AnvilANVIL

Privacy Policy

How your data is handled

Who we are

Anvil ("the app") is a personal trading and market-scanning tool that connects to your own broker account via API. The app operator is the data controller for the information described below.

What we collect

Broker API credentials — API key, identifier and password, which you enter yourself in Settings.

Trading activity — signals generated, order attempts, broker responses, position and account snapshots, and the audit trail of each placement.

Push subscriptions — the browser push endpoint and keys required to deliver notifications when the app is closed.

Local preferences — risk %, timeframe, notification toggles and environment selection, stored in your device's local storage.

How credentials are protected

Broker credentials are encrypted with AES-256-GCM before being written to the database and are only decrypted server-side at the moment a broker request is made. They are never exposed to the browser, never logged, and never shared with third parties.

How we use your data

Solely to operate the app for you: authenticating to your broker, scanning markets, sizing and placing orders you or your auto-trade settings authorise, showing your positions and history, and sending the notifications you have enabled. We do not sell data, run advertising, or profile you.

Third parties

Market data and order execution are provided by your broker (Capital.com), which is the controller of your brokerage account data under its own privacy policy. Application data is hosted on our managed cloud backend. Push messages are delivered via your browser vendor's push service.

Retention

Credentials are retained until you replace or delete them. Audit and event records are retained so you keep a complete trading record; you can request deletion at any time. Trade history itself is read live from your broker and is not duplicated permanently.

Your rights

Under UK GDPR you may request access, correction, deletion, restriction or portability of your personal data, and may withdraw consent for notifications at any time from the notification settings. Requests are handled through the contact route you use to reach the app operator.

Changes

This policy may be updated as the app evolves. Material changes will be surfaced in the app before they take effect.