Effective 12 August 2026
Picksmith lets you optionally connect a brokerage account so My Holdings can show live positions instead of only manual entries. Here is exactly how that connection works and what we do — and do not — have access to. This page covers brokerage integrations specifically; see our full Privacy Policy and Terms of Service for complete details.
Connections use broker-issued API credentials, not your brokerage login:
Picksmith never receives or stores your brokerage username or password.
Picksmith's brokerage integrations are built for read-only access: we request positions (and related account info needed to display them) to power My Holdings and performance context. We do not place trades, move funds, or withdraw money. There is no flow in Picksmith to grant trading permissions, and we do not initiate trades or transfers on your behalf under any circumstance.
For Alpaca, create a read-only key when your broker allows it, so the credential itself cannot trade even outside Picksmith.
API keys, secrets, and tokens are encrypted at rest with Fernet (keyed from a server secret) before they are written to our database. We store only what is needed to reconnect and sync: provider, encrypted credentials, account identifier, a short key hint (for example the last few characters), and last-sync metadata. We do not store plaintext credentials.
Live positions are pulled from the broker when you use My Holdings; we do not keep a separate long-term copy of your full brokerage trade blotter for that sync.
Connections to brokers and to Picksmith use encrypted (TLS) transport.
You can disconnect a brokerage from Account → Broker connections. Disconnecting deletes the encrypted credentials from Picksmith immediately, so we retain no ongoing ability to read that account through our systems.
Disconnecting Picksmith does not automatically revoke the key or token at the broker. Also revoke or delete the API key or token in your Alpaca, Tradier, or SnapTrade settings if you want access removed at the source.
If no broker is connected, My Holdings uses the buy/sell transactions you enter manually. We use holdings data to show your portfolio and compare performance with the S&P 500. We do not sell this data or share it with advertisers.
Reviewing each provider's own security and privacy pages is a reasonable step before connecting.
Email support@picksmith.co or use the contact form. If you believe your account has been compromised, disconnect the broker on Account immediately, revoke the API key or token at the broker, and contact us.