Privacy Policy
What we collect, why we collect it, and what we do not do with it. Written from what the code actually does.
Last updated 17 August 2026
The short version
- You can use the screener, fund pages, comparisons and every calculator without an account and without giving us anything.
- We run no advertising, no analytics trackers and no third-party cookies. There is no Google Analytics, no pixel, no ad network on this site.
- We never sell or rent personal data, and we do not share it with fund houses or distributors.
- Calculator inputs are computed in your browser and are not sent to us.
- Deleting your account deletes your data — account, watchlist, preferences and imported portfolios.
What we collect
If you create an account:
- your email address and a one-way hash of your password (we never store the password itself);
- optionally a display name, phone number and avatar colour, if you fill them in;
- your watchlist, saved screens and table/column preferences;
- the planner and profile answers you choose to give — risk appetite, investment horizon, age, monthly income and expenses, existing corpus, emergency-fund and ELSS preferences — used only to generate your plan on /plan;
- whether you opted in to email alerts, and when a digest was last sent to you.
If you import a portfolio: the holdings data in your Consolidated Account Statement — folio numbers, AMC and scheme names, ISINs, units, NAVs, amounts and transaction dates, plus the investor name and statement period printed on it. This is the most sensitive data on the site and it exists only to compute your holdings, returns and capital gains.
Your PAN is not stored. The CAS parser uses the “PAN:” line only as a landmark to locate the investor name in the document; the number itself is never written to the database. The uploaded PDF is parsed in memory and is not retained after import.
For everyone, account or not:
- server request logs — URL, timestamp, HTTP method, status and IP address — kept short-term for debugging, security and abuse prevention;
- aggregate traffic counters (page hit counts, and a probabilistic unique-visitor estimate derived from IP) used only to see how busy the site is;
- login attempt counters, keyed to your email and address, used to rate-limit brute-force attempts.
What stays in your browser
Theme, watchlist for signed-out visitors, screener state, chart and column preferences and dismissed notices are stored in your browser’s localStorage under wealthticker:* keys. They never reach our servers, and clearing your browser data removes them.
Every calculator on the site runs entirely in your browser. The amounts, rates and tenures you type into a SIP, tax, retirement or XIRR calculator are not transmitted to us.
Cookies
One cookie, and only after you sign in: wealthticker_session, which holds a random session token so the site knows you are logged in. It is HTTP-only, expires, and is deleted when you sign out.
There are no advertising, tracking or analytics cookies on this site, and no third-party cookies. We do not track you across other websites.
Why we use it
- To run the features you asked for — your watchlist, your plan, your portfolio, your alerts.
- To keep accounts secure — session management, login rate-limiting, abuse prevention.
- To keep the site working — diagnosing errors and understanding load.
- To email you — verification and password-reset codes, and the fund-event digest if you opted in.
We do not profile you for advertising, and we do not use your portfolio to decide what any other user is shown.
Who we share it with
We do not sell personal data. We share it only with the providers needed to operate the service:
- Email delivery (Resend) — receives your email address and the message body when we send you a verification code, a reset code or an alert digest.
- Google Gemini — if you use the Ask AI search box, the question you typed is sent to Google’s API to be translated into a screener query. Only your question text is sent: no account details, no portfolio, no identifiers. Don’t type anything into it you wouldn’t send to a third party.
- Hosting and infrastructure — the servers and databases the site runs on process this data on our instructions.
We may also disclose data where the law requires it, or where it is necessary to investigate abuse or protect the service.
Data we fetch from third parties — AMFI, mfapi.in, AMC disclosures, news feeds, market data — is public fund data and is fetched by a background worker on a schedule. It carries nothing about you; those sources never learn that you looked at a fund.
How long we keep it
- Account data, watchlist, preferences and portfolios: until you delete them or delete your account.
- Sessions: until they expire or you sign out; expired sessions are purged automatically.
- Request logs: short-lived and rotated; they are for debugging, not a record of you.
- Aggregate traffic counters: retained as counts, with no ability to reconstruct an individual’s browsing.
Your choices and rights
You can use almost the entire site without an account. If you have one, your settings page lets you view and change your details, change your password, edit the profile answers behind your plan, and turn email alerts on or off. An imported portfolio can be deleted from the portfolio page itself.
Deleting your account deletes your data. The delete option in settings removes your account row and, with it, your sessions, watchlist, preferences and every imported portfolio, folio and transaction. It is immediate and not reversible.
Under India’s Digital Personal Data Protection Act, 2023 you have the right to access, correct and erase your personal data, to withdraw consent, and to raise a grievance. The settings page covers most of this directly; for anything it doesn’t, write to support@wealthticker.in and we will respond within a reasonable period.
Security
Passwords are stored only as salted one-way hashes. Session tokens are stored hashed, never in the clear. Traffic is served over HTTPS, databases are not exposed to the public internet, and login attempts are rate-limited.
No system is perfectly secure, and we cannot guarantee against every attack. If you find a security problem, please report it to support@wealthticker.in rather than disclosing it publicly.
Children
The site is not directed at children, and accounts are intended for people old enough to contract under Indian law. We do not knowingly collect data from children; if you believe a child has created an account, write to us and we will remove it.
Changes to this policy
When this policy changes, the date at the top of the page changes with it. If a change materially affects how your personal data is used, we will make that clear on the site rather than relying on you re-reading this page.
Contact
Privacy questions, data requests and grievances: support@wealthticker.in. Include the email address on your account so we can find the right records.