Legal
Information Security Policy
Organization: AdSnap, LLC (operating as Coattail) · Owner: Jonathan Allen, Founder & CEO · Effective: June 2026 · Review Cadence: Annually
1. Purpose and Scope
This policy governs how Coattail protects production systems, user data, and third-party credentials. It applies to all infrastructure, code, and personnel (including contractors) involved in operating the Coattail mobile application and its backend services.
2. Access Control
The principle of least privilege is enforced at every layer:
- Database (Supabase): Row-Level Security (RLS) policies restrict each authenticated user to their own data. No query can return another user's records. Service role keys — used only by server-side functions — are never exposed to client applications.
- Brokerage data: Plaid and SnapTrade credentials are stored in server-side database tables with no client-readable policy. Edge Functions access them through service-role authorization only. Brokerage login credentials are handled by the connection provider and brokerage, not by Coattail.
- Infrastructure secrets: All API keys and service credentials are stored as encrypted GitHub Actions secrets or Supabase Edge Function secrets. No secrets are committed to source control.
.env.local is gitignored and excluded from all builds.
- Production access: Only the founder has access to production infrastructure (Supabase dashboard, Railway, GitHub repository). No shared credentials are used.
3. Data Classification and Handling
| Classification |
Description |
Examples |
Controls |
| Highly Sensitive |
Data whose exposure could cause financial or identity harm |
Plaid and SnapTrade credentials, portfolio holdings, brokerage account IDs, order records |
Service-role-only table; no client RLS; AES-256 at rest; TLS 1.2+ in transit |
| Sensitive |
Personal identifying information |
Email address, display name, profile photo, push notification token |
RLS-protected; stored in Supabase (encrypted at rest); never logged |
| Internal |
Operational and diagnostic data |
Usage analytics, crash reports, app logs |
Anonymized where possible; retained per vendor policy (Amplitude, Sentry) |
| Public |
Publicly available government and regulatory data |
Congressional STOCK Act trades, SEC filings, FDA decisions |
Sourced from public APIs; no special restriction; not PII |
Supabase enforces AES-256 encryption at rest and TLS 1.2+ for all data in transit. No sensitive data is stored in client-side storage (AsyncStorage holds only non-sensitive UI preferences).
4. Credential and Secret Management
- All credentials follow a named-secret pattern: stored in the platform's encrypted secret store (GitHub Actions Secrets, Supabase Secrets, Railway Environment Variables) — never hardcoded.
- Secrets are rotated immediately upon suspected compromise.
- Third-party credentials (SnapTrade, Plaid, RevenueCat, OpenAI, and market-data providers) are scoped to the minimum permissions required for each backend function.
- Plaid connections are read-only. SnapTrade connections may support order transmission after explicit user review and confirmation; Coattail does not execute, clear, settle, or custody trades.
5. Vulnerability and Patch Management
- Dependencies are reviewed via
npm audit before each production build.
- The Expo SDK and Supabase client are kept on current stable releases.
- Security advisories from Supabase, Expo, and Plaid are monitored and addressed within 14 days of a critical advisory.
6. Incident Response
In the event of a suspected breach or unauthorized access:
- Contain — Immediately rotate affected credentials via the relevant secret store dashboard.
- Assess — Determine scope of exposure using Supabase logs and Sentry crash reports.
- Notify — If user data is confirmed exposed, notify affected users within 72 hours via in-app message and email.
- Remediate — Patch the vulnerability before restoring affected services.
- Document — Record the incident, timeline, and remediation steps.
7. Third-Party Vendor Security
All third-party vendors handling user data are evaluated for SOC 2 compliance or equivalent before integration:
| Vendor |
Purpose |
Compliance |
| Supabase |
Database, authentication, storage, and Edge Functions |
SOC 2 Type II |
| Plaid |
Brokerage connectivity (read-only investments product) |
SOC 2 Type II, PCI DSS |
| SnapTrade |
Brokerage connectivity, portfolio data, and order transmission |
Reviewed through vendor security and contractual documentation |
| Railway |
Background job runner for daily data ingestion |
SOC 2 Type II |
| Sentry |
Crash reporting and error monitoring |
SOC 2 Type II |
| Expo (EAS) |
App build infrastructure and push notification delivery |
SOC 2 Type II |
8. Data Retention and Deletion Policy
Effective: June 2026 · Reviewed: Annually
8.1 What We Retain and For How Long
| Data Type |
Retention Period |
| Account credentials (Supabase Auth) |
Active until account deletion |
| Brokerage connection credentials (Plaid and SnapTrade) |
Active until user disconnects brokerage or deletes account |
| Synced portfolio holdings |
Active until user disconnects the linked account or deletes account |
| Morning brief history |
90 days rolling |
| Trade feed and investor data |
Indefinite (public disclosure data — not PII) |
| Push notification tokens |
Active until account deletion or token rotation |
| Analytics events (Amplitude) |
Per Amplitude's data retention policy (24 months) |
8.2 User-Initiated Deletion
Users may request full account deletion at any time by contacting [email protected] or via the in-app Settings screen. Upon verified request, we will:
- Revoke or delete all active Plaid and SnapTrade connections as part of the deletion workflow
- Delete account-scoped holdings, brief history, profile data, and authentication identity, subject to limited records retained for security, audit, dispute, or legal obligations
- Confirm deletion in writing to the requesting email address
8.3 Brokerage Disconnection
When a user disconnects a brokerage account, Coattail revokes or deletes the applicable provider connection and removes current synced account and holdings data from active use. Limited order, security, audit, or legal records may be retained where reasonably necessary.
9. Policy Review
- This policy is maintained in compliance with applicable U.S. data privacy laws including CCPA.
- This policy is reviewed annually by the founder and updated to reflect any material changes to the technology stack, data handling practices, or regulatory environment.
Last reviewed: June 2026 · Next review due: December 2026