Privacy Policy
Last updated: May 2026
This Privacy Policy explains how Spell ("we," "us") collects, uses, and protects information when you use Spell Trade Pro (the "Service").
1. Information We Collect
1.1 Information you provide
- Account information: name, email, organization (when you sign up).
- Brokerage credentials: API keys you supply to connect a third-party brokerage account.
- Watchlists, strategies, and notes you create within the Service.
1.2 Information collected automatically
- Usage telemetry: pages viewed, features used, error logs.
- Audit-log events: every signal, AI prompt, kill-switch toggle, and order action.
- Device information: browser version, operating system, IP address (logged for security).
2. How We Use Information
- To operate, secure, and improve the Service.
- To provide AI-generated analysis on securities you choose to research.
- To send service notifications (security alerts, billing, important changes).
- To comply with legal obligations.
3. AI Processing
When you trigger AI features, relevant context (e.g., a ticker symbol and the cached OHLCV data for that ticker) is sent to our AI provider (currently Anthropic) to generate the analysis. We do not send your brokerage credentials, account balance, or holdings to the AI provider.
4. Brokerage Credentials
Brokerage API keys you connect are stored encrypted at rest. They are used only to make read or order-placement calls on your behalf, and only when you trigger an action. They are never shared with third parties.
5. Data Sharing
We do not sell your personal data. We share data only with:
- Your selected brokerage (when you place an order).
- Our AI provider (analysis context only - see Section 3).
- Infrastructure providers (hosting, error monitoring) under data-processing agreements.
- Authorities when legally required.
6. Cookies & Local Storage
We use a minimal set of cookies and local-storage values for session management and UI preferences. We do not use third-party advertising cookies.
7. Your Rights
You can:
- Access, correct, or delete your account data.
- Export your watchlists, strategies, and audit log.
- Disconnect your brokerage at any time.
- Close your account; we will delete personal data within 30 days, subject to legal retention requirements.
8. Security
- Brokerage credentials are encrypted at rest.
- All traffic is encrypted in transit (HTTPS/TLS).
- Audit logging is append-only and immutable.
- Production access is restricted to authorized personnel.
9. Children
The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal data from minors.
10. International Users
The Service is currently offered to users in the United States only. If you access the Service from outside the United States, you do so on your own initiative.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will indicate the date of the most recent change at the top of this page.
12. Contact
Questions about this Privacy Policy or your data? privacy@spelltradepro.com.
This Policy has not been reviewed by counsel and is an interim boilerplate suitable for the internal MVP phase. It will be replaced by a privacy-attorney-reviewed policy (covering CCPA, GLBA, and other applicable frameworks) before public commercial release.