Privacy
Last changed 16 August 2026.
What is stored
An e-mail address, a password hash, the name you type into settings if you type one, the risk answer if you give one, and everything the account does: deposits, orders, ledger lines, strategy allocations, saving plans and alerts. Server logs hold the address of the request, the path and the time.
How the password is stored
As a scrypt hash with a random salt. The password itself is never written anywhere and cannot be read back out of the hash.
Who else sees it
Nobody. The data is not sold, not shared with advertisers, and not passed to a third party. Outgoing requests go only to the data sources named on the pages: sec.gov, disclosures-clerk.house.gov and the price vendor. Those requests carry an instrument symbol and never anything about an account.
Cookies
One cookie, holding a signed session identifier, set when you sign in and removed when you sign out. There is no analytics script and no third-party tag on any page.
Removal
The settings screen closes the account and removes the address. Ask at support@multillm.online for a copy of what is held under an account, or for it to be deleted outright.