Collected on purpose.
Stored on this box.
1 · What we store
One login per person: username plus a salted, slow-hashed password (PBKDF2, 60k rounds — never stored in plaintext, never displayed). A session cookie so you stay signed in (HttpOnly, SameSite strict, 30 days). Nothing else about you — no email harvesting, no profiles, no analytics.
2 · What we deliberately don't do
No ad networks. No trackers. No cookies for advertising. No sale of data — there's no data to sell. Broker API credentials (Alpaca by default) are stored only for your own account's execution in paper or live real-money mode, encrypted at rest, and are used solely to place the orders you approve — never for anything else.
3 · Third parties that touch this page
Apache ECharts — charts render locally in your browser from self-hosted code (no third-party calls for charts). Google Fonts — typefaces load from their CDN. Alpaca — the operator's data source (server-side, not from your browser). Each has its own privacy policy; this site adds nothing to them.
4 · Your controls
Sign out anywhere (session cookie invalidated). Ask to have the login record deleted — it's one line in one file, and deletion is honored. In a future commercial version, users would connect their own brokers via OAuth — at which point credentials would never touch this server at all.
5 · Security posture
TLS enforced on every route; login rate-limited; password hashes file-permission restricted (0600); the dashboard server binds to localhost only behind TLS; live data endpoints require an authenticated session.