IndexAlpha treats your data with the same care as a bank. We use bank-grade encryption in transit and at rest, host on Google Cloud infrastructure, never sell data to third parties, and let you permanently delete your account anytime.
account security is the set of technical and operational safeguards that protect your data on a service. On IndexAlpha, account security covers four areas: encryption (in transit and at rest), authentication (how you log in), data minimization (we only collect what is needed), and deletion (your right to remove your data at any time). These align with US government guidance on financial data protection — see the FDIC for how brokerages and banks differ on protection, and the CFPB on consumer financial data rights.
All traffic between your browser and IndexAlpha is encrypted with TLS 1.3. All data stored in our databases is encrypted at rest with AES-256. If someone intercepted the network traffic, they would see only ciphertext. If someone got physical access to a drive, they would still need a key they cannot obtain.
Accounts are secured with email and password, plus optional multi-factor authentication (SMS or authenticator app). We use industry-standard password hashing (bcrypt) — even IndexAlpha cannot read your password.
We collect only what is needed to run the service: email, your saved portfolios and watchlists, and anonymized usage analytics. No Social Security number, no bank credentials, no government IDs.
On Google Cloud infrastructure in the US. Google Cloud is SOC 2 Type II certified and meets ISO 27001 requirements.
No — and it should not be. IndexAlpha is a research tool, not a bank or brokerage. We do not hold your money. Your actual investments sit at your brokerage, which is typically SIPC-insured. See the FDIC for the distinction between bank and brokerage protection.
Everything — portfolios, watchlists, email, usage history — is permanently deleted within 30 days. We also keep an audit log of the deletion (timestamp only, no personal data) for legal compliance.
Only if you email us with a support question and voluntarily share it. Automated systems access portfolio data to run calculations; no human reads individual portfolios.
We would notify affected users within 72 hours — faster than required by most US state laws — with a clear description of what happened, what data was affected, and what we are doing about it. No incidents have occurred to date.
Yes. EU users have full access, correction, and deletion rights under GDPR. Email hello@indexalpha.ai to exercise any of those rights.
Commercial financial tools often sell user data or run advertising that reads your inputs — IndexAlpha does neither. The closest comparison is a government-run tool like the SEC's Compound Interest Calculator, which is free and ad-free because it is a public service. IndexAlpha is privately funded, but operates under the same principle: your data is your data.
Beginners: If you worry about giving a website information about your money, read this page. IndexAlpha asks for less information than most sites — we do not need your Social Security number, your bank account, or your brokerage password.
Intermediate investors: If you manage significant personal investments, the lack of brokerage-credential requirement means IndexAlpha cannot be a vector for account takeover on your brokerage. Combined with optional MFA, this makes it a low-risk research tool to add to your workflow.