Privacy Policy
Last updated: July 13, 2026
This policy describes what data BagBot ("we") collects when you use bagbot.gg and the BagBot mobile app, how we use it, and the choices you have.
Data we collect
- Account data. Your email address, name, and authentication details, managed through our sign-in provider, Clerk.
- Brokerage credentials. If you connect your own Alpaca account, the API keys you provide are encrypted and used solely to place and manage orders you have authorized. You can revoke them at any time from your Alpaca dashboard.
- Identity verification (managed brokerage accounts). If you open a brokerage account through the app, the information required for KYC — such as your SSN, date of birth, ID images, and bank details — is passed directly to Alpaca and is never stored in BagBot's database. We retain only Alpaca's opaque account identifiers and categorical status codes.
- Prediction-market credentials. If you connect Polymarket, the wallet key you provide is encrypted and used solely to place orders you have authorized.
- Trading activity. Orders, positions, approvals, and results for accounts you connect, so we can show your portfolio and history and operate the service.
- Connected content. Posts and messages ingested from sources that you or group creators connect (such as Discord channels or X accounts), used to surface signals.
- Usage data. Product analytics, device information, and push notification tokens.
- Payments. Card and billing details are collected and processed by Stripe. We never see or store your full card number.
How we use it
To operate the service: authenticate you, deliver signal alerts, prepare and execute trades you authorize, display your portfolio, bill subscriptions and fees, provide support, and improve the product. We do not sell your personal data.
Who we share it with
Service providers who operate parts of the product on our behalf: Alpaca (brokerage execution and account opening), Polymarket (event-contract execution), Clerk (authentication), Convex (database and backend), Stripe (payments), and our analytics, email, and push-notification providers. Each receives only what it needs for its function. We may also disclose data where required by law.
Retention and deletion
We keep account and trading records while your account is active and as required for legal, accounting, regulatory, security, and audit purposes. You can revoke brokerage access at any time by deleting your API keys at your broker. To request deletion of your BagBot account and associated personal data, use our account deletion page or contact support@bagbot.gg.
Security
Credentials are encrypted in transit and at rest, access is restricted, and sensitive identity documents are proxied to our brokerage partner rather than stored. No system is perfectly secure; we encourage strong, unique passwords and prompt reporting of any suspected issue.
Eligibility
BagBot is not directed at children and is available only to users who are old enough to open a brokerage account in their jurisdiction (18+ in the United States).
Changes
We may update this policy from time to time. Material changes will be announced in the app, and the "Last updated" date above always reflects the current version.
Contact
Questions about this policy: support@bagbot.gg. See also our Terms of Service, Disclosures, and Account Deletion.