Picksmith
Menu
Home
Research Latest ResearchPick RankingFree ResearchCEO Central
Stock Search
Tools NewsCapitol TradesFollow the Money
Financial Wellbeing Retirement CalculatorInvestment CalculatorTax HarvestLoan Calculator
Event Calendar Market EventsEarningsStock SplitsUpgrades & Downgrades
BlogPricing

Account

Sign up freeLog in
My HoldingsAccountSubscribeLog out
    Sign up freeLog in
    My HoldingsAccountSubscribefrom $14.99/moLog out

    Home
    Research
    Latest ResearchPick RankingFree ResearchCEO Central
    Stock Search
    Tools
    NewsCapitol TradesFollow the Money
    Financial Wellbeing
    Retirement CalculatorInvestment CalculatorTax HarvestLoan Calculator
    Event Calendar
    Market EventsEarningsStock SplitsUpgrades & Downgrades
    BlogPricing

    How We Protect Your Data

    Effective 12 August 2026

    Picksmith lets you optionally connect a brokerage account so My Holdings can show live positions instead of only manual entries. Here is exactly how that connection works and what we do — and do not — have access to. This page covers brokerage integrations specifically; see our full Privacy Policy and Terms of Service for complete details.

    We never ask for your brokerage username or password

    Connections use broker-issued API credentials, not your brokerage login:

    • Alpaca — you create an API key and secret in your Alpaca dashboard and paste them into Picksmith. Prefer a read-only key.
    • Tradier — you create an access token in Tradier's API Access settings and paste it into Picksmith.
    • SnapTrade (when available) — you authenticate in SnapTrade's portal so supported brokerages can be linked without pasting those brokers' passwords into Picksmith.

    Picksmith never receives or stores your brokerage username or password.

    Read-only use

    Picksmith's brokerage integrations are built for read-only access: we request positions (and related account info needed to display them) to power My Holdings and performance context. We do not place trades, move funds, or withdraw money. There is no flow in Picksmith to grant trading permissions, and we do not initiate trades or transfers on your behalf under any circumstance.

    For Alpaca, create a read-only key when your broker allows it, so the credential itself cannot trade even outside Picksmith.

    How credentials are stored

    API keys, secrets, and tokens are encrypted at rest with Fernet (keyed from a server secret) before they are written to our database. We store only what is needed to reconnect and sync: provider, encrypted credentials, account identifier, a short key hint (for example the last few characters), and last-sync metadata. We do not store plaintext credentials.

    Live positions are pulled from the broker when you use My Holdings; we do not keep a separate long-term copy of your full brokerage trade blotter for that sync.

    Data in transit

    Connections to brokers and to Picksmith use encrypted (TLS) transport.

    Revoking access

    You can disconnect a brokerage from Account → Broker connections. Disconnecting deletes the encrypted credentials from Picksmith immediately, so we retain no ongoing ability to read that account through our systems.

    Disconnecting Picksmith does not automatically revoke the key or token at the broker. Also revoke or delete the API key or token in your Alpaca, Tradier, or SnapTrade settings if you want access removed at the source.

    What else we store for My Holdings

    If no broker is connected, My Holdings uses the buy/sell transactions you enter manually. We use holdings data to show your portfolio and compare performance with the S&P 500. We do not sell this data or share it with advertisers.

    Third parties involved

    • Alpaca — SOC 2 Type II (per Alpaca's public security page)
    • Tradier — review their privacy and security practices before connecting
    • SnapTrade — SOC 2 Type II (when that connect option is enabled)

    Reviewing each provider's own security and privacy pages is a reasonable step before connecting.

    Questions or concerns

    Email support@picksmith.co or use the contact form. If you believe your account has been compromised, disconnect the broker on Account immediately, revoke the API key or token at the broker, and contact us.

    Picksmith

    Quality Company Research

    Research

    • Latest Research
    • Pick Ranking
    • Free Research
    • CEO Central

    Tools

    • News
    • Capitol Trades
    • Follow the Money
    • Stock Search

    Financial Wellbeing

    • Retirement Calculator
    • Investment Calculator
    • Tax Harvest
    • Loan Calculator

    Event Calendar

    • Market Events
    • Earnings
    • Stock Splits
    • Upgrades & Downgrades

    Company

    • Blog
    • Pricing
    • About
    • Contact

    Profile

    • Sign up free
    • My Holdings
    • Account
    TermsPrivacyData protectionRefunds

    For informational and educational purposes only — not investment advice. Past performance is not indicative of future results.

    © 2026 Picksmith