Privacy Policy

Last updated: 26 September 2026

This policy explains what personal data FinSharpe Private Limited ("FinSharpe", "we", "us") collects when you use the FinSharpe mobile app or the FinSharpe web app, why, who it goes to, how long it is kept, and the rights you have under India's Digital Personal Data Protection Act, 2023 (the "DPDP Act"). For the purposes of the DPDP Act, we are the Data Fiduciary and you are the Data Principal.

FinSharpe Private Limited (CIN U66190PN2021PTC201064) is registered with the Securities and Exchange Board of India (SEBI) as an Investment Adviser, registration number INA000018489, and is enlisted with BSE Administration and Supervision Limited under BASL2075. Registered office: 506 Seasons Business Square, Aundh, Pune 411007.


1. The short version

  • You can browse Home, Discover and IPO Watch without an account. While you browse as a guest, the app sends us no account or device identifier for you.
  • To chat, connect your investments or run reports, you create an account with your name, email and a password.
  • What you type into chat is answered by AI models from OpenAI, Anthropic and Google. Every request to those models goes through our AI routing provider, OpenRouter, which sends it only to services that keep no copy of it once they have answered and do not train on it — today Microsoft Azure, Google Cloud and Amazon Web Services. One exception: when our data tools search company filings, prospectuses or their own catalogue, a short search text written from your question goes directly to OpenAI, which does not train on it and may keep it for up to 30 days (section 2.2). Our AI hosting and monitoring provider (LangChain / LangSmith) keeps your conversations so you can return to them. Some of these providers process data outside India.
  • If you connect your investments, your financial data comes to us through MoneyOne (OneMoney), an RBI-licensed Account Aggregator, only with your consent. We do not keep a separate copy of your holdings on our servers; the mobile app keeps a copy on your phone so your portfolio opens quickly, and a browser you used with an earlier version of the web app may still hold one (section 3). If you ask about your portfolio in chat, the holdings are saved with that conversation, and copies can stay in our AI monitoring records for up to 180 days (section 2.3).
  • You can withdraw consent for any connection at any time, and you can delete your account.
  • We do not sell your data and the app shows no advertising.

2. What we collect, and why

2.1 Account

Data Why Where it is kept
Name, email address To create and identify your account, and to email you a 6-digit verification code Our database (AWS, Mumbai region)
Password To sign you in. We store only a one-way bcrypt hash, never the password itself Our database
Verification code To confirm you own the email address. Stored only as a hash; it expires after 10 minutes Our database
Session tokens To keep you signed in. Access tokens last 15 minutes; refresh tokens last 7 days and change every time they are used. We store refresh tokens only as hashes Our database; on your phone in the Android Keystore / iOS Keychain
Account role and credit balance To decide which features your account can use, and to charge and show you credits (section 2.4) Our database

Verification codes are delivered by Amazon Web Services Simple Email Service (Mumbai region), which receives your email address and the code.

2.2 Chat

When you use chat we process:

  • the messages you send, including any images or spreadsheet files you attach;
  • the answers, tool results and reports generated for you;
  • which AI model you picked for each conversation;
  • if you ask about your own portfolio, the holdings you have connected (section 2.3).

Why: to answer your questions, keep your conversation history so you can return to it, check that answers are grounded in the data they cite, suggest follow-up questions, and screen messages for content we cannot help with (for example, requests that include someone's PAN, Aadhaar or bank account numbers).

Who receives it:

Recipient What they receive Purpose
OpenRouter, Inc., United States (every conversation) Everything in the next four rows, on its way to the AI model Routing each request to an AI model. OpenRouter does not keep the content of requests or answers. It keeps a record of each request without its content (for example, how much text was processed)
The AI model you pick — from OpenAI, Anthropic or Google (Gemini). "Auto" picks one of them for you Your conversation and attachments, and a summary of your holdings if you ask about your portfolio Generating the answer
Gemini (Google) (every conversation, whichever model you pick) Your latest message, and up to 400 characters of each of a few earlier messages Screening the message before it is answered
Gemini (Google) (every conversation) The conversation Suggesting follow-up questions and checking answers against their sources
An OpenAI embedding model, through OpenRouter (most conversations) A short search text written from your question, converted to a numerical representation ("embedding") Choosing which data tools can answer it
LangChain, Inc. (LangSmith / LangGraph Platform), United States Your conversations and the steps taken to answer them Hosting the chat service, storing conversation history, and monitoring quality and errors
Our data-tool servers (hosted on Railway, Singapore) The inputs the AI passes to a tool — for example a list of holdings when you ask for a portfolio report. They are not told who you are Fetching market data, filings and analytics, and rendering reports
OpenAI, United States, directly and not through OpenRouter (when a data tool searches filings, prospectuses or its own catalogue) A short search text the AI writes from your question. OpenAI is not told who you are Turning the search text into an embedding so the tool can find matching passages or data. OpenAI does not train on it and may keep it for up to 30 days to check for misuse
Google, if you use Hear Output in the mobile app on an Android phone The text of the answer you ask to hear Reading the answer aloud. The app asks your phone for Google's Indian English voice. Depending on your phone, that voice may run on the phone itself, and then the text stays there, or on Google's servers, and then the text is sent to Google to be turned into speech

Where the AI models run. OpenRouter sends each request only to a service it classifies as zero data retention: one that keeps no copy of the request or the answer once it has responded, and does not train on it. Today that means Microsoft Azure for OpenAI's models (including the embedding model that chooses data tools), Google Cloud (Vertex AI) for Gemini, and Amazon Web Services (Bedrock) or Google Cloud (Vertex AI) for Anthropic's Claude; requests sent through OpenRouter do not go to OpenAI or Anthropic themselves. These services may hold part of a request in memory for a short time so that a follow-up is processed faster; they do not store it. If OpenRouter's list of zero-data-retention services changes, a request may go to another service on that list, never to one outside it. OpenRouter may also sort a small sample of requests by topic for its public usage statistics; it does this without linking them to us or to you, and does not keep the text.

Searches by our data tools. One kind of request does not go through OpenRouter. When one of our data tools searches company filings, IPO prospectuses or its own list of data sources, it sends the search text — a short query the AI writes from your question — directly to OpenAI in the United States, to turn it into an embedding. OpenAI is not told who you are. Under OpenAI's terms for its API, it does not use the text to train its models, and it may keep it for up to 30 days to check for misuse, or longer where the law requires.

These providers process data on their own infrastructure, some of it outside India (see section 5). None of the AI model providers uses your data to train its models.

Push notification text. If you allow notifications, the notification that tells you an answer is ready shows the first 48 characters of your question. That text passes through Google Firebase Cloud Messaging to reach your phone. The notification is marked private: if your phone's lock screen is set to hide sensitive notification content, it shows only that FinSharpe has a notification until you unlock the phone. If your lock screen is set to show all content, the question is visible there. You can change this in your phone's notification settings, or turn off FinSharpe's notifications altogether.

2.3 Connected investments (RBI Account Aggregator)

FinSharpe is a Financial Information User on India's Account Aggregator network, regulated by the Reserve Bank of India. We use MoneyOne (OneMoney) as the Account Aggregator.

What happens when you connect:

  1. You enter your mobile number and PAN in the app. We pass them to MoneyOne so it can find your accounts. We keep your mobile number on the consent record (below); we do not store your PAN on our servers.
  2. MoneyOne shows you, on its own page, exactly what is being requested: the type of data, the purpose, how often it can be fetched, and how long the consent lasts. You approve or reject it there. The app never sees your OneMoney login.
  3. With your approval, the institutions that hold your data — depositories and registrars such as CDSL, NSDL, KFintech and CAMS, and your bank if you connect a bank account — send it through MoneyOne.

The data can include, depending on what you connect: holdings (ISIN, security or scheme name, units, price and value), mutual-fund folio numbers and transactions, SIPs, bank account type, masked account number, branch, IFSC, balance and transactions, and account holder details such as holder name, KYC status and nominee.

Why we use it: to show your portfolio and net worth, analyse allocation, returns, risk and concentration, detect SIPs, answer your questions about your portfolio in chat, and generate the alerts and reports you ask for. We do not use it for anything you have not consented to, and we do not use it to lend to you or to sell you products.

What we keep, and where:

Data Where How long
Consent record: consent ID, data type, created and expiry dates, your mobile number and name Our database Until you revoke the consent or delete your account
Your financial data No separate copy on our servers. It is fetched through MoneyOne when the app asks for it and passed through our servers to your phone or browser. Holdings fetched to answer a chat question are held in our server's memory for up to 3 minutes, so that one answer fetches them once. Holdings you send for analysis are processed and not saved —
Holdings fetched to answer a chat question Saved with that conversation, by our chat hosting provider (LangChain). Copies can also appear in our AI monitoring records (LangSmith) With the conversation (section 6). Monitoring records: up to 180 days, and not removed when the conversation or your account is deleted
A copy of your financial data On your phone, in the app's private storage Until you sign out or your session expires, you revoke that connection, or you uninstall the app
A copy of your financial data saved by an earlier version of the web app, if you connected your investments there In your browser's storage for this site Until you clear this site's data in your browser. Signing out, deleting your account or revoking that connection does not remove it, and the web app no longer saves a new copy (section 3)

Your portfolio in chat. If you ask about your own portfolio in chat, we fetch your connected holdings through MoneyOne at that moment, give the AI model a summary of them (section 2.2), and save the full list with that conversation so the app can show it. It is deleted with the conversation. Copies can also appear in our AI monitoring records (LangSmith), which we keep for up to 180 days and which are not removed when the conversation or your account is deleted. Holdings you type or upload into chat yourself are handled as chat content (section 2.2), not under the Account Aggregator consent.

Consent terms. Our consent requests follow the Account Aggregator fair-use template for wealth management and advisory services (Sahamati template CT004). Under that template, a consent is for providing wealth management and advisory services, lasts at most 1 year, lets data be fetched at most 31 times a month, and covers at most 20 years of history for securities and mutual funds and 13 months for other accounts such as bank deposits. MoneyOne shows you the exact values, including how long we may keep the data, before you approve. A consent ends on its own when its term is over, and no more data can be fetched after that.

Revoking consent. In the app, open Portfolio, then the connection, and choose to disconnect it. We ask MoneyOne to revoke the consent, delete our consent record, and remove the copy on your phone. You can also revoke consents directly in the OneMoney app or website. Revoking stops future data fetches; it does not affect analysis we have already shown you.

2.4 Credits and reports

Research reports are paid for with credits, and chat is measured in credits; our Terms of Use say when chat answers use them. We add credits to your account — when you sign up, and when you ask us for more. Nothing is sold in the app.

We keep a credit history for your account: an entry for every chat turn, with the credits it cost (or, before chat answers use credits, would have cost) and the conversation it belongs to; every report you ran; and every time credits were added to or returned to your account — each with the date. Where the app shows you this history, it shows it in credits only. Behind each chat entry we also keep our own cost figures for it (which AI models ran and how much text they processed), to check what our providers bill us. The app never shows those figures. We use the credit history to charge credits, to show you your usage where the app offers it, and to check our providers' bills; not to profile you, and not for advertising.

Asking for credits. You can ask us for more credits by email. Where the app offers Request credits, tapping it opens a message in your own email app, addressed to info@finsharpe.com and prefilled with your account email, your balance, and your phone platform and app version. You decide whether to send it; the app itself sends nothing.

Reports. When you run a research report, we record the report and the run's results, so you can open it again; the credits it cost appear in your credit history. If you create a share link for a report, anyone with the link can open that report, and we count how many times it is viewed. You can revoke a share link at any time.

2.5 Notifications

  • Answer-ready notifications (optional). If you allow them, we store your phone's Firebase Cloud Messaging token, its platform (Android or iOS) and your user ID, so we can tell you when a long answer is ready. We delete this registration when you sign out, when the token stops working, or when another account signs in on the same phone. See section 2.2 for the text a notification carries.
  • IPO reminders. These are scheduled on your phone only. The issue name, symbol and closing time stay on the device; nothing is sent to us.

We ask for notification permission only when you first use a feature that needs it.

2.6 Guests

While you browse without an account, the app sends no account identifier with its requests. Google Firebase, which delivers notifications, may create an installation identifier and a notification token on your phone when the app starts. They stay between your phone and Google: the app sends the token to us only once you are signed in (section 2.5).

2.7 Crash reports and usage analytics

We do not collect crash reports or usage analytics. If we add them, we will update this policy, and the store privacy declarations, before we start collecting them. The one record we keep of how much you use chat and reports is your credit history (section 2.4), which exists so that credits can be charged and shown to you.

2.8 Server logs

Our servers keep operational logs to run and secure the service. They can contain your user ID, consent IDs, the IP address a request came from (for example, when we limit repeated sign-in attempts), the app version and phone platform the app reports, and, if an email fails to send, your email address. We do not log your password, verification codes or financial data. Logs are kept for no more than 90 days.

2.9 Connecting other AI apps

You can connect another AI app — for example, an AI assistant that supports connectors — to FinSharpe's data tools by signing in with your FinSharpe account. A connection works only while access has been granted to your account. When you use one, we keep:

  • the access granted to your account, with when it was requested, approved and expires;
  • a record of each sign-in token issued to the connected app, and when it was last used;
  • a record of each call the app makes to our data tools: which tool, the inputs it sent (which can include holdings or other details you gave that app), when, how long it took and whether it worked, together with your account ID;
  • running totals of how much the access is used, per day and per tool, with the stocks and funds it asked about stored only in scrambled (hashed) form.

We use these to run and secure the connection, to decide how much use it allows, and to understand demand. Our data-tool servers know which account a connected app's call is for. What you type into the other AI app is covered by that app's own privacy policy: we receive only its calls to our tools. When you delete your account, we delete the access and its tokens and remove your account ID from the call records; the records and the usage totals are kept (section 6).

3. What stays on your phone or in your browser

Data Stored Removed when
Session tokens, your email, a session security key Android Keystore / iOS Keychain You sign out, or your session expires
Mobile number and PAN you last entered to connect an account, and any connection in progress Android Keystore / iOS Keychain You sign out; an unfinished connection is dropped after 24 hours
Push registration ID Android Keystore / iOS Keychain You sign out
A copy of your connected financial data App-private storage You sign out or your session expires, you revoke that connection, or you uninstall the app
Company filing PDFs you opened from chat App-private storage, up to 100 MB You sign out
IPO reminders, and whether you have already been asked about notifications Android Keystore / iOS Keychain You cancel the reminder (past reminders are cleared automatically), or uninstall the app. These belong to the phone, not your account
Your theme and AI model choices, a cached list of public strategies App-private storage You uninstall the app
Report PDFs you share The phone's temporary folder The operating system clears it

Uninstalling the app removes all of the above from the phone. None of it is included in Android cloud backups or device-to-device transfers: the app is excluded from both, so nothing it stores is copied to your Google Drive or carried to a new phone.

On the web. If you use the FinSharpe web app, your browser keeps: sign-in cookies (your session tokens, which the page's scripts cannot read, and a cookie with your user ID, name and account role so the page can show who is signed in); your chat preferences, saved watchlists and similar settings; and, while you connect an account, a note of the connection in progress, which the browser drops when you close the tab. Signing out removes the sign-in cookies. An earlier version of the web app also saved in your browser a copy of the financial data from investments you connected there, so your portfolio opened quickly, and a record of each connection (including its consent ID and your mobile number). The web app no longer saves either. It removes those connection records when you open Import there, or when you delete your account in that browser. The copy of your financial data can stay until you clear this site's data in your browser: signing out, deleting your account or revoking the connection does not remove it. The web app is hosted by Vercel, which passes your requests to our servers.

4. Who we share data with

We share personal data only with the service providers named in section 2, to run the features you use:

  • AI routing, model and hosting providers: OpenRouter; Microsoft (Azure), Google (Google Cloud) and Amazon Web Services (Bedrock), which run the AI models from OpenAI, Anthropic and Google; OpenAI, directly, for our data tools' searches; LangChain (LangSmith).
  • Account Aggregator: MoneyOne (OneMoney), and through it the financial institutions you approve.
  • Infrastructure: Amazon Web Services (database and email, Mumbai), Railway (data-tool servers, Singapore), Google Firebase (notification delivery), Vercel (the web app, and the web address that hands you back to the app after an Account Aggregator consent).
  • Reading answers aloud: Google, when the mobile app reads an answer aloud with Google's online voice (section 2.2).

We may also disclose data when required by law, a court order or a regulator (including SEBI and RBI), or to protect the rights and safety of our users and the service.

We do not sell personal data, and we do not share it for advertising.

Links to other sites. News articles and filings open the publisher's own site, which has its own privacy policy. Videos play inside the app through YouTube's privacy-enhanced embedded player (youtube-nocookie.com), and video thumbnails load directly from YouTube; YouTube's own privacy policy covers both. Versions of the mobile app released before in-app playback open videos on YouTube itself.

5. Where your data is processed

Our database and email service are in India (AWS Mumbai). Our data-tool servers run in Singapore (Railway). Our application servers — which handle sign-in, chat, reports and credits, and pass your Account Aggregator data from MoneyOne to the app — run in the United States (LangChain), as do our AI routing (OpenRouter), the web app (Vercel) and our data tools' searches (OpenAI). The AI models run in data centres that OpenRouter chooses for each request, in the United States, the European Union or other regions (Microsoft Azure, Google Cloud and Amazon Web Services). When the mobile app reads an answer aloud with Google's online voice, Google turns the text into speech on its own servers, which may be outside India. Under section 16 of the DPDP Act, personal data may be transferred outside India except to countries the Government of India restricts by notification; we will not transfer data to such a country.

6. How long we keep data

Data Kept for
Your account Until you delete it
Unverified sign-ups 7 days, then deleted
Chat conversations, including any holdings saved with them Deleted automatically within about 30 days of the last time the conversation was used; sooner if you delete your account
Your requests and answers at OpenRouter and at the services that run the AI models Not kept once the answer is sent (section 2.2)
Search text our data tools send to OpenAI (section 2.2) Up to 30 days at OpenAI, unless the law requires it to be kept longer
Records of how chat answers were produced, in our AI monitoring tool (LangSmith), which can include your messages and any holdings fetched for them No more than 180 days, then deleted automatically. Deleting a conversation or your account does not remove them sooner
Records of data-tool calls Kept. Calls made while answering your chats are recorded without your account ID. Calls made by other AI apps you connected (section 2.9) carry your account ID until you delete your account, when we remove it
Access you gave other AI apps, and their sign-in tokens (section 2.9) Until you delete your account
Usage totals for other AI apps you connected (section 2.9) Kept, without your account ID
Consent records Until you revoke the consent or delete your account
Reports you ran and their results As long as your account exists
Your credit history Kept for as long as your account exists. When you delete your account, we remove your account ID from it
Push registrations Until you sign out or the token stops working
Server logs No more than 90 days
Backups of our database Overwritten within 2 days

When you delete your account, we delete your personal data as described in how to delete your account. A few records outlive it: records of data-tool calls, usage totals for any AI apps you connected, and your credit history, all without your account ID; AI monitoring records and server logs, until they expire on the schedule above; search text held by OpenAI, for up to 30 days; and database backups, for up to 2 days. A copy of your financial data that an earlier version of the web app saved in a browser can stay there until you clear it (section 3).

7. Your rights

Under the DPDP Act you have the right to:

  • Access — ask what personal data we hold about you, how we use it, and who we have shared it with (section 11).
  • Correct, complete, update or erase your personal data (section 12). You can delete your account yourself; see how to delete your account.
  • Withdraw consent at any time, as easily as you gave it (section 6(4)). Withdrawing consent does not affect processing that already happened. For Account Aggregator data, revoke the connection as described in section 2.3.
  • Grievance redressal — have your complaint handled by our Grievance Officer (section 13).
  • Nominate someone to exercise these rights if you die or become incapable (section 14).

To use any of these rights, email info@finsharpe.com from the address on your account, or write to the Grievance Officer below. We will confirm who you are before acting, and respond within 21 days of receiving your request.

If you are not satisfied with our response, you may complain to the Data Protection Board of India.

8. Security

  • All traffic between the app and our servers is encrypted in transit (HTTPS).
  • Sign-in credentials on your phone are kept in the Android Keystore / iOS Keychain. Every signed-in request also carries a per-session security key, so a stolen token alone cannot be replayed.
  • The copy of your financial data sits in the app's private storage, which only this app can read, on top of the encryption your phone already applies to everything it holds. We do not encrypt that file a second time. It is removed when you sign out, and it is never copied into a backup or a device transfer.
  • Passwords, verification codes and refresh tokens are stored on our servers only as hashes.
  • Using a refresh token twice signs out every session on the account.

No system is perfectly secure. If a personal data breach affects you, we will inform you and the Data Protection Board of India as the DPDP Act requires.

9. Children

FinSharpe is for people aged 18 and over. We do not knowingly process the personal data of children. If you believe a child has created an account, contact us and we will delete it.

10. Changes to this policy

We will update this policy when what we collect or how we use it changes — for example, before we add crash reporting or analytics. We will change the date at the top and, for material changes, tell you in the app or by email before the change applies.

11. Contact and grievances

Support: info@finsharpe.com

Grievance Officer
Mr. Sabir Bakir Jana
FinSharpe Private Limited, 506 Seasons Business Square, Aundh, Pune 411007
Email: info@finsharpe.com · Phone: +91 7028004994

Complaints about our investment advisory services follow the grievance redressal process in our Investor Charter:

  1. Write to us. Contact the Grievance Officer above. We respond within 21 days of receiving your complaint.
  2. Escalate to SEBI. If you are not satisfied, lodge the complaint on SCORES 2.0 (https://scores.sebi.gov.in), where it is reviewed first by the designated body (IAASB) and then by SEBI, or email it to the IAASB.
  3. Online dispute resolution. If it is still unresolved, take it to SmartODR (https://smartodr.in) for online conciliation or arbitration.

You can also write to the Office of Investor Assistance and Education, Securities and Exchange Board of India, SEBI Bhavan, Plot No. C4-A, G Block, Bandra Kurla Complex, Bandra (E), Mumbai 400051.

Get Free access to our Data Driven

Research Articles & Market Updates.

Company Name: FinSharpe Private Limited.

SEBI Registered Investment Advisor Reg No: INA000018489 (Validity: Oct 13, 2023 - Perpetual).

BASL ID: BASL2075

CIN: U66190PN2021PTC201064.

Address– 506 Seasons Business Square, Aundh, Pune 411007 Phone – 9607795005.

Principal Officer: Mr. Rohan Borawake, Contact No: 91 9923411966, Email: info@finsharpe.com Compliance Officer: Mr. Sabir Bakir Jana, Contact No: 91 7028004994, Email: info@finsharpe.com Grievance Officer: Mr. Sabir Bakir Jana, Contact No: 91 7028004994, Email: info@finsharpe.com

Corresponding Local SEBI Office : SEBI Bhavan Plot No.C4-A, G Block, Bandra Kurla Complex, Bandra (E), Mumbai - 400 051.

For grievances - https://smartodr.in/

Standard warning “Investment in securities market are subject to market risks. Read all the related documents carefully before investing.”

Disclaimer “Registration granted by SEBI, membership of BASL and certification from NISM in no way guarantee performance of the intermediary or provide any assurance of returns to investors”

FinSharpe Pvt. Ltd. All Rights Reserved

Get Free access to our Data Driven

Research Articles & Market Updates

Company Name: FinSharpe Private Limited.

SEBI Registered Investment Advisor Reg No: INA000018489 (Validity: Oct 13, 2023 - Perpetual).

BASL ID BASL2075

CIN: U66190PN2021PTC201064.

Address– 506 Seasons Business Square, Aundh, Pune 411007 Phone – 9607795005.

Principal Officer: Mr. Rohan Borawake, Contact No: 91 9923411966, Email: info@finsharpe.com Compliance Officer: Mr. Sabir Bakir Jana, Contact No: 91 7028004994, Email: info@finsharpe.com Grievance Officer: Mr. Sabir Bakir Jana, Contact No: 91 7028004994, Email: info@finsharpe.com

Corresponding Local SEBI Office : SEBI Bhavan Plot No.C4-A, G Block, Bandra Kurla Complex, Bandra (E), Mumbai - 400 051.

For grievances - https://smartodr.in/

Standard warning “Investment in securities market are subject to market risks. Read all the related documents carefully before investing.”

Disclaimer “Registration granted by SEBI, membership of BASL and certification from NISM in no way guarantee performance of the intermediary or provide any assurance of returns to investors”

© FinSharpe Pvt. Ltd. All Rights Reserved