Privacy Policy
This Policy explains how RoboSelf handles personal information when you visit, create an account, connect providers, use trading and AI tools, participate in community features, or contact us.
Effective and last updated: July 17, 2026 · Version privacy-2026-07-17-us-ca-v2
1. Scope and accountability
RoboSelf, the operator of the Investapp service (“RoboSelf,” “we,” “us,” or “our”), is responsible for the personal information it controls. This Policy applies to our websites, web and mobile applications, APIs, support, and related services (the “Service”). It does not replace the privacy notices of your broker, SnapTrade, an AI provider, Stripe, Google, or another independent service you choose to use.
Our Privacy Officer can be contacted at privacy@roboself.app. We may need to verify your identity and authority before completing a privacy request.
2. Information we collect
Account, identity, and profile information
This may include your name, email address, authentication identifier, avatar, username, country or region, language, time zone, experience level, risk tolerance, goals, market interests, preferences, and account settings. Authentication providers such as Firebase or Google may supply identifiers and basic profile information when you sign in.
Broker, portfolio, and financial-account information
When you connect a broker directly or through SnapTrade, we may receive connection identifiers and permissions; brokerage and account names or types; masked account numbers; balances, buying power, currency, holdings, positions, transactions, orders, fills, fees, and status; and connection or synchronization metadata. Depending on the connection method, we may process broker API credentials or access tokens. Provider-hosted authorization may allow connection without RoboSelf receiving your broker password.
RoboSelf does not receive custody of the cash or securities in your connected brokerage account. Disconnecting a broker stops future connection activity through RoboSelf but may not immediately delete information already stored for security, reconciliation, legal, or account-history purposes.
Strategies, trading activity, and analytics
We process strategy rules, symbols, time frames, parameters, risk controls, optimization inputs and results, historical data selections, backtests, paper trades, deployments, signals, alerts, approvals, order instructions, positions, performance records, portfolio analytics, and related logs. This information may reveal financial interests and activity and is treated accordingly.
AI data
We may process prompts, instructions, selected model and provider, files or market context supplied to a model, outputs, feedback, token or cost usage, error logs, and AI-agent configurations and actions. If you bring your own provider key, we process the key or token to make the requested call and manage the connection. Do not submit secrets, third-party personal information, or confidential material unless you are authorized and the disclosure is necessary.
Billing, subscription, and referral information
We may receive Stripe customer and subscription identifiers, plan, billing interval, payment status, invoice and transaction identifiers, partial payment-method details such as card brand and last digits, tax status, trial and renewal dates, cancellation state, discounts, and refunds. We may also process referral codes, affiliate attribution, and associated reward status. Full card entry is generally handled by Stripe.
Community, communications, and support
This may include public profile information, posts, comments, reactions, ratings, shared strategies, reports, moderation records, contact-form submissions, support messages, survey responses, and feedback. Content you choose to publish is visible to other users and may be indexed or copied outside the Service.
Device, usage, cookie, and security information
We may collect IP address, browser and device type, operating system, app version, language, identifiers, referring URL, pages and features used, timestamps, session and authentication events, API calls, crash and diagnostic data, security events, approximate location inferred from IP, and cookie or local-storage values. Legal acceptance records may include document and acknowledgement versions, timestamp, applicable legal-package scope, IP address, and user agent.
Notification information
If you enable notifications, we may process web-push subscriptions and device tokens or identifiers used for email, SMS, WhatsApp, Telegram, or other channels, together with delivery, preference, and unsubscribe status.
3. Where information comes from
- You: information you enter, upload, configure, publish, or authorize.
- Your devices: technical, usage, cookie, local-storage, security, and diagnostic information.
- Connected services: brokers, SnapTrade, authentication providers, payment providers, AI providers, notification channels, and market-data or news sources.
- Other users or public sources: community activity, shared content, reports, public filings, and market information.
- Our systems: derived analytics, risk metrics, fraud signals, service logs, and records produced when you use the Service.
4. Why we use information
We use personal information to:
- create, authenticate, secure, support, and administer accounts;
- connect and synchronize services you authorize and display broker, portfolio, strategy, and order information;
- run backtests, simulations, analytics, AI requests, agents, alerts, notifications, and user-directed automation;
- process subscriptions, trials, discounts, referrals, invoices, cancellations, and account entitlements;
- provide public or community features according to your sharing choices;
- diagnose errors, reconcile records, monitor reliability, prevent fraud and abuse, enforce limits and terms, and protect users and markets;
- respond to questions, privacy requests, disputes, security incidents, and legal process;
- measure and improve features, interfaces, and performance using information reasonably necessary for those purposes; and
- comply with tax, accounting, sanctions, court, regulatory, recordkeeping, and other legal obligations.
Depending on the law and context, our authority may be your consent, performance of our contract with you, compliance with law, or our legitimate interests in operating and securing the Service. We seek express consent where required for sensitive or unexpected processing. You may withdraw consent, subject to legal or contractual limits, but doing so may prevent the affected feature from working.
5. How and why we disclose information
We may disclose relevant information to the following recipients:
- Brokers and connectivity providers: including SnapTrade and a broker you select, to connect accounts, retrieve authorized data, transmit instructions, synchronize status, and troubleshoot.
- AI providers: including OpenRouter or the model provider you select, to process prompts and context, return output, and measure usage. Provider handling may also be governed by your own provider account and terms.
- Cloud, authentication, and security providers: including Firebase, Google Cloud, and reCAPTCHA, to host, authenticate, protect, and operate the Service.
- Payments and business operations: including Stripe, analytics, communications, notification, support, and professional service providers that perform work for us.
- Market-data, news, and research providers: when identifiers or request context are needed to retrieve the data or feature you request.
- Affiliates and referral participants: for attribution, fraud prevention, and reward administration, limited to what is reasonably needed.
- The public or other users: when you publish a profile, post, rating, comment, agent, strategy, or share link.
- Authorities and affected parties: where we reasonably believe disclosure is required or permitted by law, legal process, safety, security, fraud prevention, rights enforcement, or market-integrity obligations.
- Transaction parties: in a financing, reorganization, merger, sale, or transfer, subject to confidentiality and applicable law.
We instruct service providers acting on our behalf to process information for the services they provide to us, subject to their roles and applicable agreements. Some connected providers act independently under their own terms and may determine their own purposes and practices. We remain accountable for personal information transferred to processors where applicable law requires it.
6. AI providers and model use
The AI provider, model, and context can vary by feature and your configuration. A request may include your prompt plus selected strategy, portfolio, market, or account context needed to answer it. Review the provider identified in the AI-provider settings before use. Do not assume a provider will treat data under RoboSelf’s retention settings when you use your own key or provider account.
RoboSelf does not intentionally include broker passwords, authentication secrets, private API keys, or full payment-card data in an AI request. A request may nevertheless include the prompt and the strategy, portfolio, market, account, or other context identified by the feature. AI routing and model providers may process, retain, log, or use requests and outputs under the provider arrangement, selected account settings, and their own terms. Their practices can change. Review the provider identified at the point of use, and do not submit information you are not authorized to disclose.
If we introduce a materially different AI-data purpose that requires notice or consent, we will provide the applicable notice and request consent before that use as required by law. Contact the Privacy Officer for information about the provider and configuration relevant to your account.
See the AI Disclaimer for accuracy, suitability, and human-review limitations.
7. Cookies and similar technologies
We and our providers may use:
- Essential storage for authentication, security, load balancing, and core preferences;
- Functional storage for interface settings, experience mode, and saved local preferences;
- Measurement data to understand feature use, errors, and journey completion; and
- Attribution storage to remember a referral code for up to 90 days and administer a requested discount or reward.
reCAPTCHA may collect device and interaction information to distinguish people from abusive traffic. Referral storage is set when a referral code is supplied to the signup page so the requested attribution or discount can remain available during signup. Browser and device settings can remove or block cookies and local storage, but the related preference or feature may stop working.
We do not currently sell personal information for money or use it for cross-context behavioural advertising. Some laws define “sale” or “sharing” more broadly; eligible users may contact us to ask about or exercise an applicable opt-out right.
8. Retention and deletion
We retain information only as long as reasonably necessary for the purposes described above, considering account status, feature needs, sensitivity, security, reconciliation, dispute and limitation periods, tax and accounting rules, legal obligations, provider constraints, and backup cycles. Different categories have different periods.
- Active account, strategy, broker, and subscription records are generally kept while the account or feature is active.
- Order, execution, reconciliation, security, legal-acceptance, billing, and audit records may remain while the account is active and in restricted backups after deletion. The current local account-deletion workflow removes records linked to the local user record, including local legal-acceptance history; we will provide notice before introducing a separate post-deletion legal-evidence retention practice.
- Public content may remain visible until you delete it or close the account, but copies may persist in other users’ records, search caches, moderation evidence, or lawful backups.
- Deleted information may remain in restricted backups until overwritten under the applicable backup cycle.
When retention is no longer justified, we delete, de-identify, or aggregate the information. Broker disconnection, subscription cancellation, and local account deletion are distinct actions and may have different effects. Local account deletion does not necessarily complete deletion from every backup or external system used by Firebase, Stripe, a broker, SnapTrade, an AI provider, or another connected service. Provider roles, retention rules, and request processes may also apply; where a provider processes personal information for us, we remain accountable as required by applicable law.
9. International processing
RoboSelf and its providers may process information in Canada, the United States, and other countries where providers or selected models operate. Those countries may have different privacy laws, and courts, regulators, or law-enforcement authorities there may lawfully access information. We use contractual, organizational, and technical measures appropriate to the transfer and remain accountable as required by applicable law.
10. Safeguards and incidents
We use administrative, technical, and physical safeguards designed for the nature and sensitivity of the information. Depending on the system, these safeguards may include access controls, authentication, encryption in transit, protected secret storage, logging, monitoring, and incident procedures. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
If a breach creates a notification or reporting duty, we will notify affected individuals and regulators as required by applicable law. You are responsible for securing your own devices and promptly revoking compromised broker or AI-provider credentials with the relevant provider.
11. Your choices and privacy rights
Depending on where you live and subject to exceptions, you may have the right to:
- know whether we process your personal information and receive access to it;
- correct inaccurate or incomplete information;
- request deletion, de-indexing, restriction, or a portable copy;
- withdraw consent or object to certain processing;
- opt out of marketing communications, sale, sharing, or targeted advertising where applicable;
- receive information about an automated decision and request review where law provides that right; and
- complain to a privacy regulator without discriminatory treatment for exercising a right.
You can update many profile and connection settings in the Service. Submit other requests to privacy@roboself.app. Describe the request, your account email, and jurisdiction. We may ask for proportionate verification, and an authorized agent may need to show authority. We will respond within the period required by applicable law.
Canada
Eligible users may request access and correction, challenge our compliance, and withdraw consent subject to legal or contractual restrictions. You may complain to the Office of the Privacy Commissioner of Canada or the applicable provincial regulator after first giving us an opportunity to address the concern.
United States
Residents covered by a state privacy law may have rights to know, access, correct, delete, obtain a copy, and opt out of sale, sharing, targeted advertising, or certain profiling, subject to thresholds and exceptions. We will not discriminate against you for exercising an applicable right, though a feature may be unavailable if required information cannot be processed.
12. Marketing and notifications
You can manage optional communications through available settings or the unsubscribe method in the message. We may still send service, billing, security, legal, and transaction communications needed for your account. Consent to optional marketing is not a condition of opening an account or using core features, and we do not treat a referral as permission to contact another person without a lawful basis.
13. Children
The Service is for adults who have reached the age of majority where they live. We do not knowingly offer trading accounts or collect personal information through the Service from children. If you believe a child provided information, contact the Privacy Officer so we can investigate and take appropriate action.
14. Changes to this Policy
We may update this Policy to reflect new features, providers, laws, or practices. We will post the effective date and provide additional notice for a material change. Where a significant new collection, use, or disclosure requires consent, we will request it before the change takes effect rather than relying only on a posted update.
15. Contact
Contact the Privacy Officer at privacy@roboself.app for questions, complaints, rights requests, or information about providers and cross-border processing relevant to your account. Please do not email passwords, full account numbers, broker secrets, private keys, or full payment-card details.