Last updated: March 2026
All broker API credentials are encrypted using AES-256 (Fernet) before storage. Passwords are hashed using bcrypt. Authentication uses JWT tokens with 30-day expiry stored in httponly cookies.
We do not sell or share your personal data with third parties except: (a) your broker, to execute trades; (b) Razorpay, for payment processing; (c) Google, if you use Google OAuth login.
Trade history and account data are retained for as long as your account is active. You may request deletion of your account and all associated data by contacting us.
We use a single httponly session cookie for authentication. No tracking or advertising cookies are used.
You have the right to access, correct, or delete your personal data. Contact us to exercise these rights.
For privacy concerns, contact us at our contact page.