Privacy Policy

# Privacy Policy — pTracker **Last updated:** 2026-09-02 **Operator:** pTracker (sole proprietor / early-access product) **Contact:** support email shown in the app (`SUPPORT_EMAIL`) This policy describes how pTracker handles personal data for users in India and elsewhere. It is written for **early-access freemium SaaS**, not as a substitute for formal legal counsel. For technical security controls (sessions, encryption, production checks), see also `docs/SECURITY.md` in the product repository (operator documentation). ## 1. Who we are pTracker is a personal net-worth and path-to-goal web application. The service is operated by the product owner (contact via the support address in the app). ## 2. Data we collect | Category | Examples | Why | |----------|----------|-----| | Account | Email, name, password hash (bcrypt) | Sign-in, support | | Portfolio (you enter) | Salary, expenses, EPF/PPF/gold/cash, loans, goals | Net-worth model | | Broker (optional, Pro) | Zerodha Kite **access token** (not password), Kite user id | Live holdings | | Billing | UPI UTR / payment claim notes, plan status | Pro unlock | | Technical | Login timestamps, app logs (may include email on auth events) | Security & ops | | Session | First-party cookie `ptracker_s` (opaque session id) | Stay signed in across refresh / tabs | We **do not** ask for your Zerodha password, TOTP, or bank passwords. Kite connects via **OAuth** in production; you authenticate with Zerodha in their browser flow. We **do not** put your portfolio balances, email, or passwords in the browser address bar. Session credentials are stored in a **first-party HTTP cookie**, not in the page URL. ## 3. How we store and protect data - Transport: HTTPS (Cloud Run / hosting). - Passwords: **bcrypt** hashes only (strength policy: min 10 characters, not only letters or only numbers). We cannot recover your password. - Kite access tokens and portfolio JSON (profile, manuals, liabilities, holdings, scenarios): **encrypted at rest** with a server secret (`APP_SECRET` / Fernet). - Database file is stored in a **private** Google Cloud Storage bucket (not public). - Snapshots of net-worth summaries may include numeric aggregates for history charts. - **Session tokens:** the browser holds a random opaque token in cookie `ptracker_s` (Secure + SameSite=Lax on production HTTPS). The server stores only a **one-way hash** of that token, with a sliding idle lifetime (default **7 days**) and an absolute maximum (default **30 days** from login). Logout deletes the cookie and revokes the server row. Changing or resetting your password **revokes all sessions**. We do not log raw session tokens. - **Password reset:** one-time codes are stored hashed server-side (~1 hour). On production we do **not** display reset codes in the browser; we attempt email delivery when configured. Contact support if you cannot reset access. - **Rate limits:** failed logins, registrations, and reset requests are rate-limited to reduce abuse. - Production hosts refuse weak/default `APP_SECRET` and forbidden broker password env vars. No security practice is perfect. You should not reuse passwords and should use a strong unique password for pTracker. ## 4. How we use data - Provide the dashboard, path engine, and account features you request - Process Pro upgrades (UPI claims / redeem codes) - Secure the service (rate limits, fraud review of UTRs) - Contact you for account/support and **product emails** (setup, how Path and Kite work, trial reminders). Each marketing/product email includes an unsubscribe link. Password-reset mail is transactional and may still send. We do **not** sell your personal data. We do **not** use your portfolio to train third-party AI models outside tools you explicitly use inside the product. ## 5. Sharing We share data only with: - **Infrastructure providers** (e.g. Google Cloud) that host the app and database under our project - **Payment rails you use** (UPI apps / banks) — payment happens on their apps; we store only the UTR you submit - **Zerodha** when you complete Kite OAuth We do not share data for advertising networks. ## 6. Your rights (DPDP-oriented) Subject to applicable law (including India’s Digital Personal Data Protection Act, 2023, where it applies), you may: - **Access** — use **Export my data** in Account - **Correct** — edit profile / portfolio in-app - **Erase** — use **Delete account** (irreversible; removes portfolio, tokens, history for that account) - **Withdraw consent** — stop using the service and delete your account To exercise rights offline, email the support address with the same email as your account. ## 7. Retention - Active accounts: retained while the account exists - Deleted accounts: removed from the live database promptly; backups (GCS object versions) may retain encrypted copies for a limited operational window - Logs: short operational retention - Auth sessions: expire automatically (sliding idle window + absolute max); revoked rows are deleted ## 7a. Cookies and similar technologies pTracker uses a **necessary first-party session cookie** only: | Name | Purpose | Duration | Essential? | |------|---------|----------|------------| | `ptracker_s` | Authenticated session (opaque id) | ~7 days idle / max ~30 days | Yes — required to stay signed in | - Not used for advertising or third-party tracking - No portfolio figures or PII are written into the cookie value beyond the opaque token - Clearing site cookies or using **Log out** ends the session ## 8. Children pTracker is not directed at children under 18. Do not create an account if you are under 18. ## 9. International processing Servers may run in regions chosen by our cloud provider (currently US multi-region endpoints for Cloud Run). By using the service you acknowledge cross-border processing for hosting. ## 10. Changes We may update this policy for product or legal reasons. Material changes will be reflected by the “Last updated” date and, where practical, an in-app notice. ## 11. Contact Questions about privacy: use the support email shown in the app footer / upgrade section.