Privacy policy
This privacy page explains, at a high level, how Monstra may collect, use, and retain information while you use Monstra software, including optional brokerage connectivity and paper automation features.
Monstra may collect account profile details, authentication identifiers, subscription records, product usage data, request logs, support messages, and bot interaction history needed to operate the service.
If you connect Alpaca, Monstra may receive and store your brokerage API credentials in encrypted form on Monstra servers, along with account metadata, holdings, balances, order status, rebalance previews, automation settings, and audit events required to support brokerage features and operational safety checks.
Monstra may use collected data to authenticate users, deliver product functionality, improve system reliability, investigate abuse, support billing, maintain audit trails, and surface algorithmic research, automation, and account-management features.
Brokerage connectivity data may be used to display supported account views, run user-requested manual workflows, verify paper automation eligibility, and maintain user-visible audit history. It is not used to provide personalized financial advice.
Some data displayed in Monstra may come from third-party providers or integrations and may be delayed, stale, incomplete, or temporarily unavailable. Monstra cannot guarantee uninterrupted availability or perfect data accuracy across every provider dependency.
Payment, authentication, hosting, analytics, and brokerage connectivity may involve third-party service providers including Stripe, Apple In-App Purchase, RevenueCat, Clerk, and Alpaca. Each operates under its own terms and privacy practices.
Monstra retains operational records, brokerage audit logs, and safety telemetry for as long as reasonably necessary to support security monitoring, billing and fraud prevention, legal and regulatory obligations, operational support, and dispute resolution. Specific retention periods vary by data category and applicable law.
Users should independently evaluate algorithmic outputs before acting on them elsewhere. Bot outputs are not personalized recommendations.