Skip to content

Privacy Policy

Last Updated: October 7, 2026

This Privacy Policy explains what personal data Stock Locker LLC ("Stock Locker", "we", "us"), collects when you use stocklocker.com and its APIs (the "Services"), why we collect it, who we share it with, and what you can ask us to do with it.

It describes the system as it is actually built. Where a piece of data cannot be deleted — because it sits on a public blockchain, or because publishing it is the entire point of the product — this policy says so plainly rather than implying otherwise.

If you do not agree with this policy, please do not use the Services.

1. Who is responsible for your data

Stock Locker LLC, 8 The Green, Suite B, Dover, DE 19901, USA, is the controller of the personal data described in this policy. You can reach us at support@stocklocker.com.

We operate from the United States. If you use the Services from elsewhere, your data is transferred to and processed in the United States and in the regions our providers operate, which may not offer the same protections as your home jurisdiction.

2. Data you give us

2.1 Account details. Authentication is handled by Clerk, Inc. When you create an account we receive an account identifier, your email address, your username or display name, and — if you sign in with a third-party provider such as X, Google or TikTok — the profile name and picture that provider returns. We never receive or store your password. If you sign in using an Apple private relay address, that relay address is all we ever see.

2.2 Profile details. Anything you enter on your profile: handle, display name, biography, avatar image, social links, the prices you set for early access to your calls, and the standing text shown on calls you post without a title or details of their own.

2.3 Calls. For each call you post we store its title and content, any images you attach, an optional public preview you write yourself, a SHA-256 hash of what was sealed, the time you posted it, and the time it is due to unlock, which equals the posting time if you post the call open. Where applicable we also store the time you chose to reveal it early or to feature it on your profile, and any notes you add to your own call afterwards. Like the call itself, a note cannot be edited or deleted once posted.

2.4 Connected accounts. When you connect an exchange or broker we store the read-only API key, secret, passphrase or report token you supply, encrypted with AES-256-GCM before it reaches the database; the key that decrypts them is held only in our hosting environment. When you connect a wallet we store its public address, after checking a signature that proves you control it; the signature authorises nothing and is not kept. Using those, we read and store your balances and positions, the value of each connection at each reading, and your trade history (instrument, side, quantity, price, fee and time of each trade, as the venue reports them; for a wallet, the swaps we identify in its public transactions over the past year). Disconnecting deletes the stored credential and the balance readings; the trades already imported stay on your profile's record, so a track record cannot be reset by disconnecting and reconnecting.

2.4a Residency check for some venues. Venues that do not serve the United States, such as Binance's global exchange, are not connected for US residents. When you connect one, we record the time you confirmed you are not a US resident, and we look up the country of the IP address your request came from in DB-IP's IP to Country Lite database (https://db-ip.com), which we keep on our own servers. The address is looked up and discarded; it is not stored and not sent to anyone.

2.4c Sanctions checks. On every visit we look up the country of your IP address in a local copy of DB-IP's free database, without sending it anywhere, and turn visits from restricted regions away (Terms 2.4); the address is not stored for this. Wallet addresses are screened against sanctions lists by TRM Labs, as listed in Section 6. Where a wallet is refused, we keep a log entry that a refusal happened, without the address.

2.4b Venues read from outside the United States. Binance's global exchange does not accept requests from where our main servers run, so we read it through a separate server we operate in the United Kingdom. Your Binance API key is stored encrypted with your other connections and is decrypted only on that server, which uses it to read your balances and trade history and to check, with Binance, that the key cannot trade, withdraw or transfer funds. What it reads is stored and shown like any other connection. Disconnecting deletes the key and the balance readings; imported trades stay on the record, as in 2.4.

2.4a Contact number. If you choose to add a phone number to your profile, we store it in international format. It is optional, it is never shown on your public profile or returned by any public query, and we use it only to contact you about your account. Remove it at any time by clearing the field.

2.5 Payment details. The only thing paid for on Stock Locker is a membership to a trader's calls, paid in USDC on the Solana blockchain; we store the payment reference, the amount, the term bought, whether the member signed up through that trader's own referral link, how the payment was divided, and the wallet each share was paid to. If you set a payout wallet, we store its public address. Plans bought before plans were retired are kept on the same basis. We do not take card payments and never see a card number. If you withdraw a balance, we store the amount.

2.6 Social accounts you verify. Where the Services offer it, verifying a YouTube or TikTok following is optional. You sign in with that account through Clerk and grant read-only access. From Google we request the youtube.readonly permission and use it only to read your channel's identifier, its handle or title, and its subscriber count. From TikTok we request user.info.basic, user.info.profile and user.info.stats and read only your account identifier, username, display name and follower count. We store the platform, the account identifier, the handle, the count and when it was read, and we refresh them only when you ask us to. We never read your videos, comments, messages, watch history or anything else, we never post or act on your behalf, and the access token itself is held by Clerk rather than stored in our database. You can withdraw that access at any time from your Google Account's third-party connections or your TikTok settings, and ask us to delete the stored verification.

2.7 Newsletter. If you sign up for the newsletter, with or without an account, we store your email address and when you signed up. We use it only to send the newsletter, and remove it when you ask us to at support@stocklocker.com.

Stock Locker's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Information received from Google or TikTok is used only to show and check the following you verified; it is not sold, used for advertising, or shared with anyone except the providers in section 6 that run the Services.

3. Data we generate or receive about you

  • Figures we compute from your connected accounts: portfolio value and its mix, its history over time, and realised profit and loss worked out from your imported trades.
  • Whether you have opted in to the leaderboard, and when.
  • Relationships you create in the product, such as which traders you follow (and which of their posts you asked to be emailed about), which you have paid for early access to, and who referred you.
  • Membership and balance records: what you bought, when it started and expires, and what has been credited to or withdrawn from your balance.
  • Server logs, written as one structured record per request: a request identifier, the HTTP method, the path, a timestamp, and the IP address the request arrived from. Values that look like credentials are redacted before a log line is written.

We do not buy personal data about you from data brokers, and we do not build advertising profiles.

4. Why we use it, and on what legal basis

  • To provide the Services you asked for — reading the accounts you connect, computing and showing your portfolio figures, posting and sealing calls, unlocking them on schedule, and showing your profile. Basis: performance of a contract with you.
  • To take payments, divide them between trader, referrer and Stock Locker, credit and pay out balances, and keep the records that tax and accounting rules require. Basis: performance of a contract, and legal obligation.
  • To keep the Services working and safe: rate limiting by IP address, refusing state-changing requests that do not originate from our own site, and investigating abuse. Basis: our legitimate interest in a service that is not trivially abused.
  • To send you service email, such as a reminder one week before a subscription expires. Basis: legitimate interest, and your consent where the law requires it.
  • To meet legal obligations and to establish, exercise or defend legal claims. Basis: legal obligation and legitimate interest.

5. What becomes public, and what stays private

5.1 Deliberately public. Your profile becomes public once at least one connected account has been read, and anyone with its address can then see it; a profile that has not connected anything is not public, unless a plan bought before plans were retired is still running. Being public is not being on the leaderboard: you are listed there only if you opt in and your verified portfolio is worth at least $50,000. On a public profile your handle, display name, biography, avatar, social links and prices are public, and so are your portfolio's total value, its mix by asset class, how that value has changed over time, the names of the venues you have connected, and your realised profit and loss. So are the title of a sealed call, the time it was sealed and its unlock time, from the moment you post it — being able to see those is what makes the seal mean anything.

5.2 Withheld until unlock. The content of a sealed call is withheld from every public read until it unlocks, except from members who have bought early access. This is enforced in the database itself: the public database roles are not granted permission to read that column at all, rather than merely being filtered out in application code.

5.3 Public once unlocked. When a call reaches its unlock time — or when you choose to reveal it early — its content becomes readable by anyone, permanently. That is the purpose of the product. Once public, it may be copied, quoted, cached or indexed by others, and we cannot retrieve those copies.

5.4 Never public. Your email address, your phone number, your API keys and tokens, and your wallet addresses are not shown on your public profile. The content of a call you have sealed and any notes on it are readable only by you and your paying members until the call unlocks.

6. Who we share it with

We do not sell your personal data. We share it only with providers who process it on our behalf, under contract, in order to run the Services:

  • Clerk — authentication, accounts and sessions.
  • Supabase — the database and file storage holding profiles, calls, images, connection data and payment records.
  • Hostinger — hosting for the application itself.
  • Resend — email we send, such as a reply to a message you send us through the contact form.
  • The exchanges and brokers you connect (Coinbase, Gemini, Crypto.com, OKX, Bitstamp, Bybit, KuCoin, Kraken, Robinhood, Interactive Brokers) — we call them with the credential you supplied to read your balances and trade history. They already hold that data; we send nothing else.
  • WalletConnect (Reown) — only if you connect a wallet from a phone: the connection between this site and your wallet app passes through WalletConnect's relay, which sees your wallet address and your IP address. We close the connection once the wallet has signed, and we have switched its analytics off.
  • Blockchain networks (Solana; Ethereum, Base, Arbitrum, Optimism and Polygon) — we query public nodes for the balances and transactions of the wallet addresses you connected, and the Solana network for payments.
  • Alchemy — for an EVM wallet you connected, we send its public address to read the token transfers in its transactions, from which we identify swaps. We send no other personal data.
  • TRM Labs — when you connect a wallet, set your payout wallet or make a payment, we send the public addresses involved to check them against sanctions lists (Terms 2.4). We send no other personal data.
  • Jupiter — when you pay in SOL or USDT, we ask it for the current price of the dollar amount in that coin. We send no personal data.
  • Jupiter — to name tokens in a Solana wallet's swaps, we look up token mint addresses in Jupiter's public token list. We send no personal data in that request.
  • Coinbase public exchange rates — we fetch dollar rates for pricing assets. We send no personal data in that request.
  • Google (YouTube Data API) and TikTok — only if you verify a social following: we ask the platform for your follower count using the read-only access you granted.

We may also disclose data where we are legally required to, or where it is necessary to protect our rights, our users, or the public. If Stock Locker is acquired, data may transfer with the business; we would tell you before your data became subject to a different policy.

7. Blockchain payments cannot be undone

USDC payments and withdrawals happen on the Solana blockchain. The wallet addresses, amounts and timestamps recorded there are public, permanent, and outside our control. We cannot edit, hide or delete them, and neither can you. A wallet address can often be linked to a person by anyone inspecting the chain. Consider that before paying from, or withdrawing to, an address you would rather not have associated with this account.

8. How long we keep it

  • Account and profile data: for as long as your account exists.
  • Calls: for as long as your account exists. Note that unlocked calls are already public — see section 5.3.
  • Connected-account credentials and balance readings: until you disconnect that account or delete your own account, whichever comes first.
  • Imported trade history: for as long as the profile's record exists, which includes after deletion (section 11).
  • Images attached to a call: for as long as the call exists.
  • Payment, membership and withdrawal records: kept after account deletion where tax, accounting or anti-fraud rules require it, typically for seven years.
  • Server logs: retained for a short period for security and debugging, then discarded.
  • Error records: where a request fails, we store what went wrong — the event, the reason, and identifiers such as the account or record involved — so the fault can be found and fixed. Values that look like credentials are replaced before the record is written. These are deleted automatically thirty days after they are made.

9. Security

All traffic is served over HTTPS. Access to sealed content is restricted at the database level rather than only in application code: the public database roles are not granted permission to read it. Exchange and broker credentials are encrypted at rest with AES-256-GCM and are never sent back to your browser. Images and charts attached to calls are held in private storage and reached only through signed links that expire within an hour, issued alongside a call the viewer is allowed to read. State-changing API requests must originate from stocklocker.com, and are rate limited per IP address.

No system is perfectly secure, and we do not claim otherwise. If we discover a breach affecting your personal data, we will notify you and the relevant regulator where the law requires it.

10. Your rights

Depending on where you live — in particular under the UK and EU GDPR, and under California law — you may have the right to:

  • Ask what personal data we hold about you, and receive a copy of it.
  • Correct data that is wrong or incomplete. Most of it you can edit yourself on your profile.
  • Delete your account and the personal data attached to it, subject to the limits in sections 5.3, 7 and 8.
  • Object to, or ask us to restrict, processing we base on our legitimate interests.
  • Withdraw consent where we relied on it, without affecting what we did before you withdrew it.
  • Complain to your data protection authority. In the UK that is the Information Commissioner's Office.

Write to support@stocklocker.com and we will respond within the period the applicable law sets, normally one month. We will not discriminate against you for exercising any of these rights. We do not sell or share personal data as those terms are defined under California law, so there is no such opt-out for you to exercise.

11. Deleting your account

You can delete your account from the Security page, or ask us at support@stocklocker.com. Deletion removes what identifies you: your handle, name, biography, images, phone number, social links, connected-account credentials, follows, notifications and social verifications. Your sealed calls, the trades imported from your accounts, the memberships you bought and your payment records stay, under a profile marked as deleted that carries no name, is listed nowhere and opens only for members who paid for its calls, so that they keep what they paid for and a track record cannot be erased and started again. The wallet addresses and exchange accounts you had connected stay on that record too, so they cannot be verified on a new profile.

Two things survive deletion, and we would rather be clear now than surprise you later. Content from calls that had already unlocked may persist in copies, caches and search indexes we do not control. Blockchain transactions remain on the public ledger permanently. We also keep the financial records described in section 8 for as long as the law requires.

12. Cookies and local storage

We use cookies set by Clerk to keep you signed in and to tell the server which account a request belongs to. These are strictly necessary: without them you cannot stay signed in. We also keep one short-lived note in your browser's local storage when you open a trader from the leaderboard, described in section 3.

If you arrive through another trader's referral link, we set one further cookie holding only that link's referral code, for thirty days. It is read once, when an account is created, to record who referred it, and it is not used to track you anywhere else. Following a referral link without creating an account leaves the cookie unused, and clearing your cookies removes it.

We do not use advertising cookies, and we do not run third-party tracking or analytics that profile you across other websites.

The Cookie Policy names each cookie individually: what it holds, how long it lasts, and how to remove it.

13. Children

The Services are not intended for anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.

14. Changes to this policy

We may update this policy as the product changes. The "Last Updated" date above always reflects the current version. If a change materially affects how we use your data, we will tell you through the Services or by email before it takes effect.

15. Contact

For any question about this policy, or to exercise any of the rights in section 10:

Stock Locker LLC

Attn: Privacy

Email: support@stocklocker.com

Address: 8 The Green, Suite B, Dover, DE 19901