This Privacy Policy explains how MoneySignals (“MoneySignals,” “we,” “us,” or “our”) collects, uses, and shares information when you use our website (moneysignals.us), our API (api.moneysignals.us), our email reports, and related services (the “Service”). By using the Service, you agree to this Policy. It should be read together with our Terms of Service.
Information you provide:
Information collected automatically:
Connected portfolios: When you import a snapshot or use an available broker connection, we store the account label, broker and environment, dated balances and holdings, and watchlist you provide on our servers to display and consolidate your information. Delegated access tokens and explicitly configured personal broker credentials are encrypted on our servers and used for supported read operations. A provider's upstream permissions may be broader than MoneySignals' permitted operations. The workspace does not place orders. Import previews expire after 20 minutes and can no longer be used. Maintenance removes expired temporary records, so physical removal may occur later than the expiry time.
Your private portfolio is not included in our public API or global-evidence MCP tools. The workspace lets you explicitly download portfolio context or authorize a separate private agent token with chosen permissions and an expiration. Private agent tokens are stored hashed and may be revoked in the workspace. Depending on permissions, your agent can read saved portfolios, explicitly linked AutoTrader records and research, and request supported broker-data refreshes. Information received by another service is governed by its own policies.
Private broker news stores a bounded sample of headline metadata, source links, clocks and symbols. Full article text, summaries and images are not retained. Portfolio and watchlist relevance is computed within MoneySignals; those holdings and watchlists are not sent to the news provider. Private news is not redistributed through the public API or public MCP.
We do not sell your personal information, and we do not use the contents of your account to target you with third-party advertising.
The account portal keeps a bearer session in this browser's local storage to maintain your sign-in. The workspace also stores display preferences and, when signed out, a device-local watchlist. The workspace does not load third-party analytics scripts; other website pages may use the analytics described below.
We use cookies and similar technologies, primarily through Google Analytics, to measure traffic and usage. You can control cookies through your browser settings and can opt out of Google Analytics using Google's opt-out browser add-on. Disabling cookies may affect some non-essential features. We do not currently respond to browser “Do Not Track” signals.
We share information only as described below. We do not sell personal information.
| Recipient | Purpose |
|---|---|
| Stripe | Payment processing and subscription management. |
| Google Analytics | Website usage analytics. |
| Email & messaging providers | Delivering our email reports and notifications to you. |
| Cloud hosting & infrastructure (e.g., Google Cloud, Cloudflare) | Hosting, content delivery, and security for the Service. |
| Connected brokers and broker-data providers | Processing your authorized sign-in, account-data and supported private headline requests. |
| Agent services you authorize | Receiving the workspace information you permit them to read, under the scopes you select. |
| Legal / safety | When required by law, subpoena, or legal process, or to protect the rights, safety, or property of MoneySignals, our users, or others. |
| Business transfers | In connection with a merger, acquisition, financing, or sale of assets, subject to this Policy. |
These providers process information on our behalf or as independent controllers under their own privacy policies.
Disconnecting a broker removes its locally stored access credential and private news cache, and keeps your last dated snapshot. Removing an account deletes its active stored portfolio records. Erasing workspace data removes active stored portfolio accounts, holdings, watchlists, temporary imports, connection credentials and private news caches. It also revokes private agent access and the link to AutoTrader records without deleting AutoTrader's underlying trading history, and requires you to sign in again. These actions do not delete your brokerage account or automatically revoke the MoneySignals app permission at the broker; revoke that permission separately in the broker's settings. Infrastructure backups may retain earlier copies until the applicable backup retention period ends.
Private headline caches expire three days after collection. Expired items are excluded from reads; maintenance removes retained metadata. Revoking an agent token stops future access but cannot remove information that an external agent has already received.
We retain personal information for as long as needed to provide the Service and for legitimate business or legal purposes. For example, we keep your email while you are subscribed and for a reasonable period afterward; API usage logs are retained for security, billing, and diagnostics for a limited period and then deleted or aggregated. Billing records may be retained longer to meet tax and accounting obligations. You may request deletion as described in Section 7.
We use reasonable technical and organizational measures to protect information, including encrypted connections (HTTPS) and access controls. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your API key confidential.
We will respond to verifiable requests within the time required by applicable law.
We are based in the United States and process information there. If you access the Service from outside the United States, you understand that your information may be transferred to and processed in the United States and other countries, which may have different data-protection laws than your own.
The Service is not directed to, and we do not knowingly collect personal information from, anyone under 18. If you believe a minor has provided us personal information, contact us and we will delete it.
The Service may link to third-party websites and services we do not control. This Policy does not apply to them; please review their privacy policies.
We may update this Policy from time to time. We will revise the “Last updated” date above and, for material changes, provide additional notice where appropriate. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
Questions or requests regarding your privacy? Contact us at [email protected].