Privacy Policy
Last updated: 20 June 2026
LakshaFin ("we", "us", "the App") is a read-only mutual fund portfolio dashboard. This policy explains what data we collect, why, how we process it, and your rights under the Digital Personal Data Protection Act, 2023 ("DPDP Act").
1. Data Fiduciary
LakshaFin operates as a data fiduciary under the DPDP Act. For queries, contact: privacy@lakshafin.com
2. What We Collect
| Data | Purpose | Storage |
|---|---|---|
| Device ID (SHA-256 hash) | Consent tracking, session identity | Cloudflare D1 (APAC) |
| Consent record | DPDP compliance proof | Cloudflare D1 (APAC) |
| Portfolio analytics (aggregated) | Dashboard rendering | Cloudflare D1 (APAC) |
| Audit logs | CERT-In compliance | Cloudflare KV + D1 (180-day TTL) |
3. What We Do NOT Collect
- Name, email, phone number, or any direct personal identifier
- Passwords or authentication credentials
- Location data, contacts, or device sensors
- Browsing history or cross-app tracking data
4. Account Aggregator Data
When you link mutual fund accounts via Account Aggregator (Anumati / Perfios as TSP), LakshaFin acts as a Financial Information User (FIU) under the RBI Account Aggregator framework.
- Consent-based: Data is fetched only after your explicit OTP-verified consent on the AA consent screen.
- Zero raw data retention: Raw financial payloads from FIPs (CAMS, KFintech) are processed in-memory and immediately discarded. Only computed analytics (ratings, scores, aggregate values) are stored.
- Read-only: LakshaFin cannot initiate transactions, transfers, or modifications to your accounts.
- Revocable: You can revoke AA consent at any time through the App or via the AA's consent dashboard.
5. CAS Upload
If you upload a Consolidated Account Statement (CAS), the file is parsed on-device within the app. Raw file contents are not transmitted to our servers. Only computed portfolio analytics are stored.
6. Data Storage & Security
- Region: All data stored on Cloudflare's APAC edge infrastructure (D1 database, KV store). Indian requests are routed to the nearest Indian or APAC point of presence.
- Encryption: Data encrypted in transit (TLS 1.3) and at rest (Cloudflare managed encryption).
- Hashing: All personal identifiers (device IDs) are SHA-256 hashed before storage. We cannot reverse the hash to identify you.
- No third-party sharing: We do not sell, share, or transfer your data to any third party for advertising, marketing, or profiling.
7. AI Analytics (Laksha AI)
Laksha AI runs on Cloudflare Workers AI (Meta Llama 3.2 1B) at the edge. Your portfolio context is sent to the model in a stateless request — no conversation history is stored, no training occurs on your data, and responses are generated in real-time without persistence.
8. CERT-In Compliance
Audit logs (consent events, data access events, security events) are retained for 180 days in compliance with CERT-In directives. Logs contain hashed identifiers only — no raw personal data.
9. Your Rights Under DPDP Act
As a Data Principal, you have the right to:
- Access: Request a copy of all data associated with your device via the Data Subject Access Request (DSAR) export feature in the App.
- Correction: Request correction of inaccurate data.
- Erasure: Revoke consent and delete all stored data instantly via the App's consent management screen. Deletion is immediate and irreversible.
- Grievance Redressal: Contact our Grievance Officer at privacy@lakshafin.com. We will respond within 7 days.
10. Children's Data
LakshaFin is not intended for individuals under the age of 18. We do not knowingly collect data from minors. If you believe a minor has provided data, contact us for immediate deletion.
11. Web Sandbox Mode
The web version at lakshafin.com operates in sandbox mode with mock data only. No real financial data is processed or stored in the web environment. Live features require the secure Android app.
12. Third-Party Services
| Service | Provider | Purpose | Data Shared |
|---|---|---|---|
| Account Aggregator | Anumati (Perfios) | Consent-based MF data fetch | User-approved consent artifacts only |
| Edge Compute & Storage | Cloudflare | Workers, D1, KV, AI | Hashed IDs, computed analytics |
13. Changes to This Policy
We may update this policy to reflect changes in our practices or legal requirements. Material changes will be communicated via the App's consent screen, requiring re-consent.
14. Contact
For privacy-related queries, DSAR requests, or grievances:
- Email: privacy@lakshafin.com
- In-App: More → Privacy → DSAR Export / Revoke Consent