Legal · privacy
Privacy Policy
Effective 2026-08-01. We collect what we need to run the service, secure optional broker connections and carry out actions you explicitly request. We do not sell your personal information.
1. What we collect
- Account data. Email, hashed password, profile details, account state, subscription tier, preferences and security/session metadata.
- Billing data. Handled by Stripe — we receive a customer ID and the last four digits of your card. We don't see your full PAN.
- Delivery data. Phone number for optional SMS, email, iOS-app device token — you choose which channels to enable.
- Broker-connection data. If you choose to connect a supported broker, we may receive the provider name, environment, redacted account identifier, granted permissions, capabilities, connection health and verification history. Depending on the provider, we may also receive an OAuth token or customer-created API token. Supported secrets are stored as encrypted server-side envelopes and are never returned to the browser after submission.
- Broker account and trading data. For a connection you authorize, EMI may read account status, balances, buying power, positions, orders, fills and limited transaction history needed to verify the connection, preview your request, prevent duplicates, show a redacted receipt and reconcile the resulting order state.
- Order and consent records. Preview terms, instrument, side, quantity, order type, entry, stop, target, time-in-force, estimated notional, confirmation time, broker response, document versions accepted and security context. These records support your instructions, dispute handling, fraud prevention and audit obligations.
- Usage telemetry. Page views, alert opens, dashboard interactions, IP and user-agent for security and abuse prevention.
- Support correspondence. Anything you send to support@, retained for service quality.
2. Connected Brokerage Accounts
If you choose to connect a brokerage account, EMI may collect and process the information necessary to establish and operate that connection. Depending on the broker and the permissions you approve, this may include:
- the broker or platform you selected;
- a redacted account identifier;
- the account environment, such as paper, practice, testnet or live;
- encrypted access tokens or API credentials;
- the permissions granted to EMI;
- account status, buying-power or position information where required to validate or display an order;
- order instructions submitted by you;
- broker order identifiers, execution status, fills, rejections and related receipts.
Where supported, EMI uses the broker’s authorization or OAuth process. EMI does not request or store your brokerage password.
Robinhood Agentic. If you authorize EMI through Robinhood’s official Trading MCP, Robinhood states that the authorized agent can read account numbers, positions, balances, transactions, order history, watchlists and scans across your Robinhood accounts, while trade placement is limited to the dedicated Robinhood Agentic account. EMI’s current pairing check uses the authorization only to initialize the MCP and verify its capability list; it does not call an account-data or order tool. If customer order tools are enabled later, EMI will process only the account and trading data needed for the customer-confirmed action and its receipt.
Broker credentials and tokens are encrypted and are not displayed after submission. EMI does not request withdrawal or transfer authority and does not use connected brokerage accounts to take custody of customer money or assets.
You may disconnect a brokerage account from the dashboard. Disconnecting prevents future use of the connection by EMI but may not delete records that must be retained for security, dispute resolution, audit or legal purposes.
Disconnecting Robinhood from EMI deletes EMI’s stored authorization-token envelope. You should also revoke the agent through Robinhood so provider-side access is invalidated.
Broker connection information is used only to validate the connection, prepare and transmit customer-authorized orders, display order status, prevent duplicate submissions, provide support and protect the security of the service. It is not sold or used for advertising.
3. What we don't collect
- Your broker website password. Where an approved provider-hosted authorization flow exists, EMI uses that flow and does not ask you to paste your broker login password.
- Withdrawal, transfer or disbursement authority. Where a provider exposes separate permissions, EMI rejects credentials that grant those powers.
- Full bank-account or payment-card information. Stripe handles subscription payment data, and your broker handles brokerage funding.
- Government IDs unless required for fraud investigation.
- Browsing activity on third-party sites.
4. How we use it
- To deliver alerts to the channels you've configured.
- To bill the desks you've subscribed to (via Stripe).
- At your request, to connect and verify a supported broker, display connection and account truth, preview an order plan, transmit a customer-confirmed order and display its redacted status or receipt.
- To enforce environment, permission, eligibility, consent, stale-quote, idempotency and duplicate-order controls.
- To support you when you ask.
- To detect fraud, abuse and account compromise.
- To improve product reliability using aggregated or de-identified operational measures. Customer broker credentials, account identifiers, positions, orders and fills do not train EMI's models.
EMI does not use a connected broker account to make withdrawals or transfers. Under the customer-directed trading model, EMI acts only on an order you preview and explicitly confirm; it does not take ongoing discretion over your live account.
5. Who else sees it
Sub-processors only — and only the minimum required:
- Stripe — payment processing.
- Twilio / SendGrid / Apple Push — alert delivery.
- Cloud provider — application hosting.
- Your selected broker or trading provider — connection authorization, account verification and any order you explicitly direct EMI to transmit.
- Google Analytics (GA4) — site usage, traffic sources, and conversion measurement so we know which marketing channels actually bring serious traders.
- Advertising platforms — Google Ads, Meta, and similar networks may receive aggregated conversion signals when we run paid campaigns, so we can measure ad performance and stop wasting money on channels that don't work.
Broker-connection and order pages do not send credential, account, position, order or fill data to advertising or behavioral-analytics providers. We do not sell, rent or trade your personal information, and we do not have a data-broker relationship.
6. Cookies
We use a small, deliberate set of cookies:
- Strictly-necessary — session, CSRF protection, login state. Cannot be disabled without breaking the product.
- Analytics — Google Analytics sets
_gaand_ga_*cookies to count visits and understand how the site is used. You can opt out via the Google Analytics opt-out browser add-on or any standard tracking-blocker. - Advertising — when we run paid campaigns, the corresponding ad-network cookies (e.g. Google Ads, Meta) may be set on landing pages so we can measure conversions. You can manage these via your Google Ad Settings and equivalent platform controls.
EU/UK visitors: where applicable consent is required, our cookie banner gates analytics and advertising cookies until you opt in.
7. Broker security and your controls
- Use the narrowest available read/trade permission and a paper, practice or testnet environment first.
- You may disconnect a broker from Account. You should also revoke EMI at the broker whenever you no longer want the connection available.
- Disconnecting prevents new EMI requests, but it may not cancel orders already accepted by your broker. Manage those orders directly at the broker.
- No internet system is perfectly secure. If EMI detects a credential or account-security incident, affected connections may be disabled and require reauthorization.
8. Your privacy rights
You may request access, correction or deletion of eligible personal information, or revoke consent where consent is the processing basis. Contact privacy@enhancedmarketintelligence.com. We aim to respond within 30 days and apply GDPR, UK GDPR, CCPA/CPRA and other rights where they apply to you and to EMI.
9. Retention
Account data is retained while your account is active and ordinarily for 12 months after closure for tax, audit and dispute purposes. Broker secrets are retained only while the connection is active or as briefly as needed to complete revocation and incident handling. Redacted order receipts, consent versions, security and audit records may be retained longer where reasonably necessary for legal, regulatory, fraud, security or dispute obligations. De-identified aggregate data may be retained longer.
10. International processing
EMI and its service providers may process information in countries other than the one where you live. Where required, we use an appropriate transfer mechanism and apply contractual and technical safeguards. Broker availability and data handling also depend on the provider and your account jurisdiction.
11. Changes and consent
Material changes will be emailed and posted here. Where a new use requires consent — including a material change to connected-broker or live-order processing — EMI requires acceptance of the current document version before enabling that use. Ordinary site use is not treated as acceptance where affirmative consent is required.
12. Contact
privacy@enhancedmarketintelligence.com for any privacy question.