registration pages and receive technical information when it loads, even before you choose that sign-in option.
- Brokerages and market-data providers. We exchange authorization and request information with brokers you connect and request stock-directory and market data from supported providers. Brokerage credentials are used only with the provider that issued them or its authorized connection service. They are not sent to unrelated market-data providers, and your CustomTrading.ai password is not included in market-data requests.
- Your instructions. We may disclose information when you ask us to do so or authorize a particular feature or recipient.
- Legal and security needs. We may disclose relevant information when reasonably necessary to meet a legal obligation, respond to valid legal process, protect rights or safety, investigate abuse, or establish or defend legal claims.
- Business changes. If the Service is involved in a merger, financing, acquisition, or transfer of assets, relevant information may be disclosed in connection with that transaction, subject to applicable confidentiality and privacy requirements. We will provide notice of changes affecting your information when required.
Independent providers handle information under their own agreements and policies. We do not make your private strategies or brokerage account references publicly available through the Service.
6. Strategy calculations and AI
The current strategy and signal features evaluate rules in the application. They do not send your saved strategies, brokerage account references, or authorization tokens to an external AI model provider. The Service does not make automated credit, lending, employment, or account-eligibility decisions about you.
If we introduce a feature that sends personal information to an external AI provider, we will explain the information and purpose before that processing begins and obtain consent where required. A description of AI-assisted tools does not itself authorize unrelated use of your financial information or model training.
8. Retention and deletion
We retain account information, saved strategies, signal records, and connection information while they are needed to provide your account and requested features. Retention also depends on the information’s sensitivity, account status, security needs, support issues, legal obligations, and the need to resolve disputes or enforce agreements.
Token expiration limits the validity of a session or authorization; it does not by itself delete stored records. Revoking broker access, closing an account, and requesting deletion are distinct actions.
On a verified deletion or account-closure request, we delete or deidentify information no longer needed, subject to applicable exceptions. We may retain records necessary for legal obligations, security investigations, fraud prevention, or legal claims. Any copies remaining in backups are subject to the applicable backup lifecycle and are not used to resume ordinary account operations. We will explain a relevant retention exception when responding to your request where required by law.
9. How information is protected
The Service uses HTTPS, salted password hashing, hashed session and recovery tokens, and authorization checks for account-specific records. Brokerage authorization credentials and stored account references are encrypted before they are saved. Connection requests use time-limited state checks to help prevent unauthorized authorization responses.
No system, transmission, or storage method can be guaranteed completely secure. Protect your devices and email account, choose a unique password, and use the security controls your sign-in and brokerage providers offer. Report suspected unauthorized access to accounts@customtrading.ai. We will provide notices about security incidents when required by applicable law.
10. Your choices and privacy rights
You can review your profile and edit available fields on the Account page, manage your password on the Change password page, and decide whether to authorize a brokerage connection. For other corrections, a copy of your information, account closure, or deletion, email accounts@customtrading.ai.
Depending on where you live and whether a law applies to our processing, you may have rights to access, correct, delete, or obtain a portable copy of personal information; object to or restrict certain processing; withdraw consent; limit certain uses of sensitive information; or opt out of sale, sharing, or targeted advertising. Applicable law may also allow an authorized agent, an appeal of a denied request, or a complaint to a privacy regulator. We will not unlawfully discriminate against you for exercising those rights.
Send requests from your account email when possible, identify the action you want, and provide enough information for us to locate your account. We may reasonably verify your identity or an agent’s authority before disclosing, changing, or deleting information. Do not send a password, access token, or full financial account number. We respond within the time required by applicable law and explain any lawful limitation. To appeal a response where available, reply to our response with “Privacy appeal” in the subject.
California residents can find additional information in the California Attorney General’s privacy-rights guidance. Rights depend on the applicable law; this Policy does not represent that every privacy law applies to every account.
11. Processing locations
Our infrastructure and service providers may process information in the United States and other countries where they operate. Privacy protections can differ between countries. Any cross-border processing remains subject to applicable legal requirements. Using the Service does not waive privacy rights that apply to you.
12. Children’s information
The Service is intended for adults 18 and older, and is not directed to children. We do not knowingly seek personal information from anyone under 18. If you believe a child has provided information, contact us at accounts@customtrading.ai so we can investigate and take appropriate steps to remove it.
13. Changes to this Policy
We will update this Policy when our practices change and revise the effective date above. For material changes, we will provide additional notice through the Service or another appropriate channel when required by law. Where a new use of information requires consent, we will obtain that consent before applying the new use. An update does not remove rights you already have under applicable law.
14. Contact CustomTrading.ai
For privacy questions, access or deletion requests, and concerns about brokerage information, email accounts@customtrading.ai. Include your account email and a brief description of the request. Keep passwords, authorization tokens, and complete account numbers out of your message.