Privacy Policy
Effective date: 21 May 2026 · Version 2026-05-v1
1. What We Collect
| Category | Data | Purpose |
|---|---|---|
| Account | Email address, name | Authentication, account management |
| Broker tokens | Kite/Fyers access token, Zerodha session token | Fetch your portfolio and holdings on your request |
| API keys | LLM provider keys (Claude, OpenAI, Gemini, etc.) | Forwarded to your chosen LLM provider on each AI request; not used by us |
| Trading settings | Risk %, capital, strategy preferences | Personalise the paper-trading simulation |
| Paper trades | Simulated trade records, P&L, decisions | Display your paper-trading history and backtest results |
| AI interactions | Your chat messages and AI responses (if persona is enabled) | Build a behavioural persona to improve AI response quality |
| Usage data | Broker connect/disconnect events, terms acceptance timestamp | Audit log, compliance |
2. What We Do NOT Collect
- Your broker login password or PIN — authentication happens directly on the broker's site via OAuth.
- Real trade orders — the Platform does not execute live trades.
- Payment information — the Platform is currently free and does not process payments.
- Device fingerprint, advertising IDs, or third-party tracking cookies.
3. How We Use Your Data
Your data is used solely to provide the Platform's features to you. We do not sell, share, or transfer your personal data to any third party except:
- Broker APIs (Zerodha, Kite, Fyers) — to fetch your portfolio on your request.
- LLM providers (your chosen provider) — to answer your AI queries using your own API key.
- Odoo — the application framework hosting this Platform.
We do not use your data to train AI models, for advertising, or for any purpose beyond operating the dashboard for you.
4. Data Retention
- AI chat history: retained until you delete your account or disable the persona feature.
- Paper trades & backtest runs: retained until you delete your account.
- Broker tokens: retained until you disconnect the broker or delete your account. Tokens expire independently per broker policy.
- Audit log: retained for 12 months.
- After account deletion, all personal data is hard-deleted within 30 days.
5. Your Rights (DPDP Act 2023)
- Right to access: Download all your data from the Connect tab → Privacy → Export My Data.
- Right to correction: Update your account details via the standard Odoo profile page.
- Right to erasure: Delete your account and all associated data from the Connect tab → Privacy → Delete My Account.
- Right to withdraw consent: Disable persona memory, analytics, and marketing emails at any time from the Connect tab → Privacy settings.
- Right to grievance redressal: Contact the Grievance Officer below.
6. Security
Sensitive credentials (broker tokens, LLM API keys) are encrypted at rest using AES-256 symmetric encryption. Access to the database is restricted to authorised server infrastructure. All data is transmitted over HTTPS.
7. This Is Not an Account Aggregator
Stock Market Dashboard uses direct OAuth with brokers to read your portfolio data. It is not registered as an Account Aggregator (AA) under the RBI Account Aggregator Framework. The AA framework is a separate regulated service.
8. Changes to This Policy
Material changes to this Policy will require you to re-accept on your next login. We will display the effective date and version number above.
9. Grievance Officer
Name: TheERPBot Team
Email: contact@theerpbot.com
Response time: Acknowledgement within 24 hours; resolution within 30 days.