HarvestEngine connects to your broker so you can run direct indexing and tax-loss harvesting on accounts you control. That requires reading your positions, lots, and trade history. It does not require sharing any of that for advertising, and we never do.
Version 2.1 · Effective 2026-09-17 · Replaces version 2.0 (2026-08-15)
HarvestEngine is software for self-directed investors. We collect the data we need to run the service and secure your account, we encrypt sensitive data, and we do not sell your personal information. We do not use third-party advertising trackers, Google Analytics, or the Meta pixel.
Rev. 2026-08 · FACTS: What does HarvestEngine do with your personal financial information?
Why we give you this notice. Financial companies choose how they share your personal information. Federal law gives consumers the right to limit some but not all sharing, and requires us to tell you how we collect, share, and protect your personal information. Please read this notice carefully. HarvestEngine (Aubrey Holdings, LLC) is a financial institution under the Gramm-Leach-Bliley Act, 15 U.S.C. §§ 6801–6809, and this section is our privacy notice under 12 C.F.R. Part 1016 (Regulation P).
What we collect. The types of nonpublic personal information we collect depend on the product or service you have with us. They include: information you give us (name, email, phone number, sign-in method, tax settings, filing status, state of residence, and the questions you type into our AI assistant); information about your transactions and account holdings that we receive from the brokerage you connect (holdings, individual tax lots, cost basis, transactions, balances, and order fills); information about your use of our service (product-analytics events, algorithm audit logs, IP address, device and browser information, and session and trusted-device identifiers); and payment information (email, name, and an internal account identifier passed to our payment processor). We do not collect your brokerage password, your bank account or routing numbers, your Social Security number, or any government-issued identification number.
What we disclose, and to whom. We disclose all of the categories of nonpublic personal information listed above, as needed, to nonaffiliated companies that perform services for us or functions on our behalf — our cloud host and database provider, our AI provider, our SMS provider, and our payment processor. We make these disclosures under the service-provider exception in 12 C.F.R. § 1016.13, and every such company is bound by a written contract that limits its use of the information to the purposes for which we disclose it. We also disclose information at your direction to the brokerage you choose to connect, and as otherwise permitted by law under 12 C.F.R. §§ 1016.14 and 1016.15 — including to respond to a subpoena, court order, or other legal process, to protect against fraud or unauthorized transactions, and to comply with federal, state, or local law.
What we do not do. We do not disclose your nonpublic personal information to nonaffiliated third parties for those parties' own marketing purposes, and we do not sell it. Because we share only in the ways described above and permitted by law, federal law does not give you a right to limit (opt out of) our sharing, and we do not offer an opt-out — there is nothing to opt out of.
Affiliates. Affiliates are companies related by common ownership or control. HarvestEngine has no affiliates and shares no information with affiliates for any purpose, including marketing. Because we share no creditworthiness or transaction information among affiliates, the affiliate opt-out under section 603(d)(2)(A)(iii) of the Fair Credit Reporting Act, 15 U.S.C. § 1681a(d)(2)(A)(iii), does not apply. Joint marketing is an arrangement between a nonaffiliated financial company and us to jointly market financial products or services to you. HarvestEngine does not jointly market.
Former customers. If you close your account, we continue to treat your nonpublic personal information as described in this notice for as long as we retain it, and we disclose it only as described above and as permitted by law. See How long we keep your data for our retention schedule.
How we protect your information. We maintain a written information security program with physical, electronic, and procedural safeguards designed to protect your nonpublic personal information, and we have designated a qualified individual responsible for it. See Security below.
Changes to this notice. We will not disclose your nonpublic personal information in a way that is inconsistent with this notice unless we first give you a revised notice and, where federal law requires it, a reasonable opportunity to opt out. Questions: privacy@harvestengine.ai, or Aubrey Holdings, LLC, Attn: Privacy Officer, 1401 21st Street STE R, Sacramento, CA 95811.
OAuth tokens issued by your broker are encrypted at rest using envelope encryption with Google Cloud KMS. The data-encryption key that protects each token is itself encrypted by a key-encryption key that is generated, stored, and used only inside Google Cloud KMS; HarvestEngine never holds the key-encryption key in plaintext and cannot export it. Each encrypted token is bound to your account's UUID as additional authenticated data, so a token cannot be decrypted in the context of any other user — a stolen ciphertext is useless without both the KMS key and the correct account context.
Tokens have hard expiry windows (typically 14 days for E*TRADE) and 2-hour inactivity timers. If you stop using HarvestEngine, the token expires automatically. You can also revoke access at any time from your broker's app-permissions panel.
When you use Shayne, our AI assistant, or AI-generated rankings, briefings, and rationales, the relevant portion of your portfolio context is sent to our AI provider, currently OpenAI, to generate the response. Depending on the feature, this can include security symbols and sectors, position sizes and dollar values, realized and unrealized gains and losses, and estimated tax figures. We do not attach your name, email address, phone number, government IDs, or broker credentials to these requests — your account is identified to us only, by an internal identifier. Anything you type into Shayne is sent exactly as you write it, so please don't type information into the chat that you don't want sent to our AI provider.
Our OpenAI organization is configured so that API inputs and outputs are not used by OpenAI to train
or improve its models. We set OpenAI's store=false parameter on production requests so
request and response content is not retained in OpenAI's dashboard or logs, and we have disabled
org-level API call logging. OpenAI still processes the data transiently to produce your response, and
under its standard API terms may retain limited copies for up to 30 days for abuse and misuse
monitoring, plus any records it must keep by law. We have not enabled OpenAI's Zero Data Retention
option, so we do not claim your data is never stored on OpenAI's systems.
How AI features work. HarvestEngine's core tax calculations — loss detection, wash-sale windows, holding periods, and tax math — run on deterministic logic that does not use AI. AI is used to rank replacement candidates, to summarize proposals, and to power the Shayne assistant. When an AI feature runs, the relevant portion of your portfolio context is sent to our AI provider as described above, under the no-training terms and abuse-monitoring-only retention set out there. These features are part of the product and are active for all accounts; we do not currently offer a per-user switch to turn them off. If you would prefer that your portfolio data not be processed by an AI provider, you can export or delete your data and close your account at any time (see How long we keep your data and Your privacy rights).
Two parts of HarvestEngine make decisions about your portfolio using software rather than a person, and you should know how they work.
The harvesting engine and the AI ranker. The engine screens your positions against rules you set (loss thresholds, wash-sale windows, restrictions, tax settings) and produces candidate trades. The AI ranker scores replacement candidates on factual attributes — sector, factor scores, beta, capitalization tier, yield, liquidity, and wash-safety. These produce candidates you review and approve. They are not investment advice and not a recommendation that any security is suitable for you.
Automation ("autonomy") rules. If you turn on automation, trades that meet the rules you configured can be approved and executed without a person reviewing them. That is a decision made exclusively by automated processing. We tell you every time it happens, at the time it happens, and we identify it as an automated decision.
Your rights around automated decisions. For any automated decision affecting you, you may ask us for: (a) the personal information we used to make it; (b) the principal factors and parameters that led to the outcome, in plain language; and (c) correction of any personal information used that is inaccurate or incomplete. You may also send us your observations and ask a member of our team with authority to review the decision to look at it. Email privacy@harvestengine.ai. You can turn automation off at any time in Settings → Autonomy, and you can veto any pending automated trade before it executes.
The main limitation you should understand: the engine sees only the accounts you connect. It cannot see holdings in your other accounts, your IRAs, or your spouse's accounts, and those can affect wash-sale outcomes.
HarvestEngine sends only transactional SMS. Requested one-time codes, including two-factor verification codes, are not part of the optional recurring text program and are sent because you requested them. The optional recurring text program has four categories: trade-approval links, account-security alerts, post-execution trade summaries, and replies when you text us. Passwordless sign-in by text is disabled. No marketing or promotional texts.
We do not sell your personal information, and we never share it with any third party for that third party's own marketing, advertising, or other independent purposes. The only outside parties that receive your data are the service providers listed below. Each is bound by contract to process it solely on our behalf, to operate the product, and may not use it for its own purposes:
None of these providers may sell your information or use it for their own marketing. In particular, your mobile phone number and your SMS opt-in and consent are never shared with any third party or affiliate for marketing or promotional purposes; your number is shared only with Twilio, strictly to deliver the messages you asked to receive.
All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
Your broker. When you connect a brokerage account, we send read requests and — only when you approve a trade, or under automation rules you enabled — orders to your broker on your instruction. Your broker is not our service provider; it is a regulated financial institution you have your own relationship and agreement with, and its handling of your information is governed by its privacy notice, not ours.
Legal process. We may disclose information to a government authority or in litigation when we are legally required to — a subpoena, court order, search warrant, or other valid legal process — or when we believe in good faith it is necessary to protect someone's safety or to investigate fraud or a security incident. Our practice is to require valid legal process, to disclose only what the process actually reaches, and to notify you before we produce anything — whenever we are legally permitted to do so and it is reasonably practicable, so you have a chance to object. We will not notify you where a court order, statute, or gag provision prohibits it, or where we reasonably believe notice would create a risk of harm to a person or would obstruct an investigation into conduct affecting your account. We will tell you after the fact once a prohibition lifts, where we are able to.
We do not sell your personal information, and we do not "share" it (as defined by California law) for cross-context behavioral advertising. If that ever changes, we will tell you before it does and give you a way to opt out. We may also disclose information in a merger or acquisition, with notice where required.
We keep each category of personal information only as long as we need it for the purpose we collected it, or as long as the law requires. Below is the retention period for each category, or the criteria we use where a fixed period isn't possible.
| Category | How long we keep it |
|---|---|
| Account identity (name, email, sign-in method) | For the life of your account, and until you close it or ask us to delete it — after which we remove your access and delete the data, except where a legal hold or a record-keeping obligation requires us to keep specific items longer. |
| Phone number and SMS consent record | For the life of your account. We keep the consent and opt-out record for at least 4 years after your last message — and may keep it longer — because federal telemarketing law lets a consumer bring a claim for up to four years and this record is our proof that you consented and that we honored opt-outs. |
| Holdings, tax lots, cost basis, transactions, balances | For the life of your account, and for a period afterward — up to about 7 years — so we can answer tax-record questions for the years you used HarvestEngine. You may ask us to delete it sooner (see Your privacy rights) and we will, except where a legal hold applies. |
| Brokerage OAuth tokens | Until the token expires (typically 14 days for E*TRADE), or immediately when you disconnect the broker or close your account — whichever is first. This is enforced by the token's own expiry, not a scheduled deletion job. |
| Algorithm audit logs and AI request metadata | Kept while your account is open and for a period afterward — up to about 7 years — so we can reconstruct what the engine did and why for any tax year you used it. Deleted on request except where a legal hold applies. |
| Product-analytics events | Kept only as long as we need them for product analytics, then deleted or aggregated so they can no longer be linked to you. |
| Device and security data (IP, device, session, trusted-device IDs) | Kept while relevant to sign-in security and fraud prevention; retained longer only for a specific record we are actively using to investigate suspected fraud or a security incident. |
| Support messages | Kept as long as we need them to support you and keep a record of the issue, then deleted when that need ends or on request. |
| Billing records | Kept for at least 7 years, because tax and accounting law requires it. Card data is held by Stripe under Stripe's retention schedule, not ours. |
Where a legal hold, a subpoena, an open dispute, or a tax or financial record-keeping obligation requires us to keep something longer, we keep only what that obligation covers, and we delete it when the obligation ends.
You can ask us to delete your data at any time — email privacy@harvestengine.ai, or start account deletion in your settings (Account → Delete account). Starting deletion immediately disables your account and stops further processing; we then remove your data and confirm in writing when that is complete, except for records a legal hold or a record-keeping obligation requires us to keep (see the table above).
Depending on where you live, you may have some or all of the following rights: to know and access the personal information we hold about you and how we use it; to receive a copy of it in a portable format; to delete it; to correct inaccuracies; to opt out of the sale of your personal information, of "sharing" for cross-context behavioral advertising, and of profiling in furtherance of decisions with legal or similarly significant effects; to limit our use of sensitive personal information; and to not be discriminated against for exercising any of them. We do not sell your personal information, we do not share it for cross-context behavioral advertising, and we do not use sensitive personal information for any purpose other than providing and securing the service you asked for, so there is nothing to opt out of or limit — but you may ask us to confirm that, and we will.
How to exercise them. Export your data as a ZIP file containing CSV and JSON files using the tool in your account settings, or email privacy@harvestengine.ai. HarvestEngine operates exclusively online and has a direct relationship with you, so email is our designated method for requests. We will verify your identity — usually by asking you to send the request from the email address on your account and to confirm details only you would know — and we will respond within 45 days, extending once by another 45 days if we need to, and telling you why. Authorized agents may submit requests on your behalf with written permission that we can verify.
If we say no. We will tell you why in writing. You may appeal by replying to our response with the word "APPEAL." We will decide the appeal and give you a written explanation within 60 days. If we deny your appeal, you may submit a complaint to your state Attorney General — for example, the Connecticut Attorney General at portal.ct.gov/ag, the Colorado Attorney General at coag.gov, the Virginia Attorney General at oag.state.va.us, or the California Privacy Protection Agency at cppa.ca.gov — and we will give you a direct link in our denial.
One important limit. Because HarvestEngine is a financial institution under the Gramm-Leach-Bliley Act, most of the financial information we hold about you is covered by that federal law and is exempt from some state privacy statutes. That exemption is about the information, not about us as a company. We honor access, correction, deletion, and portability requests for your data whether or not a particular state law compels us to, except where a legal hold, a tax or financial record-keeping obligation, or a fraud or security investigation requires us to keep something. If we hold something back, we tell you what and why.
We currently serve users in the United States and Canada. See Canada below for PIPEDA and Quebec Law 25 rights. If you are somewhere else, contact us and we will tell you what rights you have.
If you are in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) applies to how we handle your personal information, and in Quebec the Act respecting the protection of personal information in the private sector (Law 25) also applies.
Where your information is processed, and what that means. HarvestEngine is a United States company. Your personal information — including your holdings, tax lots, cost basis, transactions, and balances — is stored and processed in the United States on Google Cloud infrastructure, and, if you turn on AI features, portions of your portfolio context are sent to OpenAI in the United States. While your information is in the United States, it is subject to United States law and may be accessible to United States courts, law enforcement, and national security authorities under a lawful order, without notice to you and without the protections of Canadian law. We use contractual and technical measures to require a comparable level of protection from our service providers, but we cannot override a valid legal order in the country where the data is held. By using HarvestEngine, you consent to this transfer and processing.
Your consent. We ask for your express consent before we collect your brokerage data and before we turn on AI features, and we identify the purpose at or before the time we collect. We collect only what is necessary for the purposes we identify, and we do not use your information for a new purpose without asking you again. You may withdraw your consent at any time, subject to legal and contractual restrictions and reasonable notice — disconnect your broker, turn off AI features in Settings, or email us. Withdrawing consent for AI features does not affect your access to the rest of the service.
Your rights. You may ask us for access to the personal information we hold about you, for an account of how we have used it and to whom we have disclosed it, and for correction of anything inaccurate or incomplete. We will respond within 30 days, or tell you why we need an extension. We provide access free of charge for routine requests.
Accountability and complaints. Our Privacy Officer is accountable for our compliance with Canadian privacy law: Kyle Aubrey, Managing Member, Aubrey Holdings, LLC, privacy@harvestengine.ai, 1401 21st Street STE R, Sacramento, CA 95811. If you have a complaint about how we handle your personal information, write to the Privacy Officer and we will investigate and respond in writing. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada (1-800-282-1376, priv.gc.ca), or, in Quebec, to the Commission d'accès à l'information du Québec (cai.gouv.qc.ca).
Breach of security safeguards. If a breach of security safeguards involving your personal information creates a real risk of significant harm to you, we will report it to the Office of the Privacy Commissioner of Canada and notify you as soon as feasible, as PIPEDA section 10.1 requires. We keep a record of every security breach involving personal information for at least 24 months.
Quebec (Law 25). If you are in Quebec, you also have the right to data portability — to receive the computerized personal information you provided to us in a structured, commonly used technological format — and the rights described under Automated decisions above. Our Privacy Officer named above is the person in charge of the protection of personal information under Law 25. We conduct a privacy impact assessment before communicating personal information outside Quebec, as article 17 requires.
Because HarvestEngine handles nonpublic personal financial information, we maintain a written information security program under the FTC Safeguards Rule (16 C.F.R. Part 314). We have designated a qualified individual responsible for the program, we assess the risks to your information and the safeguards that control them, we train the people who handle it, we require our service providers by contract to protect it, and we review the program at least annually and whenever something material changes.
Technical safeguards include: envelope encryption for broker tokens using Google Cloud KMS; encryption of data in transit using TLS 1.2 or higher; encryption at rest for our databases and backups; multi-factor authentication for administrative access to systems that hold customer information; role-based access controls granted on a least-privilege basis; logging of privileged activity; per-account data isolation enforced at the database layer by PostgreSQL row-level security; and secure disposal of customer information when we no longer need it.
No system is perfectly secure, and we do not promise that ours is. If a security incident affects your personal information, we will notify you as required by applicable law — and, where the law does not require notice but we judge that you would want to know, we will tell you anyway. We will also report qualifying incidents to the Federal Trade Commission as required by 16 C.F.R. § 314.4(j), and to the Office of the Privacy Commissioner of Canada where Canadian law requires it.
We use only essential/functional cookies — for your session, your trusted-device preference, and sign-in-flow state. We do not use advertising or cross-site tracking cookies, Google Analytics, or the Meta pixel.
Do Not Track and Global Privacy Control. Some browsers send a "Do Not Track" (DNT) signal or a Global Privacy Control (GPC) signal to tell websites you don't want to be tracked across sites or to opt out of the sale or sharing of your personal information. HarvestEngine does not track you across other websites, does not sell or share your personal information for cross-context behavioral advertising, and allows no third party to collect personally identifiable information about you across sites through our service. There is therefore nothing for a DNT or GPC signal to turn off, and our behavior is the same whether or not your browser sends one: no cross-site tracking, no sale, no sharing. If that ever changes, we will update this notice before the change takes effect and we will honor GPC signals as an opt-out request as required by 11 C.C.R. § 7025.
HarvestEngine accounts are for adults. You must be at least 18 to create one. The service is not directed to children, we do not market it to children, and we do not knowingly allow anyone under 18 to create a HarvestEngine account or to provide us with personal information directly.
Custodial and minor's brokerage accounts. You may connect a custodial account (for example, an UTMA or UGMA account) if you are the adult custodian legally authorized to act for it. When you do, the financial information we receive about that account — holdings, tax lots, cost basis, transactions, and balances — relates to the minor beneficiary, and you provide it to us as the custodian, on the minor's behalf. We use it only to run the service on that account, we apply the same protections to it as to any other account data, and we never use it for marketing or profiling. The minor does not have a HarvestEngine account and we collect nothing from the minor directly.
If you believe a person under 18 has created an account or sent us personal information directly, email privacy@harvestengine.ai and we will delete it.
We may update this policy; for material changes we will email registered users and update the "Last updated" date. This Privacy Policy is the operative statement of how HarvestEngine handles your data. Enterprise customers who require a separate Data Processing Addendum may execute one with us; where signed, it supplements this policy for that customer. Questions: use the contact form and choose "Privacy & personal info", or email privacy@harvestengine.ai, or write to Aubrey Holdings, LLC, Attn: Privacy Officer, 1401 21st Street STE R, Sacramento, CA 95811.
Version 2.1, effective 2026-09-17. Prior versions: 2.0 (2026-08-15) and 1.0 (2026-08-05). Email privacy@harvestengine.ai for a copy of any prior version.
HarvestEngine.ai is a product of Aubrey Holdings, LLC, a California limited liability company (DBA registered in Santa Clara County, California).