Privacy Policy
Effective date: August 10, 2026
This Privacy Policy explains what information Advanticks (operated by Tom Bednarczyk, "we," "us," or "our") collects, how it's used, and your choices. It applies to app.advanticks.com.
1. Information We Collect
- Account information: your email address and authentication identifiers, managed by Supabase Auth (the identity provider we use). If you sign in with Google or Apple, we receive the basic profile information those providers share for authentication (typically name and email) — we never see or store your password for any sign-in method. If your account uses two-factor authentication, the authenticator secret is stored encrypted.
- Brokerage data (only if you choose to connect a broker): encrypted OAuth access credentials, and trade history (symbols, quantities, prices, and timestamps) and account summary data (portfolio value, cash, buying power, positions) that we read from the broker's API using those credentials. If you enable automated trading, we also store a record of every order the Service placed on your behalf.
- Manually entered data: any trade journal entries, notes, or setup tags you type in yourself, plus the strategies you build and the chart examples you grade.
- Preferences: saved settings like table column order/visibility and dashboard layout, tied to your account so they follow you across devices.
- Activity and security records: an audit log of state-changing actions taken in your account (for example signing in, saving a strategy, connecting a broker, or canceling an order), each recorded with a timestamp, the page it happened on, and the IP address the request came from. We also record the time and IP address at which you accepted the welcome risk notice.
- Usage data: basic technical logs generated by the normal operation of a web application.
We do not collect payment information or government ID numbers, and we never receive your brokerage password.
2. How We Use Information
- To operate your account, authenticate you, and display the scanner, dashboard, and journal features.
- To sync and display your trade history if you connect a brokerage account.
- To place and manage orders at your broker, but only for accounts on which you have enabled automated trading.
- To save your preferences across sessions and devices.
- To keep a security and troubleshooting record of what happened in your account, and to evidence that you were shown and accepted the risk notice.
- To train the machine-learning models used by your strategies. Those models are trained on historical market data (prices, volume) together with the chart examples you graded yourself. Your strategies, graded examples, and models are private to your account and are not pooled with, or used to train models for, any other user.
3. The In-App Assistant
The Service includes an optional chat assistant, powered by Anthropic's Claude API. It is read-only: it cannot place, change, or cancel orders. When you send it a message, your message and the answers to the read-only lookups it performs on your behalf — which can include your strategies and their settings, your broker orders and positions, your automated trade records, and your journal trades — are transmitted to Anthropic in order to generate a reply. Anthropic processes this data as our service provider. If you would rather this data were not sent to a third party, simply do not use the assistant; the rest of the Service works without it.
4. How Information Is Stored and Protected
Application data is stored in a Postgres database hosted on Railway. Brokerage credentials and authenticator secrets are encrypted at rest before being stored. All traffic to the Service is encrypted in transit (HTTPS/TLS, via Cloudflare). Access to administrative functions is restricted to allowlisted administrator accounts.
5. Third-Party Service Providers
We share the minimum data necessary with the following providers, solely to operate the Service:
- Supabase — authentication (stores your email and login identifiers).
- Alpaca and, if connected, TradeStation / Charles Schwab / Tradovate (NinjaTrader) — market data, and (only if you connect your own account) your brokerage trade history and account summary, and any orders placed for you.
- Anthropic — powers the in-app assistant; receives your messages and the account data described in Section 3, only when you use it.
- Coinbase — crypto market data (not tied to your personal identity).
- Financial Modeling Prep — company, float, and logo data (not tied to your personal identity).
- Railway — application hosting and database storage.
- Cloudflare — DNS and TLS/SSL for app.advanticks.com; as the network layer in front of the Service it also sees the IP address of requests.
- Logo.dev and flagcdn.com — company logo and country-flag images, looked up by ticker/country code only.
We do not sell your personal information to anyone, and we do not share it with advertisers.
6. Data Retention
Your account data is retained while your account remains active. If you disconnect a brokerage account, its stored credentials are removed. If you'd like your account and associated data deleted entirely, contact us (below) and we will delete it, other than any records we're required to keep for legal reasons — which includes the record of your acceptance of the risk notice and the audit log of trading activity, since those exist precisely to evidence what was authorized and when.
7. Your Choices
- You can disconnect a connected brokerage account at any time from the Brokers page, and you can stop automated trading at any time using Halt all trading or by disabling a subscription.
- You can edit or delete manually entered journal trades yourself; broker-synced trades can be annotated (notes/tags) but not altered, since they reflect the broker's own record.
- You can choose not to use the in-app assistant, in which case no account data is sent to Anthropic.
- You can review your own activity, including the IP addresses recorded against it, on the Audit Log page.
- You can request a copy or deletion of your data by emailing us.
8. Cookies
We use a single signed session cookie to keep you logged in. We do not use third-party advertising or tracking cookies.
9. Children's Privacy
The Service is not directed at, and is not intended for use by, anyone under 18.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will update the effective date above when changes are made.
11. Contact
Questions about this Privacy Policy, or requests to access or delete your data, can be sent to [email protected].