Privacy policy
Last updated: August 11, 2026
Plain-English summary: We collect the minimum needed to run the service — your email, your choices (agents, broker, paper/live), encrypted broker API keys if you connect one, and an audit log of what the system did for you. On the phone that adds one thing: a push-notification token, and only if you allow notifications. We never sell your data, we never post your personal trades publicly (only the public model account is broadcast), and you can delete your whole account yourself in the app (Settings → Delete account) or by emailing hello@agentvest.ai.
This policy covers agentvest.ai, app.agentvest.ai, and the AgentVest apps for iOS and Android.
Information we collect
- Account: your email address, your name, and profile picture (provided by Google Sign-In or Sign in with Apple, or the email you enter), and a derived user id. If you sign up with a password we store a hash of it, never the password itself.
- Profile & enrichment: an optional, self-reported "about you" (your role, what you want your agent to do, rough portfolio-size band, how you heard about us) — none of it required — plus a company name we infer from your email's domain and a tag for how you first reached us. Used to support you and prioritize what we build; it never affects how your agent trades.
- Configuration: the agents you enable, broker choice, paper/live mode, approval mode, and risk-disclosure acknowledgements (versioned, timestamped).
- Broker credentials: API keys you paste to connect a brokerage (e.g. Alpaca). Stored encrypted at rest (Fernet via a server-side key) and used only to operate the features you enabled. We never see your brokerage username/password.
- Activity & audit: per-account audit logs (signals evaluated, orders placed/skipped, approvals, access grants) and position/P&L records needed to render your dashboard.
- Waitlist: the email you submit, with a source tag and timestamp.
- Technical: a session cookie (sign-in state), a first-party random
identifier (an
av_aidcookie on the app; a same-named localStorage value on this site) we use to count visits and measure our own signup funnel on our own servers, and standard server logs (IP, user agent, timestamps) from our hosting provider. No advertising trackers, no third-party analytics scripts — analytics data never leaves our infrastructure and is never sold or shared.
Mobile app (iOS and Android). The app signs in to the same account and reads the same data as the web dashboard — it never places an order itself. Beyond everything above, it involves exactly three device-level things:
- Push notifications: if you allow notifications, the app obtains an
Expo push token (an
ExponentPushToken[…]string that identifies this installation, not you) and sends it to us with your device platform — the literal stringiosorandroid. We store one row per device: token, platform, and the time it was last refreshed. We use it only to notify you about your own account (a signal fired, a co-pilot trade needs your confirmation, a position closed). Notification permission is asked for once, is optional, and can be revoked in your device settings — if you decline or revoke, no token is sent and the app works normally. Notification text is delivered by Expo (see below), so keep in mind that a notification's title and body pass through them. - Session tokens on the device: your access and refresh tokens are held
in expo-secure-store, which is the iOS Keychain / Android Keystore. To
be precise rather than flattering: we do not set a custom Keychain accessibility class,
so the library default applies — the entry is readable only while the device is
unlocked, and it can be carried to a new device by an encrypted device backup
or restore. Signing out or deleting your account clears it. (A web build of the same
code exists for our own dev and testing; there the tokens fall back to
localStorage, which is not encrypted.) - Which platform you signed in from: sign-in requests carry a
sourcetag (ios,android, orweb), recorded as your signup source and in your audit log.
What the app does not do: it asks for no location, contacts, photos, camera, microphone, or health data; it does not read your device's advertising identifier; and it contains no third-party analytics, advertising, or crash-reporting SDK. Notifications are the only permission it ever requests, and we do not track you across other apps or websites.
How we use information
- Operate the service: run the agents you enabled, place orders you authorized, render your dashboard, mint your MCP token.
- Safety and integrity: enforce risk limits, audit what the system did, prevent abuse.
- Communications: transactional messages about your account. If we ever send marketing, it will be opt-in with one-click unsubscribe.
- Legal compliance and record-keeping.
We do not sell or rent personal information, and we do not share it with third parties for their own marketing.
The public model account vs. your account
AgentVest broadcasts the trades of its own model account to the public dashboard, Telegram, and X. Your trades, positions, and P&L are private to your dashboard and are never published.
Who processes data on our behalf
- Fly.io — application hosting and storage (US region).
- GitHub Pages — serves this static site.
- Google — sign-in (OAuth); we receive your email/name, never your password.
- Apple — Sign in with Apple in the iOS app. We receive an identity token containing a stable Apple user id and, on your first authorization only, an email address (which may be an Apple private-relay forwarding address) and the name you chose to share. Apple never receives your AgentVest activity.
- Expo — push-notification delivery for the app (Expo fans out to Apple's APNs and Google's FCM). Expo receives your device push token and the title, body, and payload of each notification we send you; nothing else about your account.
- SnapTrade — read-only brokerage aggregation, used only if you link an outside brokerage to track it. You sign in to your broker inside SnapTrade's own hosted portal, so your brokerage username/password never reach us; we hold an opaque user secret (encrypted at rest) plus a connection id, and read positions and balances. This link is read-only — it cannot place orders.
- Alpaca / your broker — executes trades in your account under your API keys.
- Anthropic (Claude) / AI providers — used for research enrichment (e.g. scoring news headlines). Headlines and market data are sent; your personal data is not.
- Stripe — payment processing if/when paid tiers launch; card details go directly to Stripe and never touch our servers.
Retention and deletion
We keep account data while your account is active. Disconnecting your broker (or unlinking SnapTrade) removes that access immediately without deleting the rest of your account.
Deleting your account — the primary route is in the app: Settings → Delete account. It asks you to confirm, then permanently erases your entire record: profile and configuration, encrypted broker credentials, position and trade history for every book, pending signals, your audit log, registered push tokens, and any practice book. Sessions on your other devices are revoked at the same time. It is irreversible — there is no undo and no recovery window. If you would rather not use the app, email hello@agentvest.ai from your account email and we will do the same thing.
What deletion does not do: it cannot close, sell, or unwind positions that already exist in your own brokerage account. We never had custody of them — deleting your record only stops our agents from managing them, and any protective stop orders already resting at your broker stay there. Positions and orders at your broker remain yours to manage with your broker.
After a deletion, the only trace we keep is a server log line recording that an account was deleted, plus anything we are required to retain by law or to resolve a dispute.
Security
- TLS everywhere; secure session cookies.
- Broker keys encrypted at rest; secrets held in the hosting provider's secret store, never in source control.
- Per-user data isolation with path-traversal guards and redacted logging.
No system is perfectly secure; if a breach affecting your data occurs, we will notify you as required by applicable law.
Your rights
Depending on where you live (e.g. California, EU/UK), you may have rights to access, correct, export, or delete your personal information, and to non-discrimination for exercising them. Deletion you can do yourself at any time (see section 05); for anything else, email hello@agentvest.ai and we will honor verified requests. We do not respond to browser "Do Not Track" signals because we do not track you across other sites.
Children
The service is not directed to anyone under 18, and we do not knowingly collect data from minors.
Changes to this policy
We will update this page as the service evolves; the "Last updated" date reflects the current version. Material changes to how we handle existing data will be notified to account holders by email.
Contact
Privacy questions or requests: hello@agentvest.ai.