1. Information We Collect
Bracket Trade ("the Service") is operated by Manifest AI Labs LLC ("we", "us", "our"). We collect the following information when you use Bracket Trade:
- Account information: Email address and password (hashed) when you register, along with your account preferences and settings
- API keys: Your brokerage API keys, and any AI provider keys you choose to add, saved to your account and stored encrypted so we can act on your behalf. Accounts set up before the current plan may instead keep their keys in the browser they were configured in; those keys are sent to us with each request that needs them. See section 3.
- Trading and analysis data: Trade history, auto-trade plans and their results, scan results (stocks, options and prediction market contracts), watchlists, news lookups, saved AI analyses and reports, and any notes you write against a trade in the journal
- Agent and API activity: If you connect an agent or another application, we store the connections you have authorized and a record of the calls made through them, including the endpoint, the outcome, and the dollar amount counted against any spending limits you set. The tokens behind those connections are stored only as hashes.
- Documents you analyze: The experimental document Q&A tool extracts the text from a PDF you upload and stores that text, the file name and the page count, along with your conversation with the AI about it. The PDF file itself is not kept.
- Usage data: Feature usage events (which tools you use and when) and AI token counts with their estimated cost, so we can improve the Service and apply the fair-use limits that come with the included AI
- Payment information: Processed by Stripe. We store your Stripe customer ID and subscription status but never your credit card details
2. How We Use Your Information
- To provide and maintain the Service
- To execute trades on your behalf and run the AI analysis you request
- To process subscription payments
- To send transactional emails (trade confirmations, account notifications)
- To understand how features are used and improve the Service
3. API Key Security
Where your keys are held. Keys you save to your account are stored in our database encrypted at rest with AES-256-GCM and decrypted only at the moment they are needed, such as placing an order with your brokerage on your instruction. You can replace or remove them at any time in Settings.
Accounts set up before the current plan may instead keep their keys in the browser's local storage on the device they were configured on. Those keys are sent to us with each request that needs them and are not written to our database. Clearing that browser's storage removes them, and the setup wizard can export a backup file first.
However they reach us, we handle them the same way: they are not written to our application logs, our error reporting strips them from reports before those reports leave our servers, we do not display them back to you in full, and we do not transmit them to anyone other than the service they are for (your brokerage, or the AI provider you chose).
4. Data Storage and Hosting
Your data is stored in a PostgreSQL database hosted by Neon. The web application is hosted on Vercel. Both providers encrypt data in transit and at rest, and both publish their own security and compliance documentation, which you can review on their websites.
5. Third-Party Services
We share data with the following third parties only as necessary to operate the Service:
- Alpaca Markets: Your Alpaca API keys to execute trades and fetch market data
- AI infrastructure providers: Market data and the scan instructions you write, so the included models can run your analysis. If you add your own AI provider keys, analysis you run with those models goes to that provider instead, using your key. We do not send your name, email, or brokerage credentials to AI providers.
- Stripe: Email and payment information for subscription billing
- Neon: Database hosting
- Vercel: Application hosting
6. Data Retention
Your data is retained as long as your account is active. When you delete your account, all associated data (trading history, API keys, watchlists, settings) is permanently deleted via cascade deletion. We do not retain backups of deleted user data.
7. Your Rights
You have the right to:
- Access your data through the Service interface
- Export your trading journal and history
- Delete your account and all associated data at any time
- Revoke API keys at any time through your account settings
8. Cookies
We use session cookies for authentication (NextAuth). We do not use tracking cookies or third-party analytics cookies.
9. Children
The Service is not intended for use by anyone under the age of 18. We do not knowingly collect information from children.
10. Changes to This Policy
We may update this policy from time to time. We will notify you of material changes via the email associated with your account.