Privacy Policy
Recent Changes
Table of Contents
Click any section to jump directly to it
1. Who is responsible for your information
AlphaHouse (“we”, “us”) operates the website at alphahouse.ai and the trading automation platform behind it. The person responsible for deciding how and why your personal information is used — the data controller — is:
- AlphaHouse, operated as a sole proprietorship based in California, United States
- Privacy contact: privacy@alphahouse.ai
What we are not. AlphaHouse is a technology provider. We never take custody of your funds and we are not a regulated financial institution. Nothing here is financial advice.
2. What we collect, and where it comes from
| Account details | Email address, password (stored only as a salted hash, never in plain text), optional display name and preferences, subscription tier. Source: you. |
| Waitlist details | Email, the capital range you selected, which exchanges you prefer, your referral code and who referred you, and your queue position. Source: you, plus a referral link if you arrived via one. |
| Exchange API credentials | API key and secret for each exchange you connect, encrypted at rest. We require trade-only permissions and never withdrawal permissions. Source: you. |
| Trading and financial data | Positions, order history, balances, equity snapshots, profit and loss, funding payments, deposits and withdrawals on the connected account. Source: the exchange, via the API key you provided. |
| Payment and billing data | Subscription status, invoice history, Stripe customer and subscription identifiers, any discount applied. We never see or store your full card number, expiry or security code — those go directly to Stripe. Source: you and Stripe. |
| Support conversations | Messages you send us by email or through the live-chat widget, and — if you are signed in and have accepted Preferences cookies — your name, email and user id passed to the chat provider. Source: you. |
| Technical and usage data | IP address, browser and device type, pages viewed, actions taken, referring site, timestamps, and error diagnostics. IP address is processed by our hosting providers for every request as a technical necessity; analytics-based usage data is collected only with your consent. Source: automatically, from your device and our infrastructure. |
| Consent and legal records | Which cookie categories you chose, when, against which policy version, whether your browser sent a Global Privacy Control signal, and the country of the request where our provider supplies it. Also the version and timestamp of the Terms, Privacy and Risk documents you accepted, with the IP address at signup. Source: automatically, when you make the choice. |
Sensitive categories. We do not ask for and do not want government identifiers, health data, biometrics, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation. Note that under California law “sensitive personal information” includes account log-in credentials — your exchange API keys fall into that category, and are handled as described in section 7.
3. Why we use your information, and our legal basis
Legal bases are those in GDPR Art. 6. Where we rely on legitimate interests, we have weighed them against your rights and you may object at any time (section 8).
| Run your account and execute the trading systems you selected | Contract (Art. 6(1)(b)). Without this data we cannot provide the service at all. |
| Take payment and manage subscriptions | Contract, and legal obligation (Art. 6(1)(c)) for tax and accounting records. |
| Send service messages — security alerts, billing notices, execution problems | Contract. These are not marketing and cannot be switched off while you hold an account. |
| Keep the platform secure, prevent fraud and abuse, keep audit logs | Legitimate interests (Art. 6(1)(f)) — protecting users and the platform from unauthorised access to accounts that control real money. |
| Waitlist, referral programme and related nurture emails | Consent (Art. 6(1)(a)) where you signed up to be contacted. You may withdraw at any time via the unsubscribe link or the privacy request form. |
| Analytics and product measurement (Google Analytics, PostHog) | Consent. Nothing loads until you accept the Analytics category, and you can withdraw at any time via . |
| Live chat support widget | Consent (Preferences category). |
| Advertising and remarketing | Consent. We do not currently run any advertising tag — see the Cookie Policy. |
| Recording your consent and legal acceptances | Legal obligation — we are required to be able to demonstrate consent (Art. 7(1)). |
| Defending legal claims and complying with lawful requests | Legal obligation and legitimate interests. |
4. Who receives your information
We do not sell your personal information for money. We use the service providers below, each of which processes data on our instructions. On whether our analytics setup amounts to “sharing” under California law, see section 9 — we have deliberately not asserted that it does not.
| Supabase — database, authentication, storage, serverless functions | All account, trading and consent data. Hosted on AWS. |
| Vercel — website hosting and delivery | IP address, request metadata and approximate location for every page request. Technically necessary. |
| Stripe — payments and subscriptions | Email, billing details, subscription and payment records. Stripe acts as an independent controller for parts of its fraud prevention. |
| Resend — transactional and campaign email delivery | Email address, message content, and delivery/open events fed back via webhook. |
| Google (Analytics 4, Tag Manager) — analytics | Usage data and online identifiers. Only with your consent. |
| PostHog — product analytics, feature flags, A/B testing | Usage events and a pseudonymous identifier. Only with your consent. Session recording and autocapture are disabled in our configuration. |
| tawk.to — live chat support | Chat messages, and your name, email and user id if signed in. Only with your consent. |
| Cryptocurrency exchanges you connect (BitGet, Gate.io, Hyperliquid) | Orders and account queries authorised by your own API key. These are independent controllers for your relationship with them, governed by their own terms and privacy policies. |
We may also disclose information to professional advisers, or to law enforcement and regulators where we are legally required to. If the business is ever sold or transferred, information may pass to the acquirer under the same protections.
No AI provider receives your personal information. We checked: the platform makes no calls to any large language model API from the website or its backend functions. An internal research tool does use the Anthropic API, but it runs offline against market data and is never given customer or account data.
5. International transfers
Our infrastructure is in the United States. The Supabase database sits in AWS us-west-1 (California), and Vercel, Stripe, Resend, Google, PostHog and tawk.to all process data in the US or globally. If you are in the UK, EEA or Switzerland, your information is therefore transferred outside your home jurisdiction.
For those transfers we rely on the Standard Contractual Clauses published by the European Commission (and the UK International Data Transfer Addendum), which are incorporated into the data processing terms our providers publish. Several of these providers are also certified under the EU–US Data Privacy Framework.
6. How long we keep your information
| Account and profile | For as long as your account is open, then deleted within 30 days of a verified deletion request. |
| Exchange API credentials | Until you remove them or close your account. Deleted immediately on request — this is the first thing we remove. |
| Trading and portfolio history | Life of the account. On deletion, either erased or irreversibly aggregated so it can no longer be linked to you. |
| Billing and tax records | 7 years from the transaction, because tax law requires it. This survives an erasure request — we will tell you when it applies. |
| Waitlist entries | Until you ask us to remove them, or 24 months after the last interaction, whichever is sooner. |
| Cookie consent records | 3 years from the decision. |
| Legal acceptance records (Terms, Privacy, Risk) | 7 years after the account closes, as evidence of what was agreed. |
| Marketing suppression list | Kept indefinitely. We must remember that you opted out in order to keep honouring it — deleting this record would let you be re-added. |
| Security and access logs | 12 months. |
| Support conversations | 24 months after the ticket closes. |
| Database backups | Deleted data persists in encrypted backups until they expire, up to 30 days for daily backups. |
Where a period is not fixed by law, we set it by asking how long the data is genuinely needed for the purpose it was collected for, balanced against the risk of holding it.
7. Security
- Encryption in transit (TLS) for all traffic, and at rest in the database.
- Exchange API credentials encrypted with a key held separately from the database, and decrypted only inside the server-side function that places an order.
- We require trade-only API permissions. We do not accept, and cannot use, keys with withdrawal rights — so a compromise of our systems cannot move your funds off the exchange.
- Row-level security in the database so one account cannot read another's data, enforced by the database rather than by application code.
- Passwords stored only as salted hashes. Administrative access is restricted and logged.
- Automated dependency vulnerability scanning and secret scanning in CI.
No system is perfectly secure. Please use a unique password, enable every protection your exchange offers, restrict your API key by IP where the exchange supports it, and revoke keys at the exchange first if you suspect a problem.
If a breach occurs that is likely to put your rights at risk, we will notify the relevant supervisory authority within 72 hours of becoming aware, and tell you without undue delay, describing what happened, what data was involved and what to do about it.
Report a vulnerability to security@alphahouse.ai. Please give us a reasonable opportunity to fix it before disclosing publicly.
8. Your rights
You can ask us to:
- Give you a copy of the personal information we hold about you, and tell you how we use it.
- Correct anything inaccurate or incomplete.
- Delete your information, where we have no overriding obligation to keep it.
- Restrict how we use it while something is being checked or disputed.
- Port it — receive it in a structured, machine-readable format, or have it sent to another provider.
- Object to processing based on legitimate interests, and to profiling.
- Withdraw consent at any time, for anything based on consent. This does not affect what we did before you withdrew.
- Stop direct marketing. This one is absolute — we will always honour it, with no balancing test.
How to ask: use the privacy request form or email privacy@alphahouse.ai. You do not need an account. Exercising any of these rights is free and we will not treat you worse for it.
How we verify it is you. Before we disclose or delete anything we confirm your identity, normally by emailing the address on the account and, for higher-risk requests, asking you to confirm details only the account holder would know. We do not ask for photo ID or government documents — collecting identity papers to answer a privacy request creates more risk than it removes. If we genuinely cannot verify you, we will tell you why rather than refusing silently.
Timing. We respond within one month (45 days for California requests). Complex requests may be extended by a further two months; we will tell you before the original deadline if that happens.
Some rights have limits. We cannot run the trading service without the trading data, so a restriction request will pause execution. Billing records must be kept for tax purposes even after deletion. We will always explain which exception we are relying on.
9. California residents
We extend the rights set out in this section to California residents, whether or not the CCPA/CPRA applies to us.
Notice at Collection. The categories we collect, why, and for how long are set out in sections 2, 3 and 6 above, and are disclosed at or before the point of collection. In CCPA terms we collect: identifiers; customer records; commercial information; internet and network activity; approximate geolocation (from IP); inferences drawn from usage; and account log-in credentials, which count as sensitive personal information.
Sensitive personal information. We use your exchange API credentials solely to perform the service you asked for — that is, to place the trades you configured. We do not use them to infer characteristics about you, which is the use CPRA lets you limit. You can still submit a “limit the use of my sensitive personal information” request through the privacy request form.
Do not sell or share. We do not sell personal information for money and never have. Using Google Analytics and Google Tag Manager can constitute “sharing” for cross-context behavioural advertising under the CPRA, depending on how they are configured. Here is how ours are configured, and what you control:
- Analytics and Advertising are off unless you switch them on — . Leaving Analytics off is what stops Google Analytics and Google Tag Manager loading at all.
- We honour Global Privacy Control as a valid opt-out of sale and sharing. If your browser sends it, the Advertising category is locked off and cannot be enabled here, and no advertising or ad-personalisation signals are sent to Google.
- You can submit an explicit opt-out via the privacy request form.
Your rights to know, correct, delete, opt out and limit are the same as those in section 8 and use the same form. We will not discriminate against you for exercising them. You may use an authorised agent; we will ask for proof of their authority.
10. Automated decisions and profiling
The platform is automated by design, and you should understand exactly what that means. Our systems automatically generate trading signals and place orders on the exchange account you connect, without a human reviewing each trade. That automation acts on market data, not on an assessment of you as a person: the same signals are produced for every subscriber to a given system, sized to the capital and leverage you chose.
Because this processing is carried out to perform the contract you entered into, and because you choose which system to run, at what leverage, and can pause or disconnect at any moment, we consider it permitted under GDPR Art. 22(2)(a). You retain meaningful control: you can stop execution, revoke the API key at your exchange, or close positions yourself at any time.
We do not use automated decision-making to decide whether you may open an account, what you pay, or your creditworthiness. We do not profile you for advertising.
If you disagree with an automated outcome you can contact us for human review at support@alphahouse.ai. Please note we can explain and correct how the system operated — we cannot reverse a trade that has already executed on an exchange.
11. Children
AlphaHouse is for adults only. You must be at least 18 to open an account, and the service is not directed at children. We do not knowingly collect information from anyone under 18.
We currently rely on the age confirmation in our Terms rather than on document-based age verification. If we learn that we hold information about a child, we will delete it and close the account. If you believe a child has given us information, contact privacy@alphahouse.ai.
12. Changes to this policy
Effective date: 1 August 2026. Last updated: 17 August 2026. Version 2.0.1.
If we make a material change we will email account holders and show a notice in the app before it takes effect. If the change affects cookies or tracking, we will ask for your consent again rather than carrying the old one over.
We will not treat your continued use of the site as agreement to a change that requires consent. The previous version of this policy said the opposite; that was wrong and has been removed.
13. Contact and complaints
- Privacy: privacy@alphahouse.ai
- Security reports: security@alphahouse.ai
- General support: support@alphahouse.ai
If you are unhappy with how we handled your information, please tell us first so we can put it right. You also have the right to complain to a data protection authority:
- EU/EEA: the supervisory authority where you live, work, or where the issue arose — directory at edpb.europa.eu.
- UK: the Information Commissioner's Office, ico.org.uk.
- California: the California Privacy Protection Agency, or the Attorney General's office.
You never need to go through us first, and complaining costs you nothing.
If you have questions about this document, please contact us at privacy@alphahouse.ai
Document maintained and updated by AlphaHouse
