SPS · Your Trading Simulator Plus
Privacy, Financial Risk & Terms of Use
Effective date: October 3, 2026
Operator: Garrett Krosschell
Privacy Contact: spstradeapp@gmail.com
Who this notice covers
This notice covers the distributed Stock Paper Scissors (SPS / Your Trading Simulator Plus) native app, developed and operated by Garrett Krosschell. A public web edition of SPS is not offered; the developer uses a private web version for development. A public privacy-information page is not a public trading website.
This notice also explains network features present in this app build, including optional server-assisted paper scheduling and browser notifications. Those features may use a developer-operated backend even though no public web edition is offered. Their availability depends on the developer's deployment. Alpaca is a separate third-party provider whose services are governed by its own agreements and privacy notices.
What SPS does — and what Alpaca does
SPS displays market information, account balances, positions and orders. PAPER mode simulates trading; optional LIVE mode sends real trading instructions using your Alpaca live credentials. Alpaca supplies market data and account/trading services. SPS is an independent software interface, not Alpaca, a securities exchange, a custodian or a source of personalized investment advice. Use of Alpaca APIs and links does not imply ownership, sponsorship, approval or endorsement by Alpaca. Your brokerage relationship and assets are managed under your agreements with the relevant Alpaca entities. SPS does not itself take deposits or custody your securities.
Information processed
Depending on the features you use, SPS processes API key identifiers and secrets you enter; account identifiers and API-returned balances, buying power, positions and order history; symbols, prices, quantities, order instructions and execution results; watchlists, favorites, comparison bookmarks, selected themes, app settings and locally recorded performance values. First-launch acceptance records contain an acceptance flag, notice version and time.
PUSH/AUTO additionally processes your selected paper/live account identifier, saved rules, quantities, spending controls, historical low-time studies, schedule times and execution/notification history. Browser push registration includes a subscription endpoint and encryption/routing keys. Notifications may contain stock symbols, schedule times and share quantities, which can be visible on a lock screen.
The SPS interface asks for API credentials, not your Alpaca account password, government ID, bank login or payment-card details. Account-opening and identity-verification information you submit to Alpaca is handled by Alpaca. Network requests expose IP addresses and browser/device request information to the destination server and its infrastructure. Server and reverse-proxy logs may contain request metadata and error information.
Where information goes and why
The native app sends account, quote and manual-order requests to Alpaca over HTTPS. Its optional scheduling controls also send paper/live API credentials and requested schedule settings to the configured SPS scheduling server. Current browser-notification registration opens the developer's web interface; it is not a native in-app notification service and may not be available to distributed-app users. Private development-interface sessions use a session cookie and server-memory credentials as described below.
These data flows let SPS connect an account, display information, submit instructions you authorize and, where enabled, execute saved paper/live schedules and deliver requested notifications. They do not upload sps_userlog.txt. The personal device log is never submitted as analytics or automatically attached to requests or support messages.
The supplied app has no advertising trackers, behavioral-advertising features, data-sale features or third-party analytics SDKs. This describes SPS, not the independent practices of Alpaca, operating systems, browsers or infrastructure providers. Information may need to be disclosed where required by law or to address fraud, security incidents or legal claims.
Personal device log — sps_userlog.txt
SPS keeps sps_userlog.txt for your own reference only. Logging is ON by default after the first-launch acknowledgment and can be turned OFF in ABOUT SPS > PERSONAL USER LOG. SPS never uploads, emails or sends this log to the developer, Alpaca or a scheduling server. It is separate from account data used for trading and server-side schedule records.
The app adds a UTC timestamped entry when a recorded event occurs: app launch and normal exit, page visits, selected feature-button presses, Alpaca connection attempts and success/failure (including remembered connections), and manual-order or schedule-request outcomes. Entries include only fixed event names, paper/live mode, page, a predefined action name and connection source when applicable. Connection failures use a generic event, not raw error text. Not every tap or background refresh is recorded; a forced termination may not leave an exit entry. This is a personal activity aid, not a complete broker audit trail or proof of execution.
The log does NOT contain API keys, secret keys, passwords, account identifiers, balances, ticker symbols, quantities, order IDs, response bodies, request headers or raw errors. Logging code accepts only predefined values. It keeps the most recent 2,000 entries, subject to a 256 KiB limit; older entries are removed automatically. There is no day-based expiry. Turning logging OFF stops new entries but keeps existing ones. CLEAR USER LOG removes the local entries; it does not delete exported copies or broker/server records.
The working file stays in the app's private storage folder. ABOUT shows its exact path. On Android, SPS uses its no-backup app directory. On Mac, it uses the app's Application Support data directory. The SPS settings-backup feature does not include this log.
EXPORT USER LOG creates a readable text copy. On Android, choose Downloads or another local device-storage folder in the Save picker; cloud destinations are not supported. Android may add a number if a file with that name exists. On Mac, the export is ~/Downloads/SPS/sps_userlog.txt, with confirmation before replacing an existing export. Exported copies remain until you delete them and may be read by anyone with access to their folder. Backups or synchronization tools you independently configure may copy exported files; SPS does not transmit them.
Device storage and backups
Native settings, favorites, comparison presets and performance records are saved in local app files. If you choose CONNECT & REMEMBER, supported builds use macOS Keychain or Android Keystore-backed encrypted credential storage. Session-only keys remain in app memory. Both PAPER and LIVE account connections, including remembered credentials, require the Authorize SPS disclosure and explicit AUTHORIZE action before connecting. CANCEL makes no new connection. ABOUT SPS is available before authorization. This app disclosure does not replace Alpaca OAuth consent. Restoring an SPS settings backup selects PAPER mode and leaves the account disconnected; select LIVE explicitly when needed. FORGET SAVED KEYS removes the stored credential copy; disconnect separately to clear the active session.
The developer’s private web interface uses browser local storage for preferences, watchlists and its first-launch acceptance record. It does not intentionally save your Alpaca secret in local storage. Clearing browser site data or native app data can remove local settings and cause the first-launch notice to reappear. Device backups or secure-storage behavior may affect what survives an uninstall.
Exported SPS backups contain settings and financial/watchlist records but exclude API credentials in the supplied implementation. They are not automatically encrypted by SPS. Protect exported files and any copies you share or place in cloud storage.
Web sessions, cookies and server storage
The developer's private web interface uses an opaque HttpOnly session cookie, currently set to expire after 12 hours, with SameSite=Lax and the Secure flag when served over HTTPS. Session credentials are held in the SPS server process. Explicit disconnect removes that session; a server restart clears in-memory sessions. Cookie expiry alone does not guarantee immediate deletion of an in-memory record. These web-session mechanisms are separate from the app's personal device log.
When server PUSH/AUTO is enabled, paper/live API credentials or OAuth tokens are encrypted at rest with a server-held key. The server stores account-scoped rules, plan data, execution/notification records and subscriptions. Encryption cannot guarantee protection if the server or encryption key is compromised. Native remembered credentials and scheduling credentials are separate copies.
The scheduler removes its stored account credentials when no PUSH/AUTO rules for that account remain active. Paused settings and historical event records can remain. Canceling a rule removes that rule but preserves execution history to prevent duplicate attempts. Subscriptions may be removed after invalid-delivery responses.
No fixed time-based deletion schedule has been configured for these operational records. Records can remain until manually removed or removed by the behavior described above. The developer does not run a separate personal-usage-log collection service. Hosting software can produce access/error logs; absence of a configured retention period does not mean that no technical logs exist. Such technical records are not sps_userlog.txt. Contact spstradeapp@gmail.com about access or deletion of any records held by the developer.
Browser notifications and third-party services
PUSH is optional and uses browser Web Push. The device's browser and its push provider process subscription routing and encrypted notification delivery. Enabling browser permission alone is separate from enabling a saved rule. Opening the browser from the native app does not itself complete registration. Connect the same selected paper/live account on the website and use its notification-registration button.
You can revoke notification permission in the browser and pause or cancel saved PUSH rules in SPS. Revoking permission or uninstalling the native app does not automatically stop server-side paper/live AUTO orders. Invalid subscription endpoints may be removed after a delivery failure. Links to Alpaca open an independently operated service, which may set its own cookies and collect information under its own policies.
Your choices and privacy requests
You can choose session-only access, avoid remembered credentials, disable PUSH/AUTO, delete local favorites and settings, remove saved keys, revoke browser notification permission and rotate or revoke API keys directly with Alpaca. Review and pause/cancel all saved rules before discontinuing the service. Disconnecting or closing SPS does not cancel submitted orders or delete your Alpaca brokerage account.
For access, correction or deletion of information held by the SPS operator, contact the privacy contact above. Identify the affected service and account without sending API secrets, passwords or identity documents in an initial message. Identity verification may be necessary. Rights and exceptions depend on the laws that apply. Requests concerning Alpaca-held information must be directed to Alpaca. Deletion can be limited where records must be retained for legal obligations, security, dispute resolution or prevention of duplicate order attempts. Ask the operator about any retained copies and backups.
Security, location and intended users
SPS uses HTTPS for its configured external connections and the device/server storage controls described above. No transmission, device or storage system is completely secure. Protect your device, use secure connections and restrict access to API keys. Revoke credentials promptly if you suspect exposure. Never send API keys, secrets or passwords to the support email.
The personal log is written on the device where the app runs. It is not hosted on the developer's server. Alpaca and any enabled third-party or backend features process other service data on their own systems; this notice does not claim that those separate records stay on your device. For questions about an enabled service's processing location, contact spstradeapp@gmail.com. SPS is intended for adults legally permitted to use the connected services, not for children.
Financial risk and user responsibility
Real securities transactions can lose some or all invested funds. Margin involves borrowing, interest, margin calls, forced liquidation and the possibility of losing more than your deposit. Market orders can fill at prices different from displayed quotes or cost estimates. Fees, taxes, slippage, liquidity constraints, outages and delayed data can change results.
Paper performance is simulated and does not establish likely live performance. Historical averages, COMP studies and AM/MD/PM/Full Day low-time calculations are not predictions or recommendations to buy or sell. The lowest price in historical data cannot be guaranteed for today's order. Share-cost displays and the 1% funds buffer are estimates, not a guaranteed price or maximum loss. MAX CASH, MAX MARGIN and MAX USE do not remove trading risk.
PUSH/AUTO supports independent PAPER and separately authorized LIVE BUY and SELL schedules. Both use the selected historical low-time schedule. LIVE BUY requires a positive MAX USE position-cost cap and maximum price per share. LIVE SELL requires a minimum price per share and available owned shares; it is not a short-selling feature. Cash and position-cost limits apply to BUY. LIVE orders are DAY limit orders that can fill later in the session, partially, or not at all. Existing paper schedules never become live automatically. Saved schedules can run after app closure or session disconnection. Multiple enabled BUY/SELL windows can attempt multiple trades of the same symbol. Notifications can arrive late or fail, and scheduled actions can be skipped or fail. Check broker records before retrying an uncertain order; a failed response does not establish that the broker rejected it. You are responsible for the settings and instructions you authorize, reviewing account activity and consulting qualified advisers when needed.
Assumption of risk and limits of liability
To the fullest extent permitted by applicable law, you assume the risks of using SPS and release its developers, operators and contributors from claims and liability for financial outcomes arising from its use, including investment losses, lost profits or opportunities, data errors, delays, interruptions, software failures and third-party services. The software is provided as available, without a promise of financial results or uninterrupted or error-free operation. This limitation does not exclude liability or waive rights that cannot lawfully be excluded or waived, including fraud, gross negligence, reckless or intentional misconduct, or other protected claims under applicable law.
Acceptance and updates
CONTINUE on first launch records acknowledgment of the displayed information and agreement to its risk and liability terms. It does not place an order, turn on LIVE mode, enable an automated rule, authorize marketing or waive rights that cannot be waived. The acknowledgment is stored per installation, separately from the personal usage log and ordinary settings backups.
ABOUT keeps these disclosures and the Privacy link available. Normal launches do not repeat the acknowledgment after acceptance. Clearing app data or using a new installation may require it again. The effective date identifies this version. Material changes will be described appropriately, with any consent required by applicable law obtained separately. The first-launch acknowledgment does not automatically authorize unrelated new uses of personal information.