Foundry

1. Who we are

Foundry is a service operated by Monkey Jockey, LLC ("Monkey Jockey," "we," "us," or "our"). It provides software that displays your brokerage account information in one place. This policy explains what we collect, why, who we share it with, and how you get rid of it. It applies to our website and application.

2. What we collect

Information you give us.

  • Account details: name, email address, and password hash.
  • Billing information, if you subscribe to a paid plan. Payment card numbers are handled by our payment processor and never reach our servers.
  • Anything you write to us in a support or privacy request.

Brokerage account information, accessed read-only through SnapTrade. When you connect a brokerage account, we receive:

  • Account balances and total account value
  • Positions and holdings, including securities, quantities, and cost basis
  • Transaction history, including trades, dividends, deposits, and withdrawals
  • Account identifiers and metadata, such as account type, nickname, currency, and the institution's name

Information collected automatically.

  • Usage and device data: pages viewed, features used, browser type, approximate location derived from IP address, and timestamps.
  • Security logs: IP addresses and authentication events, kept to detect and investigate abuse.

3. Read-only access — Foundry cannot trade

Foundry requests read-only access to your brokerage accounts. We can retrieve balances, positions, and transaction history. We cannot place, modify, or cancel an order, execute a trade, transfer funds, withdraw assets, or change any setting at your broker. Foundry does not offer trade execution and does not act on your behalf in any market.

If we ever introduce a feature that could act on an account, it would require your separate, explicit authorization, and we would update this policy and notify you before it took effect.

4. Credentials and access tokens

We never receive, store, or transmit your brokerage username or password. You authenticate directly with your financial institution through SnapTrade. Your broker then issues a revocable, read-only access token to us. We never see the credentials you typed.

Access tokens are encrypted at rest using industry-standard encryption with keys held in a managed key management service, and encrypted in transit using TLS 1.2 or higher. Tokens are scoped to read-only permissions, are never stored in plain text, are never logged, and are never shared with any third party outside the processors listed in section 7.

Your Foundry password is stored only as a salted cryptographic hash. We cannot read it.

5. How we use data

We use the information described above to:

  • Show you your accounts, balances, positions, and transaction history
  • Produce the summaries, groupings, and performance views you ask for
  • Authenticate you and keep your account secure
  • Bill you, if you are on a paid plan
  • Answer your support and privacy requests
  • Diagnose faults, prevent abuse, and meet our legal obligations

Where the GDPR applies, we rely on the performance of our contract with you for delivering the service, our legitimate interests for security and fault diagnosis, and your consent where the law requires it.

6. We do not sell your data

We do not sell, rent, lease, trade, or otherwise monetize your personal information or your brokerage account data. We do not share it with advertisers, data brokers, marketing networks, or analytics partners for their own purposes. We do not use it to build or enrich profiles for anyone else, and we do not disclose it for cross-context behavioral advertising.

We have not sold or shared personal information in the preceding twelve months, as those terms are defined by the California Consumer Privacy Act.

7. Who we share with

We share data only with service providers who process it on our instructions, under contract, and only as needed to run Foundry:

  • Passiv Inc. (SnapTrade) — brokerage data aggregation and connectivity. SnapTrade brokers the connection to your financial institution and passes account data to us. Its handling of your data is also governed by its own privacy policy.
  • Cloud hosting and infrastructure providers — storage, compute, and content delivery for the application.
  • Payment processor — subscription billing for paid plans.
  • Error monitoring and product analytics — diagnostics and usage measurement. These receive usage and device data. They do not receive brokerage account data.

We may also disclose information if we are legally required to, or to protect our rights, safety, or property, or those of our users. If Foundry is involved in a merger, acquisition, or sale of assets, we will notify you before your information becomes subject to a different privacy policy.

8. How we protect it

  • Encryption in transit using TLS 1.2 or higher
  • Encryption at rest for stored account data and access tokens, with keys managed in a key management service
  • Access restricted to personnel who need it, with multi-factor authentication required
  • Audit logging of access to production systems

No system is perfectly secure, and we do not claim otherwise. If a breach affects your personal information, we will notify you and any regulator we are required to notify, within the time limits the law sets.

9. Disconnecting and revoking access

You are in control of every connection, and you can end one at any time. There are two routes, and either one works on its own:

  • In Foundry. Go to Settings → Connections, choose the account, and select Disconnect. This deletes the access token immediately and stops all further access.
  • At your broker. Open your institution's security, privacy, or connected-applications settings and revoke Foundry's access. This ends our access immediately, regardless of anything on our side.

Disconnecting removes the token and stops new data from arriving. To also delete the account data we already hold, email privacy@monkey-jockey.com. We will delete it within 30 days and confirm when it is done. You can delete your entire Foundry account from Settings → Account, which removes all connections and all associated data.

10. Retention and deletion

  • Brokerage account data is kept while the connection is active, and deleted within 30 days of the connection being removed.
  • Account and profile data is kept while your account exists, and deleted within 30 days of account closure.
  • Security and audit logs are kept for up to 12 months for abuse detection.
  • Billing records are kept for as long as tax and accounting law requires, typically seven years.

11. Your rights

Wherever you live, you can ask us to:

  • Tell you what personal information we hold about you
  • Give you a copy in a portable format
  • Correct anything inaccurate
  • Delete it
  • Restrict or object to a particular use
  • Withdraw a consent you previously gave

If you are in California, you also have the right not to be discriminated against for exercising these rights. Since we do not sell or share personal information, there is nothing to opt out of, but you may still make any of the requests above. If you are in the EEA or UK, you have the right to complain to your data protection authority.

Email privacy@monkey-jockey.com. We acknowledge requests within 10 days and resolve them within 30. We may need to verify your identity first, and we do not charge for this.

12. International transfers

We and our service providers may process your information in countries other than your own, including the United States. Where we transfer personal information out of the EEA or UK, we rely on Standard Contractual Clauses or another lawful transfer mechanism.

13. Children

Foundry is not directed to anyone under 18, and we do not knowingly collect information from them. If we learn we have, we delete it. If you believe a child has given us information, write to privacy@monkey-jockey.com.

14. Changes to this policy

If we change this policy we will update the date at the top. For changes that materially affect how we handle your data — a new category collected, a new purpose, a new recipient — we will notify you by email or in the application before the change takes effect.

15. Contact

Privacy and data requests: privacy@monkey-jockey.com
General support: support@monkey-jockey.com
Security reports: security@monkey-jockey.com