Privacy Policy
Last updated: September 5, 2026
Genobee ("we", "us") is operated by Genobee LLC, a California limited liability company. We run the Genobee application at genobee.ai and its companion iPhone app. This policy explains what we collect, how we use it, who we share it with, and the controls you have. We collect only what we need to run the product, and we never sell your data.
What we collect
- Account identity — your name and email address, provided when you sign in with Google or Discord. This is how we create and secure your Genobee account.
- Brokerage data — holdings, balances, and order activity from the brokerage accounts you choose to connect, accessed only through the connection you authorize.
- Security & device data — session and device metadata (e.g., approximate device fingerprint and sign-in events) used to protect your account and power new-device verification. On iOS this includes a push notification token if you enable notifications.
- What you ask the assistant — the questions you type and the portfolio context needed to answer them (for example, the positions a question is about). See "AI features" below.
- Product usage — events about which screens and features are used, so we can find what is broken or confusing. They record what you did rather than what you own: an order you place records its symbol, side, quantity, and order type, but your position sizes and brokerage balances are not sent. We store these events ourselves and never use them to track you across other apps or websites. On iPhone they are sampled: everything that failed is kept, and successful events are kept for one session in ten.
How we use it
- To display your unified portfolio and account activity.
- To place the trades and actions you initiate and approve in the app.
- To run the monitors you create and notify you when one needs your attention.
- To answer the questions you ask the assistant and to prepare event and market summaries for the symbols you hold.
- To secure your account — two-factor authentication, new-device challenges, and an auditable activity log.
How your brokerage connection is protected
- Connections are established through your broker's own authorization, or through our connectivity provider, SnapTrade, for brokers that do not offer direct authorization. Genobee never sees or stores your brokerage username or password.
- The credentials that let us read your accounts and place the orders you confirm are encrypted at rest with AES-256-GCM before they are written to our database, and are transmitted only over HTTPS. The encryption key is held in Google Cloud KMS and is never stored beside the data it protects.
- You can disconnect any linked brokerage at any time from Settings. We delete the stored credential, so Genobee can no longer reach that account; where the connection was made through SnapTrade, we also ask SnapTrade to remove it.
What is stored on your device
The iPhone app keeps four items in the iOS keychain: your Genobee sign-in token, its refresh token, a device cookie used for new-device verification, and an analytics device id. Your brokerage credentials are never stored on your device — they are held on our servers, encrypted as described above.
Who we share it with
We do not sell your personal or financial data, and we do not share it for advertising. We share data only with the providers below, and only to the extent needed to provide the service.
- SnapTrade — brokerage connectivity for most supported brokers. SnapTrade holds the connection to your broker and returns your holdings, balances, and orders to us. Their handling of your data is governed by SnapTrade's own privacy policy.
- Your broker — when you connect directly (for example Webull, Alpaca, or Schwab) or place an order, the broker receives the authorization and the order you confirmed.
- Google — Gemini models process the questions you ask the assistant, together with the portfolio context needed to answer them. The event and market summaries in Discover are generated one ticker at a time, from the ticker and the date alone: your holdings are never in that prompt, and they are used only on our own servers, to decide which summaries to show you. We never send your credentials.
- Google Cloud — hosting and encrypted storage.
- Apple — delivery of push notifications on iOS.
- Market data providers — receive the symbols you look up so we can show prices, never your identity or holdings.
AI features
The assistant and the event and market summaries are generated by AI models. They can be inaccurate or incomplete, and nothing they produce is placed in your account unless you review and confirm it yourself.
Your choices & rights
- Access and review your linked accounts, sessions, and activity log in-app.
- Disconnect any brokerage at any time.
- Turn push notifications off at any time, in the app or in iOS Settings.
- Delete your Genobee account — which removes your identity record and triggers deletion of the associated account data.
- California residents — you have the right to know what personal information we collect and how we use it, to correct or delete it, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined under California law. To exercise any right, email team@genobee.ai.
Children
Genobee is not directed to anyone under 18, and we do not knowingly collect personal information from anyone under 18.
Data retention
We retain account and connection data for as long as your account is active. When you disconnect a brokerage, we delete its stored credential.
When you delete your account we delete your identity, your linked-account records and your security activity log along with it. Before that, we revoke the external authorizations that can be revoked — your SnapTrade connections, and Alpaca's OAuth token. Some brokers publish no revocation endpoint; for those (Schwab and Webull today) the credential is deleted here and you remove Genobee's access in the broker's own portal. We record which ones were outstanding rather than assume they were revoked.
Security
We protect your data with encryption in transit and at rest, two-factor authentication, new-device verification, and an activity log you can review. If we learn of a breach that affects your data, we will notify you as required by law. To report a security issue, email team@genobee.ai.
Changes
We may update this policy as the product evolves. Material changes will be reflected here with a new "last updated" date.
Contact
Questions about Genobee or this policy? Email team@genobee.ai. Our Terms of Service are at genobee.ai/terms.