Privacy Policy
Last updated: September 7, 2026
The short version
Futures has no account with us, no analytics, and no trackers, and it collects
nothing about you as a person. It talks to two services, both of which you
connect yourself with credentials you supply: Alpaca, for the brokerage
account it displays, and the trading bot’s own status service at
stocks.infutures.xyz, for the log of what the bot did. Nothing else.
One thing does leave your phone and get stored: if you switch the daily recap on, the service is given the notification token Apple issues for this app on this device, because that is the only way a notification can be addressed. That is the whole of it, and it is covered below.
Your Alpaca credentials
Futures shows you a brokerage account you already have at Alpaca. To do that it needs an Alpaca API key pair, which you paste in yourself.
That key pair is stored in the iOS Keychain on your device, protected so it is only readable after you have unlocked the phone, and it is never synced to another device or backed up off it. It is sent to Alpaca’s API and to nowhere else. We never receive it, never see it, and have no server that could.
Signing out deletes it. Deleting the app deletes it.
The bot’s log
The app can also show what the trading bot itself did — the checks it ran, the
orders it placed, the reasons it gave. That comes from the bot’s own status
service at stocks.infutures.xyz, and it is optional: the app works without it
and simply does not show those panels.
Connecting it means pasting a read-only access token you generate on that service. Like the Alpaca key pair, it is stored in the iOS Keychain on your device, sent only to that service, and deleted when you sign out or delete the app. The token cannot write anything: it reaches the read endpoints and nothing else.
The requests carry the token and nothing about you.
What the app sends, and where
Requests go to Alpaca:
api.alpaca.marketsorpaper-api.alpaca.markets— your account, positions, order history and portfolio history, depending on whether your key is for a live or a paper accountdata.alpaca.markets— market prices for the symbols your account holds and for the two index benchmarks the app charts against
…and, if you have connected the log, to stocks.infutures.xyz for the bot’s
sessions, checks, orders and status.
Alpaca’s handling of that data is governed by your agreement with Alpaca, not by this policy.
There are no other network calls. No analytics service, no crash reporter, no advertising SDK, no content delivery network, no fonts fetched at runtime.
Notifications, and the one thing that is stored about your device
The daily recap is off until you switch it on, and it lives behind the log connection — without that, the app never offers it.
Switching it on does three things:
- iOS asks whether you will allow notifications. If you say no, nothing else happens.
- You sign in to the bot’s service with a passkey. The passkey stays on your device and in your iCloud Keychain; we never see it, and it is the only way the service will accept a write.
- The app sends the service the notification token Apple has issued for this app on this device, along with whether that token is for Apple’s production or sandbox push environment, and a label for the device. The label is what iOS gives apps for a device name — for an app like this one that is the model, “iPhone”, not the name you chose for your phone.
That token is a device identifier, it is stored against your account on the service so it knows where to send the recap, and it is declared as collected data in the app’s privacy manifest. It is used for one thing: delivering these notifications. It is not shared, not sold, and not used to track you across apps or websites.
The notification itself is sent through Apple’s Push Notification service, which is how every notification on iOS works. It carries counts — how many checks ran, how many trades were placed — and never a dollar figure.
Turning it off. Switch the recap off in Settings, or turn notifications off for Futures in iOS Settings, and the app stops registering. Deleting the app invalidates the token at Apple’s end, after which nothing can be delivered to it.
Reading only
Futures can only read. Its Alpaca client issues GET requests and has no code
path that places, modifies, or cancels an order, and an automated test enforces
that. Nothing you do in this app can move money or change a position.
What else is stored on your device
A few small preferences, held in the app’s own settings storage and never transmitted:
- your total deposits figure, if you enter one, so the all-time return can be worked out correctly
- whether you chose the light, dark, or system appearance
- whether you are currently in demo mode
- whether you switched the daily recap on, and — so the app doesn’t re-register the same device every launch — the last notification token it sent and when
Demo mode
The sign-in screen offers a demo. It opens the whole app on invented figures with no key pair, no network requests, and nothing stored beyond the flag saying you are in it. If you only ever use the demo, the app never contacts Alpaca at all.
Analytics and tracking
Futures contains no third-party analytics, advertising, or tracking software. We do not use the Advertising Identifier (IDFA) and we do not track you across apps or websites. The app’s privacy manifest declares no tracking domains and exactly one collected data type — the notification token described above, linked to you and used only to deliver the recap you asked for.
Children
Futures collects nothing about anyone as a person. It is a tool for viewing a brokerage account you already hold.
Not financial advice
Futures displays figures from your own account. It does not provide investment advice, recommendations, or projections, and the figures it shows are for information only. Alpaca’s own records are authoritative.
Contact
Questions about this policy? Email arrouse88@gmail.com.