Privacy Policy
This Privacy Policy explains what information GexStrike LLC ("we", "us", "our") collects when you use the Top Stocks mobile app or the website at gettopstocks.com (together, the "Service"), how we use and protect it, and the choices you have.
1. Data we collect
- Email address. If you join the waitlist or create an account, we collect your email address to communicate with you about the Service.
- RevenueCat app user ID. If you make the in-app purchase, a pseudonymous app user ID is created in RevenueCat to manage your purchase entitlement across devices. This ID is not linked to your real-world identity by us.
- Alpaca API keys. Only if you enable Autopilot, we collect the API keys to your own Alpaca brokerage account. Keys are stored encrypted at rest using Fernet symmetric encryption and are never logged in plaintext.
- Usage analytics. We collect basic analytics — screens viewed, feature usage and crash data — aggregated or pseudonymous wherever possible, to operate and improve the Service.
2. Data we do not collect
- We do not collect or retain your brokerage balances, positions, or trade history beyond what the Autopilot operation technically requires to function — and none of it is sold.
- We do not collect passwords for Alpaca or any other third-party service.
- We do not collect advertising identifiers, your contact lists, or your precise location.
- We do not receive or store your payment card details — those are handled by Apple, Google, or Stripe, depending on what you purchase.
3. Storage and security
Alpaca API keys are encrypted at rest (Fernet); all traffic to and from the Service uses TLS; access to production systems is limited to what is needed to operate the Service; keys are never written to logs. Our databases are hosted on Railway (Postgres in production) and Supabase infrastructure.
We keep your data while your account is active. When you delete your account, we delete your associated data — including any stored Alpaca keys — from our production systems, subject to backups cycling out and to records we must keep by law.
4. Third parties we work with
We share data with the following processors, only as needed to operate the Service. Each processor's own privacy policy applies to its handling of your data.
- Apple App Store / Google Play — billing for the in-app purchase.
- RevenueCat — purchase and entitlement processing.
- Stripe — billing for the Autopilot subscription. Your payment card data is handled by Stripe and never touches our servers.
- Alpaca — brokerage connectivity for Autopilot.
- Railway and Supabase — infrastructure and database hosting.
- Vercel — website hosting.
We do not sell your personal data, and we do not share it with third parties for their advertising.
5. Your rights
You can:
- Access a copy of the personal data we hold about you;
- Correct inaccurate data;
- Delete your account and associated data, including any stored Alpaca API keys;
- Revoke your Alpaca API keys at any time — in the app, or directly with Alpaca — which stops Autopilot's access to your brokerage account;
- Unsubscribe from non-essential emails at any time via the link in the email.
To exercise any of these, use the in-app settings or contact us at privacy@gexstrike.com. We respond to requests within [response window — attorney to set].
6. Children's privacy
The Service is not directed to children under 13, and in practice is aimed at adults with brokerage accounts. We do not knowingly collect personal data from children. If we learn that we have collected data from a child under 13, we will delete it.
7. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you in the app and/or by email before they take effect. Continued use of the Service after notice constitutes acceptance of the updated policy. Prior versions are available on request.
8. Contact
Privacy questions and requests: privacy@gexstrike.com.