Legal

Privacy Policy

Effective date: June 9, 2026

1. Introduction

YieldDock ("we," "us," or "our") operates the website and application available at www.theyielddock.com (the "Service"). This Privacy Policy explains what information we collect, how we use it, and what rights you have. By using the Service you agree to the practices described here.

YieldDock is a read-only portfolio tracking tool. We connect to your brokerage accounts solely to display aggregated data. We do not trade, transfer, deposit, or withdraw funds on your behalf under any circumstances.

2. Information We Collect

Account information. When you register, we collect your email address, name, and a hashed password, stored in our authentication provider (Supabase) and used solely to authenticate you.

Brokerage connection credentials. When you connect a brokerage, we receive an OAuth token from our third-party brokerage connectivity provider (SnapTrade). These tokens authorize read-only data pulls only. We store them encrypted. YieldDock employees do not use these credentials for any purpose other than fetching your portfolio data at your request.

Portfolio data. We retrieve and temporarily cache portfolio snapshots (positions, balances, transactions, options) from your brokerage via SnapTrade. This data is associated with your account and is not shared with third parties for advertising or profiling.

Usage data. We may collect standard server logs (IP address, browser type, pages visited, timestamps) for security monitoring and service improvement. This data is not sold or shared for marketing purposes.

Communications. If you contact us by email, we retain your message and contact details to respond to you.

3. How We Use Your Information

We use information we collect to: provide and maintain the Service; authenticate your identity and protect your account; retrieve and display your brokerage data at your request; generate AI-assisted insights based on your portfolio; send transactional emails (confirmations, password resets); detect and prevent fraud and unauthorized access; and comply with legal obligations.

We do not sell, rent, or trade your personal information. We do not use your portfolio data to train AI models or for purposes beyond providing the Service to you.

4. Third-Party Services

The Service integrates with third-party providers whose privacy policies also apply to you:

  • SnapTrade – brokerage connectivity. SnapTrade establishes read-only OAuth connections. YieldDock never stores your brokerage username or password directly.
  • Supabase – authentication and database. Your account credentials and portfolio data are stored on Supabase-hosted infrastructure.
  • Market Data Providers (e.g. Polygon.io) – stock quotes, options chains, and dividend data are sourced from third-party providers on an "as-is" basis and may be delayed per their terms.
  • AI Providers (OpenAI / Anthropic) – when you request AI analysis, summarized portfolio data may be sent to AI providers to generate responses. We do not send your brokerage credentials or personally identifiable account numbers to AI providers.

5. Data Visibility and Access

YieldDock is designed so that YieldDock employees and staff do not have routine visibility into your individual brokerage account data. Your portfolio snapshots are fetched on-demand by the application in response to your own requests. No YieldDock personnel review your individual holdings, positions, or transactions in the normal course of operations. Access to production databases is restricted to authorized engineering personnel solely for operating and maintaining the Service and responding to security incidents.

6. Data Security

We implement industry-standard security measures including TLS encryption in transit, encrypted storage for sensitive credentials, database-level row security, and strict access controls. However, no electronic storage or transmission is 100% secure. We cannot guarantee absolute security. We encourage you to use strong, unique passwords and enable multi-factor authentication on your brokerage accounts independently of YieldDock.

7. Data Retention

We retain your account information for as long as your account is active or as needed to provide the Service. You may request deletion of your account and all associated data at any time by emailing hello@theyielddock.com. Portfolio snapshots are transient and are not retained beyond the caching period needed to serve the application.

8. Your Rights

Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data. To exercise any of these rights, contact us at hello@theyielddock.com. We will respond in a reasonable time and in accordance with applicable law.

9. Children's Privacy

The Service is not directed to children under 18. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal information, please contact us and we will promptly delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the effective date. Your continued use of the Service after changes constitutes acceptance of the updated policy.

11. Contact

Questions about this Privacy Policy? Email us at hello@theyielddock.com.