Privacy Policy

Last updated 2026-08-18

What we collect (account, encrypted broker keys, your trading activity), who processes it, how long we keep it, and how to ask for access or deletion.

1. Scope

This Privacy Policy explains how Meshesha ("Meshesha", "we") collects, uses, shares, and retains information when you use the Service. It applies to members and to people who request access. We do not sell personal information and we do not use it for advertising.

2. What we collect

  • Account data: name, email address, password hash (email sign-up) or your Google account identifier and profile basics (Google sign-in), role, two-factor and passkey enrollment data, and the invite that admitted you.
  • Session and security data: IP address, browser/user agent, sign-in times, and security events; the record of every consent you give in the app (document, version, time, IP, user agent).
  • Broker connection data: the Alpaca API key and secret you provide (encrypted at rest with AES-256-GCM; never displayed back to you), your Alpaca account number and account status, and — pulled from the Broker while connected — balances, buying power, orders, positions, and fills.
  • Trading and configuration data: your subscriptions, risk profile, execution settings, every signal relayed to you, every order we transmit and its outcome, journal entries, alerts, and the activity log of your account.
  • Signal-provider data (if you bring your own source): the source's name and description, its webhook configuration (secret stored encrypted), the raw payloads your producer posts, and the circles you create — including the email addresses of the members you add.
  • Support data: messages you send us and, when an administrator acts inside your account for support, a log of that access.

We do not collect government IDs, Social Security numbers, bank details, or funding information — those live with the Broker, which performs its own identity verification under its own privacy policy.

3. How we use it

  • To run the Service: authenticate you, relay signals, transmit orders you have authorized, monitor positions, show you your dashboard, and send you the notifications you enable.
  • To keep the Service safe: detect abuse, enforce rate limits and the invite gate, investigate incidents, and maintain the audit trail of orders and consents.
  • To operate and improve the platform: aggregate, de-identified usage and performance statistics; error and health monitoring; operational alerts to the Operator (which may reference your account identifier and order details).
  • To comply with law and enforce our Terms.

4. Who we share it with

We share personal information only with the service providers that host and run the platform, each acting on our instructions, and with your broker as needed to execute what you have authorized:

  • Alpaca Securities LLC / Alpaca Markets — receives the orders we transmit for you and returns your account data.
  • Neon (managed PostgreSQL) — stores the database.
  • Railway — hosts the application servers.
  • Google — sign-in (if you use Google), and Google Cloud Pub/Sub for platform-operated email signal sources.
  • Slack — operational alerts to the Operator.
  • Other members — only what the feature requires: circle owners see the emails they added; members of a circle see the source's name and its owner's display name; if a provider opts a source into benchmark scoring, its aggregate simulated score and owner display name are shown to all members. Individual trade results for a shared source are shown only to that source's owner and circle members.

We may disclose information if required by law, subpoena, or regulator, to protect the rights and safety of members or the public, or in connection with a reorganization or transfer of the Service (in which case this policy continues to apply).

5. Retention

  • Order, execution, position, and journal records — retained for the life of your account and thereafter as long as reasonably necessary for audit, dispute, and legal purposes (target: at least 6 years, in line with securities record-keeping norms).
  • Raw inbound signal payloads and platform activity logs — retained while the source/account is active; a formal retention schedule is being adopted (see the legal review checklist).
  • Webhook delivery attempt logs — 30 days. Invite-request throttle records — a few hours.
  • Broker credentials — deleted immediately when you disconnect a broker connection or when your account is deleted.
  • Consent records — retained for as long as the account exists plus the applicable limitations period.

6. Security

Broker credentials and webhook secrets are encrypted at rest with AES-256-GCM under a key held only by the application servers. Data is isolated per user with database row-level security in addition to application checks. Two-factor authentication and passkeys are available and recommended. No system is perfectly secure; if we learn of a breach affecting your personal information we will notify you as required by applicable state breach-notification law.

7. Your choices and rights

  • Access and correction: your profile, settings, and trading history are visible in the app; you can update your profile and settings directly.
  • Disconnect: remove your broker credentials at any time under Settings → Broker; regenerate keys at Alpaca to revoke access from their side as well.
  • Deletion: ask us to delete your account and personal information — contact your platform administrator (the person who invited you) through the app. We will delete or de-identify what we can, retaining only what we must keep for legal, audit, or dispute purposes (for example order records). If you have ever owned a shared signal source, that source is retired first so members' histories remain intact.
  • State privacy rights: depending on where you live you may have rights to know, delete, correct, or opt out of certain processing. We honor such requests as required; make them through the contact above. We do not sell or share personal information for cross-context behavioral advertising.

8. Children, location, and changes

The Service is for adults (18+) and is intended for U.S. residents; we do not knowingly collect information from children or offer the Service in the EU/UK. We may update this policy; material changes will be presented for acceptance in the app and the version date above will change.