Need a hand? You're in the right place.
Use the password reset flow. We'll email you a link to set a new one. Links expire 60 minutes after they're sent and work once.
That's fine. You can keep using your SSO provider, or set a password from your security page. Setting one doesn't disable SSO; you'll just have two ways in.
From /account/security, scroll to Phone, enter your number, click Send verification code, then enter the 6-digit code we text you. Once verified, you can flip on MFA in the next section.
If your phone is lost or you're not getting the SMS, the fastest recovery is to email support@harvestengine.ai from the email address on your account so we can verify it's you.
E*TRADE today. Schwab is in development. Fidelity (read-only) and Interactive Brokers will follow. The intent is to be broker-agnostic — your money stays at your broker, we connect via OAuth and act on your behalf for the trades you approve.
From the V2 admin gear in the trading dashboard, find the E*TRADE authentication panel and follow the prompts. The flow uses E*TRADE's OAuth, so you log in directly with E*TRADE — we never see your password.
Revoke our OAuth grant from your broker's website (each broker has a "Connected apps" or similar page). That immediately cuts our access. You can also email us to request account closure + deletion of your data.
See our Privacy Policy. Short version: account profile (email, name, optional phone), brokerage data (positions, lots, trades) read via OAuth, and usage logs. We don't sell or share your data for advertising.
Encrypted at rest with envelope encryption: a Google Cloud KMS master key wraps each token, with your user ID bound as "additional authenticated data" so the ciphertext can't be silently moved between user rows. A database leak alone would yield nothing decryptable.
From /account/security, scroll to Trusted devices. Each device shows browser, IP, and last-seen date — click Revoke on any you don't recognize.
Twilio toll-free verification is in progress (1–3 business days from registration). It enables once carrier verification clears.
If you've enrolled a phone number, we use SMS for: authentication codes, MFA on sign-in (if enabled), trade-approval links, and post-execution summaries. ~5 messages per month for typical use.
Reply STOP from your phone to unsubscribe at any
time. Reply HELP for support links.
SMS opt-in / opt-out and frequency are documented in our Privacy Policy section 5. Standard carrier SMS rates may apply.
Support: support@harvestengine.ai — general questions, sign-in problems, account recovery
Privacy: privacy@harvestengine.ai — data-rights requests (CCPA, GDPR), privacy concerns
Legal: legal@harvestengine.ai — terms questions, legal notices