Legal
Privacy Policy
What we collect, what we never do, and how to get your data deleted. Plain-English, short, and dated so you can tell when it last changed.
Last updated: 9 September 2026
Overview. This Privacy Policy explains how FinvestR Capital ("FinvestR", "we", "us" or "our") collects, uses, stores and protects your information when you use the FinvestR website and mobile applications (collectively, the "Service"). We designed this policy to be short and readable. If you have questions at any point, write to [email protected].
We update, change or replace any part of this policy by posting updates on this page. Where changes are material, we will also notify you inside the Service before they take effect.
1. What we collect
Depending on how you use the Service, we collect:
- Account details: your email address, name, and authentication identifiers (including your Google account identifier if you sign in with Google). Passwords are stored only as bcrypt hashes; we never store them in plain text.
- Portfolio data: the contents of the Consolidated Account Statement (CAS) PDFs or other portfolio files you upload, which may include your name, email, PAN, folio numbers, scheme holdings and transaction history.
- Goals and preferences: financial goals, target amounts, risk preferences and watchlists you create.
- Chat content: the messages you send to the FinvestR AI assistant and the responses it generates.
- Usage and diagnostics: app interactions, crash logs and device identifiers used to keep the Service secure and to fix problems.
2. What we do NOT collect
We do not collect your location, contacts, photos, microphone audio, health data or browsing history. We do not read anything from your device other than the files you explicitly upload. We do not run third-party advertising SDKs inside the app.
3. How we use your information
We use your information to:
- Operate the Service: parse your CAS, compute portfolio analytics, track goals and deliver the features you use.
- Generate AI responses: your chat messages and relevant portfolio context are processed by large language model providers to produce answers.
- Authenticate you and keep the Service secure, including fraud and abuse prevention.
- Communicate service messages such as email verification, password resets and important product updates.
- Improve the Service using aggregate, de-identified usage patterns.
4. What we never do
We do not sell your personal data. We do not share your data with advertisers. We do not use your portfolio or chat content to build advertising profiles. Your data is used to run FinvestR for you, and for nothing else.
5. Who we share data with
We share data only with the processors needed to run the Service, under contractual confidentiality obligations:
- Supabase: hosting of the application database and authentication, encrypted at rest (AES-256) and in transit (TLS).
- Large language model providers: chat message content is sent to our AI providers to generate responses. Chat content is encrypted in transit and is not used by us for advertising.
- Razorpay: payment processing for paid subscriptions. Card and UPI details are handled entirely by Razorpay and never touch our servers.
- Google: if you use Google sign-in, Google processes the authentication flow and shares your basic profile (name, email) with us.
- AMFI, CDSL/NSDL and AMCs: portfolio data shown in the Service is sourced from these providers. Where you transact through the FinvestR portal, transaction details are shared with the relevant asset management companies and registrars to execute and service your investments.
- Email delivery providers: to send transactional email such as verification and password reset messages.
6. Security
All traffic to the Service is encrypted in transit with TLS. Data at rest is encrypted by our infrastructure providers. Passwords are bcrypt-hashed. Access to production data is restricted to a small number of authorized personnel and is audited.
No online service can promise perfect security. If a security incident affecting your data ever occurs, we will notify you and the relevant authorities as required by applicable Indian law.
7. Data retention and deletion
We keep your data for as long as your account is active, or as needed to provide the Service and comply with legal obligations (including books-of-account requirements that apply to us as an AMFI-registered distributor).
You can delete your data: request full account and data deletion from in-app settings (Profile, Danger zone), from our dedicated deletion page at /delete-account, or by emailing [email protected]. We complete deletion from production systems within 30 days; encrypted backups rotate out within 90 days. Deleting your account removes your profile, uploads, goals, watchlists and chat history.
8. Your rights
Under Indian data-protection law (including the Digital Personal Data Protection Act, 2023) and, where applicable, other regimes such as the GDPR, you have the right to access, correct, and delete your personal data, to withdraw consent, and to nominate a representative. To exercise any of these rights, email [email protected] and we will respond within a reasonable time.
9. Children
The Service is intended for users who are at least 18 years of age. We do not knowingly collect data from children. If you believe a minor has provided us personal data, contact us and we will delete it.
10. Changes to this policy
We may update this Privacy Policy from time to time. The date at the top of this page always shows when it was last revised. Material changes will be announced inside the Service before they take effect.
11. Grievance officer and contact
If you have questions, requests or complaints about this policy or your data, contact our grievance officer: [email protected], or by post to FinvestR Capital, #361, 2nd Floor, 7th Cross, 1st Block, Jayanagar, Bengaluru 560011, India. We aim to acknowledge grievances within 48 hours and resolve them within 30 days.