[ Legal ]
Privacy Policy
Minto exists to mirror one trading strategy into accounts you own. We collect the minimum needed to do that, and nothing we collect is ever sold.
Version 2026-07. Last updated July 2026.
Who we are
Minto is operated from Iceland. For anything in this policy, contact the operator at darrikonn@gmail.com.
What we collect
Account identity: your name and email address, handled by our authentication provider (Clerk) when you accept an invite.
Broker credentials: the Alpaca API keys and Polymarket wallet credentials you connect. They are stored encrypted on our servers and used for exactly one purpose: executing the mirrored strategy in your own accounts. We can trade with them; we cannot move money out of your accounts to anywhere else.
Trading data: positions, orders, balances, and history from your connected accounts, so the app can show you your own book and so guard rails can be enforced.
Device data: a push notification token if you enable notifications, and basic error diagnostics (via Sentry) when something breaks.
What we use it for
Operating the mirroring service, showing you your own data, sending you notifications you asked for, keeping the system healthy, and billing if you are on a paid plan (handled by Braintree; card numbers never touch our servers).
What we share
Only with the services that make Minto run: Clerk (authentication), Amazon Web Services (hosting, EU region), Sentry (error monitoring), Braintree (payments, when applicable), and the brokers you yourself connected. We do not sell data, run ads, or share your information for marketing.
Retention and deletion
We keep your data while your account is active. Broker connections can be removed in the app at any time, which revokes our access. You can delete your account and its data directly in the app settings, or by contacting the operator. Trade records that the law requires us to keep are retained for the mandated period, then deleted.
Your rights
Under the GDPR and Icelandic data protection law you can request access to, correction of, or deletion of your personal data, object to processing, and lodge a complaint with the Icelandic Data Protection Authority (Persónuvernd). Email the operator and it will be handled directly.
Changes
If this policy changes in a way that matters, you will be told in the app or by email before the change takes effect.