Privacy policy
This Privacy Policy explains how Monstra, LLC (“Monstra,” “we,” “us,” or “our”) collects, uses, shares, and retains personal information when you use the Monstra website, hosted application, and related services (the “Service”). It is incorporated into the Monstra Terms of Service and End User Agreement and should be read with them. Monstra is free to use; there is no subscription or purchase flow, so no billing or payment data is collected.
Information you provide
Brokerage information
If you connect Alpaca — by authorizing Monstra through Alpaca Connect (OAuth) or by pasting an API key and secret — Monstra receives and stores your OAuth access token or API credentials in encrypted form on Monstra servers, together with account metadata, holdings, balances, order status, rebalance previews, automation settings, and audit events needed to support brokerage features and operational safety checks. Monstra does not ask for, and you should not provide, your brokerage username or password.
Information collected automatically
Information from third parties
We receive account and profile details from our authentication provider, and brokerage and market data from Alpaca and other market data providers, as described in this policy.
We use personal information to:
Brokerage connectivity data is not used to provide personalized financial advice, and Monstra does not use personal information for third-party advertising.
Monstra does not sell your personal information. We share it only as described here.
Service providers
We use third-party providers that process personal information on our behalf. Each operates under its own terms and privacy practices. The principal providers as of the effective date are:
We will update this list when our principal providers change.
Brokerage transmissions
At your direction, Monstra sends requests and simulated paper orders to Alpaca for the brokerage connection and automation you have enabled.
Other users
Creator Bots and portfolios you publish, along with your username and avatar, may be visible to other users of the Service.
Legal and business reasons
We may disclose information to comply with law or legal process, to protect the rights, property, or safety of Monstra or others, and in connection with a merger, acquisition, financing, or sale of assets, subject to this policy.
Monstra and its providers use cookies and similar technologies. Some are essential, such as those that keep you signed in and remember your preferences. Others support analytics: the Service uses Google Analytics to understand how the site is used. You can block or delete cookies in your browser settings or use Google's browser opt-out tools, though blocking essential cookies may prevent you from signing in.
Some features, such as assistants, autofill, and description generation, send the text and strategy details you enter to OpenAI to generate a response. Do not enter sensitive personal information into these features. OpenAI processes that information under its own terms and privacy practices, and AI output may be inaccurate. Monstra also uses AI to generate research and news summaries from public market information.
Some data displayed in Monstra comes from third-party providers or integrations and may be delayed, stale, incomplete, or temporarily unavailable. Monstra cannot guarantee uninterrupted availability or perfect data accuracy across every provider dependency.
Monstra retains operational records, brokerage audit logs, and safety telemetry for as long as reasonably necessary to support security monitoring, fraud and abuse prevention, legal and regulatory obligations, operational support, and dispute resolution. Specific retention periods vary by data category and applicable law. When you delete your Account, we delete your Account data as described below, though copies may remain in backups and logs for a limited time and we may keep records we are required or permitted to keep for legal, security, or fraud-prevention purposes.
You can also make any privacy request by emailing Support@monstra.bot.
Brokerage credentials and access tokens are stored in encrypted form, and we use access controls and monitoring to protect personal information. No method of transmission or storage is completely secure, and Monstra does not warrant that unauthorized access will never occur. You are responsible for keeping your sign-in credentials confidential.
This section supplements the rest of this policy and applies to California residents under the California Consumer Privacy Act, as amended (“CCPA”).
Categories of personal information collected
In the past 12 months, Monstra has collected the following categories:
Brokerage credentials and access tokens are “sensitive personal information” under the CCPA. Monstra uses them only to provide the Service you request, so there is no right to limit their use.
Sources, purposes, and disclosures
We collect this information from you, from your devices, and from the providers described above, for the purposes described in “How we use information.” We disclose it for business purposes to the service providers listed in “How we share information.” In the past 12 months we have not sold or shared personal information, as those terms are defined in the CCPA.
Your rights
California residents may request to:
To make a request, email Support@monstra.bot. We will need to verify your identity by matching information you provide to information in your Account. An authorized agent may submit a request for you with your written permission. We aim to respond within 45 days and will tell you if we need more time.
Under California Civil Code § 1798.83, California residents may ask which categories of personal information we disclosed to third parties for their direct marketing purposes. Monstra does not disclose personal information for that purpose.
The Service is intended for people who are at least 18 years old. Monstra does not knowingly collect personal information from anyone under 18. If you believe a minor has provided us personal information, contact us and we will delete it.
Monstra is based in the United States. Your information is processed and stored in the United States and in any other country where our service providers operate.
Monstra's source code is publicly available under the GNU Affero General Public License v3.0 (AGPL-3.0) at github.com/MPoncini96/Monstra, including instructions for self-hosting your own instance with your own brokerage connection instead of using Monstra's hosted service. This policy covers only the hosted Service. If you run a self-hosted instance, you operate it and are responsible for the data it handles; Monstra does not receive personal information from instances it does not operate.
We may update this policy from time to time. Material changes will be posted here with an updated effective date and, where practicable, notice through the Service. Your continued use after the effective date of a change constitutes acceptance of the revised policy.
Monstra, LLC — Support@monstra.bot