Legal
Privacy Policy
Last updated: May 28, 2026
This Privacy Policy explains how Tomcrest ("Tomcrest," "we," "us") handles information when you use our website and application. It applies to visitors and signed-in users. For a shorter, product-focused overview, see our security & privacy overview.
These documents describe how Tomcrest works today. They are not legal advice; consider having qualified counsel review them before you rely on them for regulatory or commercial obligations.
1. Who we are
Tomcrest provides AI-assisted portfolio intelligence for individual investors. We operate the Tomcrest web application and related services.
Privacy questions and requests: support@tomcrest.com.
2. Information we collect
Depending on how you use Tomcrest, we may collect:
- Account information — When you sign in with Google, we receive identifiers and profile details Google shares with us (such as your email address and name) to create and maintain your Tomcrest account.
- Brokerage data (optional) — If you connect Charles Schwab, we receive read-only data Schwab makes available through OAuth, such as account identifiers, holdings, cash balances, open options, and recent orders. We do not receive your Schwab password.
- Product usage data — Strategy preferences, watchlists, chat history, settings, and similar in-app content you create or save.
- AI interactions — Prompts and context we send to our AI providers to generate responses (for example, portfolio summaries, research answers, and news analysis for Pro users).
- Technical data — Log data, device/browser type, IP address, and analytics events that help us operate, secure, and improve the service.
- Communications — Information you send when you contact support.
3. How we use information
- Provide, maintain, and personalize the Tomcrest service
- Sync and display your portfolio, research, and alerts
- Generate AI-powered insights grounded in your context
- Authenticate you and protect against abuse or fraud
- Respond to support requests and communicate about the product
- Understand usage and improve features (including analytics)
- Comply with law and enforce our Terms of Service
We do not sell your brokerage holdings or Schwab account data.
4. Schwab and Google
Read-only Schwab access via OAuth — Tomcrest does not receive your login credentials and cannot place trades.
Schwab and Google process your information under their own policies when you use their sign-in or authorization flows. Tomcrest only receives data you authorize through those flows. You can disconnect Schwab in Tomcrest Settings or revoke Tomcrest in your Schwab account settings.
5. AI and market data providers
We use third-party services to power AI features and market/company data (for example, large language model providers and market data APIs). Those providers process data on our behalf according to their agreements with us and only as needed to deliver the feature you request.
AI output may be inaccurate or incomplete. Do not treat it as financial, tax, or legal advice.
8. Retention
We retain information for as long as your account is active or as needed to provide the service, comply with legal obligations, resolve disputes, and enforce agreements. When you disconnect Schwab, we stop syncing new brokerage data. Chat history and preferences may remain until you delete your account or ask us to delete eligible data.
9. Security
We use reasonable administrative, technical, and organizational measures to protect information. No method of transmission or storage is completely secure. See our security overview for more detail.
10. Your choices and rights
- Disconnect Schwab or sign out of Tomcrest at any time
- Revoke Google access to Tomcrest from your Google account settings
- Email us to request access, correction, or deletion of account data where applicable law provides those rights
If you are a California resident, you may have additional rights under applicable privacy laws. Contact support@tomcrest.com to exercise them.
11. Children
Tomcrest is not directed to children under 13 (or the minimum age required in your jurisdiction), and we do not knowingly collect their personal information.
12. International users
Tomcrest is operated from the United States. If you access the service from other regions, your information may be processed in the U.S. and other countries where our providers operate.
13. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version with a new "Last updated" date. Material changes may be communicated in the app or by email where appropriate.
14. Contact
Include the Google email you use to sign in so we can locate your account.
See also Terms of Service.
