MVP privacy notice
Privacy and credential handling
Last updated: July 17, 2026
Data we process
We process account identifiers, email, nickname, university membership, paper-portfolio balances and positions, performance metrics, league entries, and operational logs needed to run and secure the competition.
Alpaca credentials
Paper API credentials are sent over HTTPS to the backend, validated, encrypted before storage, and excluded from browser-readable database access and application logs. They are decrypted only in backend memory when a portfolio synchronization requires them.
Public information
Leaderboard snapshots may publicly display your nickname, university, permanent participant ID, rank, and approved performance metrics. If you create a participant profile, your chosen name, bio, and approved social links are shown only according to the visibility settings you control. Email addresses, credentials, and raw account responses are never public profile or leaderboard fields.
Retention and deletion
Disconnecting Alpaca deletes the stored encrypted credentials. You may request account deletion and correction of profile information. Backup copies may persist for a limited operational retention period.
Service providers
Supabase provides authentication and database services, Alpaca provides the connected paper account, and the selected hosting providers process data required to deliver the application.