Privacy Policy

Last updated: 20 June 2026

LakshaFin ("we", "us", "the App") is a read-only mutual fund portfolio dashboard. This policy explains what data we collect, why, how we process it, and your rights under the Digital Personal Data Protection Act, 2023 ("DPDP Act").

1. Data Fiduciary

LakshaFin operates as a data fiduciary under the DPDP Act. For queries, contact: privacy@lakshafin.com

2. What We Collect

Data Purpose Storage
Device ID (SHA-256 hash) Consent tracking, session identity Cloudflare D1 (APAC)
Consent record DPDP compliance proof Cloudflare D1 (APAC)
Portfolio analytics (aggregated) Dashboard rendering Cloudflare D1 (APAC)
Audit logs CERT-In compliance Cloudflare KV + D1 (180-day TTL)

3. What We Do NOT Collect

4. Account Aggregator Data

When you link mutual fund accounts via Account Aggregator (Anumati / Perfios as TSP), LakshaFin acts as a Financial Information User (FIU) under the RBI Account Aggregator framework.

5. CAS Upload

If you upload a Consolidated Account Statement (CAS), the file is parsed on-device within the app. Raw file contents are not transmitted to our servers. Only computed portfolio analytics are stored.

6. Data Storage & Security

7. AI Analytics (Laksha AI)

Laksha AI runs on Cloudflare Workers AI (Meta Llama 3.2 1B) at the edge. Your portfolio context is sent to the model in a stateless request — no conversation history is stored, no training occurs on your data, and responses are generated in real-time without persistence.

8. CERT-In Compliance

Audit logs (consent events, data access events, security events) are retained for 180 days in compliance with CERT-In directives. Logs contain hashed identifiers only — no raw personal data.

9. Your Rights Under DPDP Act

As a Data Principal, you have the right to:

10. Children's Data

LakshaFin is not intended for individuals under the age of 18. We do not knowingly collect data from minors. If you believe a minor has provided data, contact us for immediate deletion.

11. Web Sandbox Mode

The web version at lakshafin.com operates in sandbox mode with mock data only. No real financial data is processed or stored in the web environment. Live features require the secure Android app.

12. Third-Party Services

Service Provider Purpose Data Shared
Account Aggregator Anumati (Perfios) Consent-based MF data fetch User-approved consent artifacts only
Edge Compute & Storage Cloudflare Workers, D1, KV, AI Hashed IDs, computed analytics

13. Changes to This Policy

We may update this policy to reflect changes in our practices or legal requirements. Material changes will be communicated via the App's consent screen, requiring re-consent.

14. Contact

For privacy-related queries, DSAR requests, or grievances: