Privacy Policy
Last updated: July 30, 2026
Overview
SharmAI is a personal financial AI assistant with optional paper trading, brokerage connections, strategy integrations, and email digests. This policy explains what information we collect, how it is used, and the choices available to you.
Information we collect
- Account details from Google sign-in (name, email, profile image).
- Chat messages, attachments, and session history you create in SharmAI.
- Trading preferences from Settings (risk profile, position limits, conviction gate, approval toggles, dashboard refresh, theme, default AI model), approval decisions, and workflow data related to proposed or executed trades.
- Optional connected services when you choose to link them — for example Robinhood connection tokens/account metadata, Composer by SoFi API credentials you store for strategy access, and Alpaca paper trading configuration.
- Portfolio and market context fetched on your behalf from data providers (quotes, filings, congressional/insider feeds, news) to power research tools, scanners, and digests.
- Email addresses used to deliver configured morning / end-of-day digests.
- Basic technical logs needed to operate, secure, and debug the service.
Data usage for AI
To generate responses, SharmAI sends relevant prompts and context to third-party AI model providers. This may include portions of your chat history, market questions, portfolio summaries, or trading-related instructions you provide. Do not share sensitive personal or financial information you are not comfortable processing through AI systems.
AI providers process data under their own privacy policies and security practices. SharmAI does not use your data to train public foundation models unless a provider's terms explicitly state otherwise.
How we use information
- Provide chat, Stock Hub, dashboard, Connections, digests, and trading workflow features.
- Store conversation history so you can return to prior chats.
- Enforce your Settings when proposing or staging trades (size, conviction, daily limits, hours, approval).
- Authenticate you and maintain account security.
- Improve reliability, prevent abuse, and troubleshoot issues.
Sharing
We do not sell your personal information. Data may be processed by infrastructure and product partners that help run SharmAI — hosting, database, authentication, AI APIs, market-data providers, email delivery, and brokerage/strategy connectors — under their own terms and security practices.
When you connect Robinhood or Composer, requests are made to those services using credentials you authorize. SharmAI does not control how those platforms use data once received.
Retention & deletion
Chat and account data are kept while your account is active so the product can function. You may delete individual chats from the sidebar. You may disconnect integrations and clear stored API credentials from Connections. Contact the operator to request account deletion.
Security
SharmAI is designed so that other users cannot read your chats, trades, or connected-account data through the product: access is gated by authentication and per-user database policies. Traffic between your browser and SharmAI is protected with HTTPS (TLS in transit). Google sign-in is handled by Supabase Auth; SharmAI does not receive your Google password.
Brokerage tokens and API credentials you connect (for example Robinhood or Composer by SoFi) are stored server-side and are not returned in normal API responses to the browser. Market-data and AI providers may receive the prompts and portfolio context needed to answer your requests — see “Data usage for AI” above.
Like most hosted apps, infrastructure operators and cloud providers that run the database, hosting, and email delivery can access systems required to operate the service (including backups). No online service can guarantee absolute security. You are responsible for safeguarding access to your account and for the credentials you choose to connect.
Contact
Questions about this policy can be sent to the SharmAI operator through the email associated with your workspace account.