Privacy Policy
Last updated: July 2, 2026
This policy explains what OpenFund stores, how it’s protected, and the choices you have. By using the Service you agree to this policy.
The short version.
We store only what’s needed to run your account and your trading workspace. Your broker keys and two-factor secrets are encrypted at rest. Each user’s data is isolated from every other user. We do not sell your data.
What we store
- Account: your email, display name, and a securely hashed password (scrypt with a per-user salt — never the plaintext).
- Broker credentials: the API keys you connect, encrypted at rest (AES-256-GCM). They are used only to place trades you or your agents initiate.
- Two-factor secrets: stored encrypted at rest and used only to verify your login codes.
- Trading data: your positions, orders, journal, and performance history — visible only to you.
- Sign-in with Google (optional): if you use it, we receive your email, name, and Google account ID to identify your account.
How it’s protected
- Traffic is served over HTTPS/TLS.
- Sensitive fields (broker keys, 2FA secrets) are encrypted at rest with a key held outside the data files.
- Sessions expire, failed logins are rate-limited, and each workspace is sandboxed to its owner.
What we don’t do
- We don’t sell or rent your personal data.
- We don’t custody or move your money — trades run through your own brokerage.
- We don’t share your trading data with other users.
Third parties
To function, the Service may send data to: your chosen brokerage (to place trades), market-data providers (for quotes and news), AI model providers (for agent research, where enabled), and Google (only if you use Google sign-in). Each processes data under its own terms.
Your choices
- Disconnect your broker at any time from Account → Broker connection; this deletes the stored keys.
- Delete your account from Account → Danger zone; this removes your profile and trading workspace.
- Enable two-factor authentication for stronger login security.
Changes
We may update this policy from time to time. Material changes will be reflected by the “last updated” date above.
Terms of Service →