TICKERALL!
Legal

Privacy Policy

Last updated: June 9, 2026

1. Who we are

TickerAll is a hosted MetaTrader 4 & 5 broker API. We hold a connection to your broker on your behalf so your code — or an MCP client such as Claude — can read market data and manage your trading accounts over our API. This policy explains what we collect, how we use it, and the choices you have. Questions: hello@tickerall.com.

2. What we collect

  • Account details — your email and authentication (sign-in via Google or email/password through our authentication provider).
  • Broker connection credentials — the server name, login, and password you provide to connect a broker account. By default we do not store these: they are held in memory only while your connection is live, used solely to authenticate to your broker, and are never written to disk or saved to our database. The one exception is the opt-in remembered-credentials setting (see §3).
  • Trading & market data — balances, positions, orders, deal/order history, symbols, and candles, accessed live from your broker to serve your API and MCP requests.
  • Billing information — handled by our payment processor (Stripe). We do not store your full card number.
  • Usage & diagnostics — API request metadata, connection health, and system logs we use to operate, secure, and improve the service.

3. Your broker password is held in memory only (unless you opt in to remembered credentials)

This is core to how TickerAll works: you send your broker password once when you connect an account. We use it to authenticate, then hold it in memory only while your connection is live — it is never written to disk and never stored in our database. Disconnect the account (or close the session) and it is gone. To reconnect later you provide it again.

The one exception — remembered credentials (Pro and Enterprise, opt-in). Some customers cannot keep their users' broker credentials on their own side and still need accounts restored after a maintenance restart. If you switch this setting on, we record your consent and store the password encrypted at rest in our credential vault, used solely to restore the connections you asked for; it is never logged or shown back to you. Switch it off and every stored password is deleted immediately. It is off by default.

4. How we use your data

To provide the service (maintain your broker connections and serve your API/MCP requests), process billing, provide support, secure the platform against abuse, and improve the product. We do not sell or rent your personal information or your trading data.

5. Connecting through Claude / MCP

When you connect TickerAll to Claude (or another MCP client), each request is authenticated with your own MCP key and scoped to your account only — the connector can reach only the broker accounts in your own pool. You can revoke an MCP key at any time from your dashboard. Your conversations with Claude are governed by Anthropic's own privacy terms; TickerAll receives only the tool calls Claude makes against your account.

6. Who we share with

Service providers that help us run TickerAll — our payment processor (Stripe), our authentication provider, and our hosting/infrastructure providers — process data on our behalf under their own terms. We may disclose information if required by law. We never sell your data.

Visitor country is looked up on our own servers from a local copy of the IP Geolocation by DB-IP database, so your IP address is not sent to a third party for it.

7. Retention

We keep account and billing records while your account is active and as needed to meet legal and accounting obligations. Trading and market data is retained to provide history and analytics features. Broker passwords are kept only in memory during a live connection, unless you have opted in to remembered credentials (see §3), in which case they are kept encrypted until you switch the setting off. You can ask us to delete your account and associated data at any time.

8. Security

All traffic is encrypted in transit (HTTPS/TLS). Access is least-privilege, broker passwords are never persisted unless you opt in to remembered credentials (and then only encrypted at rest, see §3), and MCP/API access is scoped per user. No system is perfectly secure, but we take protecting your credentials and data seriously.

9. Your choices

You can disconnect any broker account at any time, revoke API or MCP keys from your dashboard, and request access to or deletion of your personal data by emailing hello@tickerall.com. Depending on where you live, you may have additional rights under local data-protection law.

10. Changes to this policy

We may update this policy as the product evolves. We will revise the “last updated” date above, and material changes will be communicated through the service.

11. Contact

Questions about privacy or your data? Email hello@tickerall.com.

Privacy Policy · Ticker All!