Privacy policy
Last updated 21 August 2026
This describes what we actually collect and do, in plain language. Where a section says we do not do something, that is a statement about how the software is built, not an aspiration.
The unusual thing about this service
Most of this policy is ordinary. One part is not, and you should read it before creating a creator account: a published track record is public, and it covers every position in the accounts you link — not a selection you approve. That is the entire point of the product. If you do not want your trading activity published, do not link a brokerage account. Reading, following and subscribing do not publish anything about you.
What we collect
Account information
Your email address, and a display name if you set one. We do not ask for a password — sign-in uses a one-time code sent to your email — so we never hold one.
Session information
When you sign in we record the time, your IP address and your browser's user-agent string, and we store a hash of your session token — never the token itself. This exists to expire sessions, to rate-limit sign-in attempts, and to let you see where your account is signed in.
Brokerage data, if you connect an account
Through our brokerage aggregation provider we receive your executed trades and positions: symbols, quantities, prices, and timestamps. The connection is read-only. We cannot place, modify or cancel orders, and we cannot move money. We never receive or store your brokerage username, password, or MFA codes — you enter those with the provider or your broker, never with us.
Payment information
Subscriptions are processed by Stripe. Card numbers are entered on Stripe's systems and never reach ours. We store an identifier for your Stripe customer or connected account and the state of your subscriptions — active, cancelled, and when that changed.
Things you write and do
Ideas you publish, comments, likes, follows, and any reports you file about other people's content.
What we do not collect
No brokerage credentials. No card numbers. No advertising or cross-site tracking. We do not buy data about you from third parties, and we do not sell or rent your data to anyone.
What is public
If you are a creator with a published record, the following is visible to anyone, including people who are not signed in:
- Your handle, display name, and the date your record was first verified.
- Computed performance: returns by period, win rate, maximum drawdown, holding periods, and the number of closed positions.
- Your positions — symbol, direction, entry and exit dates, and the resulting return. For options, the contract: underlying, call or put, strike and expiry, and how it ended — sold, expired, assigned or exercised.
- Coarse position-size bands rather than exact dollar amounts, so scale is legible without publishing your account balance.
- Ideas you publish, and whether each was public or subscriber-only.
We do not publish your account balance, your email address, or your identity beyond the name and handle you choose.
Who we share data with
Only the providers that make the service work, and only what each one needs:
- Our brokerage aggregation provider — to establish and maintain your read-only connection and deliver your trade history.
- Stripe — to process subscription payments and creator payouts. Stripe collects tax and identity information directly from creators for payouts; we do not see it.
- Our email provider — to deliver your sign-in codes and service notices.
- Our market data provider — we send ticker symbols to check whether a name may be published about. No personal information is included in those requests.
- Our hosting provider — which operates the servers and database.
We may also disclose information where the law requires it, or where it is necessary to investigate suspected market manipulation, fraud, or abuse of the service.
How long we keep things
Sign-in sessions expire 24 hours after they are created, and there is no sliding renewal — the clock does not reset when you use the service.
Verification records are permanent by design and by necessity. Position history, track-record snapshots, published ideas, and subscription history are append-only ledgers: a correction is recorded as a new entry rather than by editing or deleting the old one. A record that could be quietly revised would not be worth publishing. This means a published track record does not disappear when you disconnect your brokerage account — the record keeps the gap and shows it.
Your choices
- Disconnect your brokerage at any time. We stop receiving new trade data immediately. Your existing published record remains, annotated to show when it stopped.
- Request access, correction or export of the personal data we hold about you.
- Request deletion of your account. We remove your account, email address, sessions and private content. Where a published record must remain — because other people relied on it, or because we are required to keep it — we will tell you which parts remain and why, rather than deleting silently or refusing outright.
- Unsubscribe from non-essential email. Sign-in codes cannot be turned off, because they are how you get into your account.
Write to hello@pickvesting.com. Depending on where you live you may have additional rights under laws such as the GDPR or the CCPA; we apply the choices above to everyone regardless of location.
Cookies
We set one cookie to keep you signed in, and a separate one for staff signing into the operator console. Both are strictly necessary for the service to function. We do not set advertising cookies and we do not embed third-party trackers.
Security
Traffic is encrypted in transit. Session tokens are stored only as hashes, so a copy of our database does not yield working sessions. Access to subscriber-only content is enforced in the database query itself, not hidden in the browser — content you have not paid for is never sent to your device. No system is perfect; if you find a vulnerability, please write to hello@pickvesting.com before disclosing it publicly.
Children
This service is not intended for anyone under 18, and we do not knowingly collect information from children. If you believe a minor has created an account, tell us and we will remove it.
Changes
If we change this policy we will update the date at the top and, for changes that materially affect what we collect or publish, notify account holders by email before the change takes effect.
Questions about this policy: hello@pickvesting.com. See also our terms of service.