Policy revision: September 18, 2026. Operator: Jacob Devin. Contact: flexocm@gmail.com.
What the service processes
We verify your Google issuer and subject to identify your app account. Browser sign-in confirms the same identity before connecting SnapTrade. The backend receives and verifies SnapTrade authorization, stores encrypted access and refresh tokens, and requests the account datasets you select. Brokerage data passes through the backend. We do not ask for brokerage passwords.
Storage and retention
Grants remain encrypted until disconnect or deletion. Encrypted import configuration, account metadata, and financial table chunks are retained for up to 24 hours of use. Expired jobs become inaccessible immediately; an hourly cleanup removes expired records within the next hour when the deployment is healthy. OAuth launch material expires after 10 minutes and browser sessions after 15 minutes. Operators must monitor cleanup; service disruption can delay physical deletion.
Google Apps Script user properties retain per-user import settings for each spreadsheet. The spreadsheet itself contains imported values and temporary stage/backup tabs. Successful import or recovery removes temporary tabs; interrupted imports retain them for recovery. Hidden tabs are not a privacy boundary. User properties also retain a random output-ownership marker so you can remove your managed values after backend deletion.
Use and sharing
Data is used to authenticate, connect, import, refresh, and recover requested tables. We do not sell financial data or use advertising trackers. Google, SnapTrade, Vercel, and the configured PostgreSQL provider process data to deliver their respective services. The operator must publish the chosen database provider, hosting region, and backup retention before release.
Your choices
Disconnect revokes app access where possible and erases local credentials and active jobs. Delete app data also removes saved import settings and the backend identity record. Remote revocation failures are reported with dashboard instructions. Brokerage connections in SnapTrade are not deleted. See data deletion for spreadsheet removal and copy/export limitations.
Google user data
Access is limited to the current spreadsheet and the functions described here. Google user data is not used for advertising or to train generalized AI models. The service’s use and transfer of information received from Google APIs must adhere to the Google API Services User Data Policy, including applicable Limited Use requirements. Generated policy text does not establish legal compliance.