Privacy Policy

Last updated: 2 May 2026

This privacy policy explains what data INDASH collects, how we use it, and your rights. We aim to be honest and concrete — no legal-jargon padding.

What we collect

Account data

When you sign up: your full name, email address, optional phone number, and a hashed password (we never store your password in plain text).

Usage data

What features you use, what stocks you add to your watchlist, what trades you log, what alerts you set. This is required to provide the service.

Broker credentials (optional)

If you connect a broker (Fyers / Angel One / Dhan), we store your API credentials encrypted at rest using Fernet (AES-128 in CBC mode with HMAC). The encryption key is held separately. We use these credentials only to fetch your authorised data on your behalf.

AI provider keys (optional)

If you use the AI Copilot, your Anthropic / Gemini API keys are stored encrypted with the same scheme. AI calls go directly from INDASH to the provider using your key — we never proxy or log the content of your AI conversations beyond what's needed to display them back to you.

Payment data

If/when you subscribe, payment processing is handled by our payment partner (Razorpay/UPI). We see only the order amount, status, and a transaction ID — never your full card number or bank credentials.

Server logs

Standard web-server logs (IP address, user agent, timestamps) for security monitoring, kept for 30 days.

What we don't collect

How we use it

Your rights

Security

Cookies

We use a single session cookie (HttpOnly, SameSite=Lax) to keep you logged in. We don't use third-party tracking cookies.

Children

INDASH is not directed at users under 18. If you're under 18 you may not use INDASH.

Changes

We may update this policy as the platform evolves. Significant changes are emailed to all subscribers.

Contact

Questions or data requests? support@investdash.ind.in