Legal

Privacy Policy

Last updated: 10 June 2026Version 1.0

This Privacy Policy explains how Intentstack Technologies ("Munafa", "we", "us") collects, uses, shares and protects personal data when you use munafa.io, app.munafa.io, api.munafa.io and related services (the "Platform"). It is published in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000 and the rules made under them, including the SPDI Rules, 2011. For the purposes of the DPDP Act, we are the Data Fiduciary and you are the Data Principal.

Plain-language summary: we collect what we need to run an investment-analysis tool — your account details, the portfolio data you give us or sync from your broker, your settings, and payment records. We never see your broker password or your card details. Portfolio context is sent to AI providers to generate your analyses. We don't sell your data, and we don't run advertising trackers.

Contents

  1. 01Data we collect
  2. 02How we use data
  3. 03AI processing
  4. 04Sharing & processors
  5. 05Cookies & tracking
  6. 06Security
  7. 07Retention
  8. 08Your rights
  9. 09Cross-border transfers
  10. 10Children
  11. 11Breach notification
  12. 12Changes
  13. 13Grievance officer & contact

01Data we collect

CategoryWhat it includesSource
AccountName, email address, password (stored only as a one-way bcrypt hash — we cannot read it), plan and role.You, at registration
Portfolio & tradingHoldings, average prices, quantities and P&L (synced from your broker or entered manually); watchlists; journal entries; backtest configurations; strategy settings.You / your broker (with your authorisation)
Broker connectionZerodha Kite Connect access token (encrypted at rest). We never receive or store your broker password, funds or securities.Zerodha OAuth flow
Notification identifiersEmail address, Telegram chat ID, WhatsApp phone number — only those you configure for alerts.You, in Settings
ContentAI chat messages, notes, saved screens, analysis history.You, while using the Platform
PaymentsOrder IDs, plan, amount, invoice records, payment status. Card / UPI / bank details are collected directly by the payment aggregator (Razorpay) and never touch our servers.Payment aggregator
API usageAPI keys you generate (stored hashed/scoped), request counts and rate-limit data.Generated on the Platform
Technical & logsIP address, browser/user-agent, timestamps, pages and features used, error logs.Automatically

We do not knowingly collect special categories of data beyond financial information inherent to the Service, and we do not collect data we do not need ("data minimisation").

02How we use data (purposes & lawful basis)

03AI processing — what leaves our servers

To generate an analysis, chat reply or report, the Platform sends relevant context to a third-party AI provider via API — this can include the stock symbol, market data, news snippets, and (for portfolio-aware features) your holdings for the relevant stock, quantities, average price and P&L, plus your chat message text.

04Sharing & data processors

We do not sell or rent personal data, and we do not share it with advertisers. We share data only with processors needed to run the Service, under contracts or terms that restrict their use of it:

RecipientPurposeData involved
RazorpayPayment processing & invoicingName, email, plan, amount; card/UPI handled by them directly
Zerodha (Kite Connect)Portfolio sync; order placement you initiateOAuth tokens; orders you authorise
AI providers (Anthropic / OpenAI / Google)Generating analyses, chat and reportsSee Section 03
TelegramAlert delivery, if you connect itYour Telegram chat ID; alert content
WhatsApp via WATI (Meta platform)Alert delivery, if you connect itYour phone number; alert content
Email delivery provider (Resend)Transactional email & alertsEmail address; message content
Infrastructure / hosting providerServers, storage, backupsAll Platform data (encrypted in transit; sensitive tokens encrypted at rest)

We may also disclose data: (a) when required by law, court order or a government/regulatory authority; (b) to enforce our Terms or protect rights, safety and security; or (c) to a successor entity in a merger, acquisition or asset sale, in which case this Policy continues to apply and you will be notified.

05Cookies & tracking

06Security

We follow "reasonable security practices and procedures" within the meaning of Section 43A of the IT Act and the SPDI Rules, and security safeguards under the DPDP Act, including:

No system is perfectly secure. You are responsible for keeping your password confidential and for the security of the devices and channels (e.g. your Telegram or WhatsApp account) you connect.

07Retention

08Your rights (Data Principal rights)

Under the DPDP Act you have the right to:

To exercise any right, email hello@munafa.io from your registered email address. We will verify your identity and respond within the timelines prescribed by law (and in any case within 30 days).

09Cross-border transfers

Our servers are located in India or with infrastructure providers serving India. Some processors (notably AI providers and email/messaging services) process data on servers outside India. Such transfers are made as permitted under the DPDP Act and subject to the safeguards in those providers' terms. By using AI-powered and messaging features, you consent to this processing.

10Children

The Platform is not directed at, and may not be used by, persons under 18 years of age. We do not knowingly process children's data; if you believe a minor has created an account, contact us and we will delete it.

11Breach notification

In the event of a personal-data breach, we will notify the affected users and the authorities (including the Data Protection Board of India and CERT-In) in the form and within the timelines required by applicable law, and will take prompt steps to contain and remediate the breach.

12Changes to this Policy

We may update this Policy from time to time. Material changes will be notified by email or in-app notice before they take effect, with the "Last updated" date revised above. Your continued use after the effective date constitutes acceptance.

13Grievance officer & contact

In accordance with the IT Act, 2000, the rules thereunder and the DPDP Act, 2023:

Data FiduciaryIntentstack Technologies
Grievance OfficerSaurabh Pushkar
AddressBengaluru, Karnataka, India
Response timeAcknowledgement within 48 hours; resolution within 30 days