Privacy Policy
This Privacy Policy explains how Intentstack Technologies ("Munafa", "we", "us") collects, uses, shares and protects personal data when you use munafa.io, app.munafa.io, api.munafa.io and related services (the "Platform"). It is published in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000 and the rules made under them, including the SPDI Rules, 2011. For the purposes of the DPDP Act, we are the Data Fiduciary and you are the Data Principal.
Contents
01Data we collect
| Category | What it includes | Source |
|---|---|---|
| Account | Name, email address, password (stored only as a one-way bcrypt hash — we cannot read it), plan and role. | You, at registration |
| Portfolio & trading | Holdings, average prices, quantities and P&L (synced from your broker or entered manually); watchlists; journal entries; backtest configurations; strategy settings. | You / your broker (with your authorisation) |
| Broker connection | Zerodha Kite Connect access token (encrypted at rest). We never receive or store your broker password, funds or securities. | Zerodha OAuth flow |
| Notification identifiers | Email address, Telegram chat ID, WhatsApp phone number — only those you configure for alerts. | You, in Settings |
| Content | AI chat messages, notes, saved screens, analysis history. | You, while using the Platform |
| Payments | Order IDs, plan, amount, invoice records, payment status. Card / UPI / bank details are collected directly by the payment aggregator (Razorpay) and never touch our servers. | Payment aggregator |
| API usage | API keys you generate (stored hashed/scoped), request counts and rate-limit data. | Generated on the Platform |
| Technical & logs | IP address, browser/user-agent, timestamps, pages and features used, error logs. | Automatically |
We do not knowingly collect special categories of data beyond financial information inherent to the Service, and we do not collect data we do not need ("data minimisation").
02How we use data (purposes & lawful basis)
- Provide the Service — generate analyses and verdicts, sync and display your portfolio, run scanners and backtests, deliver alerts to channels you chose. (Consent / performance of contract)
- Billing — process subscription payments, maintain invoices and billing history as required by tax law. (Contract / legal obligation)
- Security — authenticate sessions, detect abuse and fraud, maintain audit logs. (Legitimate use / legal obligation)
- Support & communication — respond to your requests; send service emails (receipts, security notices, material changes). We send marketing communications only with your consent and always with an opt-out.
- Improvement — aggregate, de-identified usage statistics to improve features. We do not use your identifiable portfolio data to train AI models.
- Legal compliance — respond to lawful requests from courts, regulators (including SEBI) and law-enforcement agencies.
03AI processing — what leaves our servers
To generate an analysis, chat reply or report, the Platform sends relevant context to a third-party AI provider via API — this can include the stock symbol, market data, news snippets, and (for portfolio-aware features) your holdings for the relevant stock, quantities, average price and P&L, plus your chat message text.
- Providers currently used: Anthropic (Claude), OpenAI and/or Google (Gemini), depending on platform configuration.
- Data is sent over encrypted connections under each provider's API/enterprise terms, which by default do not permit training on API data.
- We do not send your password, email, payment details or broker tokens to AI providers.
04Sharing & data processors
We do not sell or rent personal data, and we do not share it with advertisers. We share data only with processors needed to run the Service, under contracts or terms that restrict their use of it:
| Recipient | Purpose | Data involved |
|---|---|---|
| Razorpay | Payment processing & invoicing | Name, email, plan, amount; card/UPI handled by them directly |
| Zerodha (Kite Connect) | Portfolio sync; order placement you initiate | OAuth tokens; orders you authorise |
| AI providers (Anthropic / OpenAI / Google) | Generating analyses, chat and reports | See Section 03 |
| Telegram | Alert delivery, if you connect it | Your Telegram chat ID; alert content |
| WhatsApp via WATI (Meta platform) | Alert delivery, if you connect it | Your phone number; alert content |
| Email delivery provider (Resend) | Transactional email & alerts | Email address; message content |
| Infrastructure / hosting provider | Servers, storage, backups | All Platform data (encrypted in transit; sensitive tokens encrypted at rest) |
We may also disclose data: (a) when required by law, court order or a government/regulatory authority; (b) to enforce our Terms or protect rights, safety and security; or (c) to a successor entity in a merger, acquisition or asset sale, in which case this Policy continues to apply and you will be notified.
05Cookies & tracking
- The app uses essential storage only: an authentication token (JWT) and your preferences (e.g. theme) kept in your browser's local storage. These are necessary for the Service to function.
- We do not use third-party advertising cookies, cross-site trackers or social-media pixels.
- Fonts are loaded from Google Fonts, which may log your IP address when serving font files.
06Security
We follow "reasonable security practices and procedures" within the meaning of Section 43A of the IT Act and the SPDI Rules, and security safeguards under the DPDP Act, including:
- Encryption in transit — TLS 1.2/1.3 across all domains, with HSTS;
- Encryption at rest for broker credentials — Kite access tokens are encrypted with AES-256-GCM;
- Password protection — passwords stored only as bcrypt hashes; we cannot read them;
- Access control — role-based access, tenant isolation at the database layer, scoped API keys;
- Infrastructure hygiene — containerised services bound to localhost behind a hardened reverse proxy, security headers, rate limiting, and security-event logging.
No system is perfectly secure. You are responsible for keeping your password confidential and for the security of the devices and channels (e.g. your Telegram or WhatsApp account) you connect.
07Retention
- Account data and content — retained while your account is active, and deleted or anonymised within 90 days of verified account-deletion request, except as below.
- Billing and invoice records — retained for 8 years as required by Indian tax and accounting laws.
- Security and access logs — retained for at least 180 days in line with CERT-In directions, then rotated.
- Broker tokens — Kite access tokens are short-lived by design and are invalidated/replaced on each re-authentication; disconnecting the integration removes the stored token.
08Your rights (Data Principal rights)
Under the DPDP Act you have the right to:
- Access — obtain a summary of the personal data we hold about you and the processing activities;
- Correction & updating — have inaccurate or incomplete data corrected (most account data is editable in Settings);
- Erasure — request deletion of your personal data, subject to the legal retention periods in Section 07;
- Withdraw consent — at any time, with effect for future processing (some features will stop working, e.g. disconnecting Kite stops portfolio sync);
- Grievance redressal — complain to our Grievance Officer (Section 13) and, if unresolved, to the Data Protection Board of India;
- Nominate — nominate another individual to exercise your rights in the event of death or incapacity.
To exercise any right, email hello@munafa.io from your registered email address. We will verify your identity and respond within the timelines prescribed by law (and in any case within 30 days).
09Cross-border transfers
Our servers are located in India or with infrastructure providers serving India. Some processors (notably AI providers and email/messaging services) process data on servers outside India. Such transfers are made as permitted under the DPDP Act and subject to the safeguards in those providers' terms. By using AI-powered and messaging features, you consent to this processing.
10Children
The Platform is not directed at, and may not be used by, persons under 18 years of age. We do not knowingly process children's data; if you believe a minor has created an account, contact us and we will delete it.
11Breach notification
In the event of a personal-data breach, we will notify the affected users and the authorities (including the Data Protection Board of India and CERT-In) in the form and within the timelines required by applicable law, and will take prompt steps to contain and remediate the breach.
12Changes to this Policy
We may update this Policy from time to time. Material changes will be notified by email or in-app notice before they take effect, with the "Last updated" date revised above. Your continued use after the effective date constitutes acceptance.
13Grievance officer & contact
In accordance with the IT Act, 2000, the rules thereunder and the DPDP Act, 2023: