Legal & Regulatory Documentation

Privacy & Data Isolation Policy

Last updated: October 2026 • APinvestment Compliance Desk

1. Data Isolation & Zero Credential Storage

At APinvestment, privacy is an architectural priority. When you connect external brokerage accounts via our integration with Plaid Inc., your financial credentials (passwords, usernames, security tokens) never touch APinvestment servers. Plaid establishes a tokenized, read-only session directly with your depository or brokerage.

All database rows associated with your portfolio, transactions, and preferences are strictly isolated under tenant-partitioned Row Level Security (RLS) in our Supabase backend.

2. What Information We Collect

We collect only the minimum required information to provide the services you request:

  • Account Identity: Email address provided through Auth0 authentication.
  • Read-Only Investment Positions: Account balance totals, ticker symbols, share counts, and cost bases received via Plaid API.
  • Usage Telemetry: Anonymous pageview metrics to diagnose system latency and performance bottlenecks.

3. Third-Party Data Sharing

APinvestment does not sell, rent, monetize, or broker personal investor data to data aggregators, advertisers, hedge funds, or high-frequency trading market makers. We utilize enterprise infrastructure providers (Auth0 for authentication, Plaid for banking connectivity, Supabase for data isolation, and Google Cloud Run for API hosting).

4. User Rights & Data Deletion

You retain the right at any time to export your data or delete your account permanently. Upon account deletion, all associated portfolio caches, session tokens, and watchlist entries are wiped from our active databases. Contact contact@ap-investment.com for data requests.