Privacy Policy

Last updated: August 28, 2026 · Version 2.3

1. Introduction

Welcome to Artha. We are committed to protecting your personal information and your right to privacy. Artha Terminal (the "Platform") is a financial intelligence tool operated by Quantrast Technologies Private Limited. It examines and explains a portfolio that you already hold with a licensed broker. It is not a broking platform: it places no orders, holds no money, and holds no securities. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use it. Please read it carefully. If you do not agree with its terms, please do not access the Platform.

The short version, which the rest of this policy expands on: we read your portfolio so that we can show you an analysis of it. We use it for nothing else. We do not sell your personal data or your portfolio data to anybody, we do not trade on it, and we do not use it to make any decision on your behalf.

2. Information We Collect

2.1 Personal Information

We collect personal information that you voluntarily provide to us when you:

  • Register for an account (email address)
  • Complete your profile (display name, username, biography, avatar, trading preferences)
  • Connect your Demat/broker accounts
  • Contact us for support
  • Subscribe to newsletters or notifications

Account registration uses a passwordless email link. We do not ask for or store a password, and we do not require a phone number to create an account.

2.2 Financial Information

When you connect a broker account, we read the data that broker releases to us under the authorisation you granted on the broker's own website. That may include:

  • Portfolio holdings and positions
  • Order and trade history for the account
  • Account balances
  • The account identifiers the broker returns with that data

We use this data only to compute and display your analysis on the Platform. We place no orders and issue no instruction to your broker, and the broker decides both the scope of the access it grants and when it expires. You can end that access at any time by disconnecting the broker in Settings.

You sign in on your broker's own site. Your broker password, PIN, and second factor are never transmitted to, or stored by, us. The access token the broker issues is encrypted with AES-256-GCM at rest.

2.3 Usage Information

We automatically collect certain information when you use the Platform:

  • Device information (IP address, browser type, operating system)
  • Usage data (pages viewed, features accessed, time spent)
  • Location data (based on IP address)
  • Cookies and similar tracking technologies

2.4 Third-Party Data

We receive information from third-party services such as market data providers, broker APIs, and authentication services (e.g., Google, Apple) if you choose to use these services.

3. How We Use Your Information

We use your information to:

  • Provide, operate, and maintain the Platform
  • Compute and display the analysis of the portfolio you have connected
  • Send you price alerts and notifications based on your preferences
  • Provide customer support and respond to your inquiries
  • Analyze usage patterns to improve our services
  • Detect and prevent fraud, security breaches, and technical issues
  • Comply with legal obligations and regulatory requirements
  • Send you marketing communications (with your consent)
  • Personalize your experience on the Platform

We also state what we do not use it for. We do not sell it. We do not trade on it or act on it in any market. We do not use your holdings to make a decision on your behalf, and we do not use them to produce advice or a recommendation for you, because we do not provide advice or recommendations at all. We do not share your portfolio data with advertisers, and we do not use it to profile you for advertising.

4. How We Share Your Information

We may share your information in the following situations:

4.1 Service Providers

We share information with third-party service providers who perform services on our behalf. These providers act as Data Processors — they process your information only on our instructions, only for the purpose described, and they are not permitted to use it for their own purposes. We use services for:

  • Application hosting, delivery, and database storage
  • Authentication and session management
  • Caching and rate limiting
  • Product analytics, but only after you consent
  • Error monitoring and application logging
  • Transactional and notification email
  • Scheduled background processing
  • Artificial intelligence features. Content sent to these services is filtered first, and we never send them your broker credentials.

You have the right to ask us who these services are. Under Section 7 you may request the identities of every service with which we have shared your personal data, and we will tell you.

4.2 Broker Partners

We exchange the minimum information necessary with a broker you have connected, so that we can identify your authorisation and retrieve your portfolio data. Each broker integration runs under a partner integration arrangement between Quantrast and that broker, over the broker's own published interface and the broker's own authorisation flow. We send that broker no instruction to buy or sell anything. Your relationship with the broker is separate and is governed by the broker's own terms and privacy policy.

4.3 AI Assistants You Connect

If you connect a third-party AI assistant to your Artha account, the data covered by the permissions you approved is sent to the provider that operates that assistant, at your direction and only when your assistant asks for it. This is the one case where your data goes to a company that is not acting on our instructions. Section 17 describes it in full.

4.4 Legal Obligations

We may disclose your information if required by law or in response to valid requests by public authorities (e.g., SEBI, court orders, law enforcement).

4.5 Business Transfers

If we are involved in a merger, acquisition, or asset sale, your information may be transferred. We will provide notice before your information is transferred and becomes subject to a different privacy policy.

We never sell your personal information to third parties.

5. Data Security

We implement appropriate technical and organizational security measures to protect your information:

  • TLS encryption for all data in transit
  • AES-256-GCM encryption for broker credentials stored at rest
  • Passwordless email-link sign-in, so there is no password for us to store or for an attacker to steal
  • Row-level security on every database table, so a user's records are only readable by that user
  • Continuous observability — application logging (Axiom), error and exception monitoring (Sentry), and platform monitoring (Vercel) — which we review for anomalies
  • Rate limiting and input validation on every application programming interface route
  • Secrets held in environment configuration, never in our source code repository

However, no method of transmission over the Internet is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

6. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. When we no longer need your information, we will securely delete or anonymize it. Transaction records may be retained for up to 7 years to comply with financial regulations.

7. Your Rights as a Data Principal

Under the Digital Personal Data Protection Act, 2023, you are a Data Principal and you have the following rights:

  • Right to access: Obtain a summary of the personal data we process about you, the processing activities we carry out, and the identities of other Data Fiduciaries and Data Processors with whom we have shared it
  • Right to correction and completion: Have inaccurate or misleading data corrected, and incomplete data completed or updated
  • Right to erasure: Have your personal data erased, unless retention is required to comply with a law
  • Right to grievance redressal: Raise a complaint with us about how we handle your data, using the process in Section 15 below
  • Right to nominate: Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity
  • Right to withdraw consent: Withdraw any consent you have given, at any time, as easily as you gave it

7.1 How to exercise these rights

Some rights you can exercise yourself, directly in the Platform:

  • Correction — edit your profile details in Settings at any time
  • Withdraw analytics consent — decline or clear analytics consent from your browser at any time; we then stop collecting product analytics about you
  • Withdraw broker access — disconnect a broker in Settings. This immediately deactivates the connection and stops all further access to that broker account. The stored credentials are retained in deactivated form so that holdings history you have already synced remains intact; email us if you want them erased outright
  • Disconnect an AI assistant. Open Settings, then API Keys, and disconnect it. Artha stops answering that assistant from its next request onwards, and we clear the approval held by our authentication provider so the assistant cannot renew its access. Section 17.4 sets out exactly what this does
  • Marketing opt-out — use the unsubscribe link in any newsletter, or turn off notification preferences in Settings
  • Export your data — download your portfolio and trade history from Settings

7.2 Deleting your account

To have your account and personal data erased, email us with:

To: team@arthaterminal.com

Subject: Deletion request

Include: the email address you signed up with

Send it from that same address where you can, so we can verify the request is yours. We will confirm and complete the deletion within 30 days, and we do not charge a fee. Erasure is permanent — your profile, holdings history, watchlists, alerts, and posts are removed and cannot be restored. We may retain the minimum records we are required to keep by law, and we will tell you if that applies to you.

Use the same address for access and nomination requests. We will verify that the request comes from you and respond within 30 days, free of charge.

The Act also requires you, as a Data Principal, to provide authentic information and not to raise false or frivolous complaints.

8. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to:

  • Essential Cookies: Required for the Platform to function (login sessions, security)
  • Analytics Cookies: Help us understand how you use the Platform
  • Functional Cookies: Remember your preferences (theme, language)
  • Marketing Cookies: Track effectiveness of advertising campaigns

Analytics are off until you consent. We show a consent notice on your first visit, and we do not collect product analytics unless you accept it. We also honour your browser's Do Not Track setting. Essential cookies needed to keep you signed in cannot be switched off, because the Platform cannot function without them. Our Cookie Policy explains each category in detail.

9. Third-Party Links

The Platform may contain links to third-party websites (broker portals, news sources, etc.). We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal information.

10. Children's Privacy

The Platform is intended only for individuals aged 18 and above, and we do not knowingly collect the personal data of children. The Digital Personal Data Protection Act, 2023 treats anyone under 18 as a child, and requires verifiable parental consent before their data is processed. It also prohibits tracking, behavioural monitoring, and targeted advertising directed at children — we do none of these. If you believe a child has registered or that we hold a child's data, contact us and we will delete it.

11. International Data Transfers

Some of the service providers listed in Section 4.1 store or process data on servers outside India. The Digital Personal Data Protection Act, 2023 permits transfer of personal data outside India except to countries the Central Government restricts by notification. Where a transfer happens, we remain accountable for your data, we contract with providers who commit to appropriate safeguards, and we share only what the provider needs to deliver its service. If the Government restricts a country we rely on, we will move that processing.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. We encourage you to review this Privacy Policy periodically. Your continued use of the Platform after changes are posted constitutes your acceptance of the updated policy.

13. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

Entity: Quantrast Technologies Private Limited (operator of Artha Terminal), a DPIIT-recognised startup (DIPP272705)

Email: team@arthaterminal.com

Social: linktr.ee/arthaterminal

14. Our Role Under the DPDP Act

Quantrast Technologies Private Limited is a Data Fiduciary under the Digital Personal Data Protection Act, 2023. That means we decide the purpose and means of processing your personal data, and we are accountable for it — including for the processing carried out by the service providers listed in Section 4.1, who act as Data Processors on our behalf.

We also comply with the Information Technology Act, 2000 and the rules made under it.

14.1 The consent we rely on

We process your personal data on the basis of your consent, which you give when you create an account and accept these terms, and separately when you connect a broker or accept analytics. That consent is limited to the purposes set out in Section 3 of this Policy, and we collect only the data needed for those purposes.

You may withdraw your consent at any time, and withdrawing it is as easy as giving it — see Section 7.1. Withdrawing consent does not make our earlier processing unlawful. If you withdraw consent for something the Platform needs in order to work, we may no longer be able to provide that part of the service.

15. Grievance Redressal

If you have a complaint about how we handle your personal data, or you are unhappy with how we answered a request under Section 7, you can raise a grievance with us. Write to our Grievance Officer:

Grievance Officer, Quantrast Technologies Private Limited

Email: team@arthaterminal.com (subject line: "Grievance — Data Protection")

We will acknowledge your grievance and respond within 30 days. Exhausting this process is your first step — if you remain dissatisfied after we have responded, or if we fail to respond in time, you may complain to the Data Protection Board of India under the Digital Personal Data Protection Act, 2023.

16. Personal Data Breaches

If a personal data breach affects your data, we will notify you and the Data Protection Board of India as required by the Digital Personal Data Protection Act, 2023. Our notice to you will describe, in plain language, what happened, the data involved, the likely consequences, what we have done to contain it, and what you can do to protect yourself. We maintain an internal process for detecting, escalating, and recording such incidents.

17. AI Assistants and the Artha MCP Server

Artha runs a read-only server that speaks the Model Context Protocol, an open standard for connecting an AI assistant to a source of data. You may use it to connect an assistant such as Claude, Codex, or Cursor to your own Artha account. This section explains what that sends, to whom, and how to stop it.

17.1 What Connecting Does

Nothing is connected by default. A connection begins in your assistant, and it does not exist until you sign in to Artha and approve it on a consent screen.

Once connected, your assistant can call a fixed set of read-only tools against your account. When it calls one, the data covered by the permissions you approved leaves Artha and reaches the provider that operates that assistant. From that moment it is held by them and governed by their privacy policy and terms, not ours.

AI assistants are non-deterministic and can be wrong. Artha does not control or monitor them. Once your data reaches your AI provider it is governed by their terms, not ours.

Four limits apply to every connection:

  • Artha sends nothing on its own. Data moves only when your assistant calls a tool
  • Every tool reads. None writes. An assistant connected this way cannot place, change, or cancel an order, and cannot alter anything in your Artha account
  • Your broker credentials are never returned. The tool that lists your broker connections returns the broker name, the connection status, and the times of connection and last sync, and nothing else
  • We do not receive your conversation with the assistant. We see the tool calls made against your account, not your prompts and not the assistant's replies

17.2 The Permissions You Approve

There are three permissions, called scopes. You approve each one on the consent screen before any access is granted:

  • Portfolio. Read your holdings, portfolio value, and risk metrics
  • Watchlist. Read your watchlists and price alerts
  • Family. Read your family's combined exposure, for members who allowed it

A tool whose scope you did not approve is not offered to your assistant and cannot be called. We resolve what an assistant may read from the grant we stored when you approved it, never from what the assistant asks for, so an assistant cannot widen its own access. Where you have approved no scopes at all, the connection reaches one tool: your basic Artha profile, which returns your display name, your username, your account identifier, and the date you joined.

17.3 Family Data

The family permission is the only one that can reach figures belonging to somebody other than you, so it carries its own rules:

  • A member's figures are included only where that member has separately allowed AI assistants to include their portfolio. A member who has not allowed it contributes to nothing
  • Family tools return household aggregates only. No tool can name a member or list what an individual member holds
  • Where fewer than two consenting members are somebody other than the person whose assistant is asking, we withhold the breakdown by symbol and by sector, and the tool states why. Household totals remain, because a total is what each member agreed to contribute. An itemised list at that point would be one identifiable person's holdings
  • Any member can withdraw that permission on the family page in Artha, and their figures are excluded from the next result

17.4 Seeing and Revoking a Connection

Settings, under API Keys, lists every assistant connected to your account: the client name recorded when you approved it, the scopes you granted, when you granted them, and when it last read data. Each one has a disconnect control. Disconnecting does three things:

  • It marks your grant revoked. From that assistant's next request onwards Artha answers none of the permitted tools. We hold no cache of a grant, so this takes effect on the next request rather than after a delay
  • It clears the record of your approval held by our authentication provider. That invalidates the sessions and refresh tokens issued to that assistant, so it cannot renew its access, and it means reconnecting shows you the consent screen again
  • It does not reach inside your assistant. If the assistant still lists Artha as a connector, remove it there as well

One honest limit. An access token already issued to that assistant remains valid at our authentication provider until it expires, and we cannot cancel it there. It can no longer read anything from Artha, because the grant behind it is gone. If clearing the approval fails for any reason, the revocation at Artha still stands and the assistant still reads nothing.

17.5 What We Record About Connections

We store connection metadata: the client name recorded at consent, the scopes granted, when the grant was made, when it was last used, and when it was revoked. This is what the list in Settings is built from.

We also record product telemetry about how the feature is used: that a consent screen was shown, approved, or denied; that a tool was called, which tool it was, which permission it needed, whether it succeeded, how long it took, and whether it returned anything at all; that a connection was revoked; and that a token was refused, with the reason and nothing else.

This telemetry carries no holdings, no quantities, and no monetary amounts. Whether a call returned anything is recorded as a yes or a no, never as a count and never as a value.

Individual tool calls are also written to the application logs described in Section 5, recording the tool, your account identifier, the permissions in force, and how long the call took. Those log lines carry no holdings and no amounts either, and they are retained under Section 6.

Ready to get started?

Sign in to track your portfolio, chat with AskWarren, and follow the market end to end.

Sign in to Artha Terminal

© 2026 Artha Terminal. All rights reserved.

We use analytics cookies to understand how you use Artha and improve your experience. No data is sold to third parties.