Privacy Policy
Effective Date: July 30, 2026
Oalgo — a product of Kshonee Private Limited
Scope: Oalgo is available exclusively to residents of India, accessing the Platform from within India. This Privacy Policy is written for that launch phase and is governed by the Digital Personal Data Protection Act, 2023. It is not a global privacy policy.
1. Introduction
This Privacy Policy explains how Kshonee Private Limited ("Company," "we," "us," or "our"), the operator of Oalgo (the "Platform," "Service"), collects, uses, discloses, stores, and protects your personal data when you visit our website, create an account, or use the Platform.
This Policy applies to all users of the Platform who are residents of India, accessing the Platform from within India, consistent with the geographic restriction described in our Terms of Service.
By creating an account or otherwise using the Platform, you agree to the collection and use of your information as described in this Policy. If you do not agree, please do not use the Platform.
This Policy should be read together with our Terms of Service.
2. What Data We Collect
2.1 Account Data
When you register, we collect your full name, email address, phone number, and country of residence. Your password is stored only in hashed form and is never accessible to us in plain text.
At signup, you confirm: "I confirm I am 18 years of age or older." We do not collect your date of birth. See Section 12 for our age-verification approach.
2.2 Strategy and Research Data
Your plain-language strategy descriptions, the AI-converted strategy logic, strategy names and parameters, and their saved status are stored on our servers. Strategy descriptions are also sent to a third-party AI provider for conversion into structured logic — see Section 7 below.
Your strategies are your intellectual property. We do not claim ownership of them, and we treat them as confidential — they are not shared with, or visible to, any other user. See our Terms of Service, Section 8, for the full ownership and confidentiality framework.
We do not keep a version history of your edits. Changes you make while analyzing or tweaking a strategy exist only in your browser session; each time you explicitly save, we store a named snapshot. Deleting a strategy is an immediate, hard delete — though backtest and forward-test results generated from that strategy persist independently, subject to the retention rules in Section 8.
2.3 Backtest and Forward-Test Data
For every backtest or forward test you run, we store the input parameters, the trade-by-trade simulation log, summary results, and the run timestamp. These are simulations only — no real order is placed and no real money is involved at any stage.
The number of stored runs is capped by your subscription tier; you may pin a limited number of runs on any tier to exempt them from automatic deletion when the cap is reached, and you may delete any run manually at any time.
2.4 Watchlists, Screens, and Alert Settings
We store the watchlists you build, the screens and scanners you configure, the alert conditions you define, and your chosen delivery channel for those alerts (for example, email address or messaging handle), together with a log of alerts sent to you.
2.5 Billing and Payment Data
We collect your subscription tier, billing state, transaction IDs, and invoice records. Your card, UPI, or other payment method details are collected and processed directly by our payment processors and are never stored on our servers.
We use third-party payment processors and may add or change processors over time. If you wish to know the identity of the specific payment processor handling your transaction, you may request this at any time — see Section 14.
2.6 Technical Data
Automatically collected when you use the Platform: IP address, device type, browser type and version, operating system, session identifiers, referring URL, and city-level location derived from your IP address.
2.7 Usage Data
Automatically collected: pages and screens visited, features used, click patterns, error events, and time spent per feature.
2.8 Session Recording
Separately from the usage data above, and only if you accept Analytics cookies, we use a third-party session-recording tool that records your on-screen activity within the Platform — the pages you view, your mouse movement and clicks, scrolling, and what you type into non-sensitive fields — and replays it to us as a video-like session. We use this to find bugs and understand where the Platform is confusing.
Sensitive fields are masked before recording. Your password is masked at the point of capture, so its contents are never recorded and never reach the recording tool — including when you use the show/hide toggle to reveal it on screen.
Session recording is off by default and is placed only after you accept the Analytics category. If you reject it, no session recording takes place. You can change this at any time via the cookie settings link in our footer.
2.9 Communication Data
If you contact support, use in-app chat (if enabled), or otherwise communicate with us, we retain the content of that communication and the date/time it occurred.
2.10 Marketing and Consent Data
We record your marketing opt-in/opt-out status, the timestamp of that choice, email campaign engagement (opens, clicks), and UTM/referral source data for attribution.
2.11 Cookie Data
See Section 16 (Cookies and Tracking).
3. How We Collect Your Data
Directly from you: account registration, the strategy builder, watchlists and alert configuration, support messages, and marketing preferences.
Automatically, as you use the Platform: technical data, usage data, cookies, and similar tracking technologies.
From third parties: our payment processors (transaction confirmations, billing status) and our AI provider(s) (the converted strategy output returned to us). Market data is obtained from data providers but is not personal data and is not specific to you.
4. Why We Process Your Data
We process personal data only where we have a lawful basis to do so, in accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011:
Data Purpose Legal Basis
Account data Create and manage your account Contract performance
Account data Fraud prevention, security Legitimate interest
Strategy data Build and evaluate your strategy Contract performance
Strategy data (sent to AI provider) AI-assisted conversion into structured logic Contract performance
Backtest and forward-test data Run and display simulation results Contract performance
Watchlists, screens, alert settings Deliver the features you configure Contract performance
Billing data Process payment, issue GST invoice Contract performance + legal obligation
Billing records Tax and accounting compliance Legal obligation
Technical data Security monitoring, fraud prevention Legitimate interest
Usage data Platform improvement, debugging, analytics Legitimate interest
Communication data Customer support Contract performance
Marketing data Marketing emails (where you've opted in) Consent
Marketing data Consent record-keeping Legal obligation
Cookie data (essential) Platform functionality Contract performance
Cookie data (functional) Remembering your preferences Consent
Cookie data (analytics) Usage analytics Consent
Cookie data (marketing/advertising) Campaign measurement and retargeting Consent
5. We Do Not Access Your Exchange, Broker, or Bank Accounts
As presently offered, the Platform does not ask for, collect, store, or use credentials, API keys, or access tokens for any exchange, broker, bank, or other financial account.
What this means in practice today:
We hold no key to any account of yours. There is no exchange connection, no API key vault, and no stored access token anywhere in the Platform.
We cannot see your portfolio, balances, positions, or trade history. If you trade, we have no visibility into it.
We cannot place, modify, or cancel an order. The Platform does not execute, route, or facilitate any transaction.
A breach of the Platform cannot expose your trading accounts, because we hold nothing that would give access to them.
Do not give these credentials to anyone claiming to be us. Any request you receive today purporting to come from Oalgo for exchange, broker, or banking credentials is fraudulent. Please report it to us immediately at grievance@oalgo.trade.
If this changes, you will know first. The Platform is under active development. If we introduce a feature that requires any external account credential, this Policy and our Terms of Service will be updated and you will be notified before that feature becomes available. It will never appear unannounced, and no credential will ever be collected without your explicit, separate action.
6. We Do Not Hold Your Funds
The Company never holds, receives, transfers, controls, or has custody of any user funds or assets, in any form, and has no ability to do so. The only money that passes between you and us is your subscription payment, handled by our payment processors.
7. AI Processing of Your Strategy Descriptions
When you describe a trading idea in plain language, that description is sent to a third-party AI provider to be converted into structured strategy logic.
What is sent: only the strategy description text itself. We do not send your account data, billing data, or any other personal data to the AI provider.
Who processes it: your strategy description is processed by one or more third-party AI providers, and our choice of provider may change over time as our AI-assisted features evolve. If you wish to know the identity of the specific AI provider(s) your strategy text has been shared with, you may request this at any time — see Section 14.
Data processing agreements. We sign a data processing agreement with each AI provider before sending any production user data to them. With that agreement in place, your strategy descriptions are not used by our AI providers to train their own models.
Where the AI output goes. The converted strategy logic returned by the AI provider is stored as part of your strategy's saved snapshot on our servers, subject to the same retention rules as the rest of your strategy data (Section 8).
Important guidance for you
Please do not include personal information — your name, financial account details, account numbers, or any other sensitive personal data — in your strategy descriptions. The Company is not responsible for personal information you choose to include in a strategy description that gets sent to our AI provider.
What the AI does and does not do. The AI in Build/Plot converts your own description into structured logic. It does not decide what to trade or when, it does not place any order, and it has no connection to any market or account. Everything it produces is information for you to review and evaluate. Full detail is in our Terms of Service, Section 7.
8. How Long We Keep Your Data
We do not keep personal data longer than necessary for the purpose it was collected, in accordance with the Digital Personal Data Protection Act, 2023.
Data Category Retention
Account data For the duration of your account, plus 3 years after deletion, to allow for legal disputes
Strategy data (the strategy object) Deleted immediately on your request; associated backtest and forward-test results persist independently under the caps described in Section 2.3
Backtest and forward-test results While your account is active, capped by subscription tier as described in Section 2.3; purged within 30 days of account deletion (processed internally immediately)
Watchlists, screens, and alert settings For the duration of your account; deleted immediately on your request
Alert delivery logs 12 months on a rolling basis
Billing records 8 years, for GST and tax compliance
Technical and usage data 12 months on a rolling basis
Communication data 3 years, for dispute-resolution purposes
Marketing consent records 6 years after you withdraw consent, to preserve proof of your consent history
Cookie data Per the lifespan of each cookie — see our Cookie Policy
When you delete your account, this Policy commits to a 30-day purge window; in practice our systems process the deletion immediately, with the 30-day window serving as your grace period to reverse the decision and our compliance buffer. Billing records are retained separately for the period stated above regardless of account deletion, as required by law.
9. Who We Share Your Data With
We do not sell your data
We do not sell your personal data to anyone, for any purpose.
We share data with the following categories of third party, each bound by confidentiality and data processing obligations:
Category What's Shared Why
Cloud infrastructure providers All platform data Hosting our servers and services (all data stored within India — see Section 10)
AI service providers Strategy description text only Converting your strategy into structured logic (Section 7)
Payment processors Name, email, billing state, transaction IDs Processing your subscription payment
Analytics provider Technical data, usage data, IP address (anonymized) Understanding how the Platform is used, improving it
Session-recording provider Recording of your on-screen activity, with passwords masked out — only if you accept Analytics cookies Finding bugs and usability problems (Section 2.8)
Advertising platforms Technical data, usage data, online identifiers — only if and when advertising is introduced, and only if you accept Marketing cookies Measuring campaign performance (Section 17)
Alert delivery providers Your chosen delivery address and the alert content Delivering the alerts you configure
Customer support tooling Name, email, communication content Managing and responding to your support requests
Legal advisors, regulators, law enforcement Relevant data, as required Legal compliance and dispute resolution
A successor entity All data Only in the event of a merger, acquisition, or sale of the Company's business
We identify our service providers by category rather than by name in this Policy, so that the categories remain accurate as individual vendors change. You have the right to obtain the identities of the specific third parties with whom your personal data has been shared — you can request this at any time using the data request process in Section 14, and we will respond within 30 days.
10. Where Your Data Is Stored
All personal data is currently stored and processed on servers located within India. We do not currently transfer your data outside India.
If this changes in the future — for example, as part of global expansion, use of a content delivery network, or backup infrastructure outside India — we will update this Policy before making that change, and will only transfer data to a jurisdiction approved under the Digital Personal Data Protection Act's cross-border transfer framework once that framework is finalized by the Government of India.
11. How We Protect Your Data
We maintain technical and organizational security measures designed to protect your personal data, including encryption of data at rest and in transit and restricted internal access.
We do not publish the specific encryption algorithm or key-management architecture we use in this Policy. This is deliberate, not an omission: naming the exact technical implementation publicly provides no benefit to you and only helps a would-be attacker.
Structurally, the most sensitive category of data in this industry — credentials to your trading accounts — does not exist on our systems at all, because we never collect it (Section 5).
No security measure is completely foolproof, and we cannot guarantee absolute security against unauthorized access, hacking, or data breaches by third parties. You play an important role in your own security too: use a strong, unique password, enable two-factor authentication if offered, and never share your login credentials with anyone.
12. Children's Data
18+ only
The Platform is intended for users 18 years of age and older only. We do not knowingly collect personal data from anyone under 18.
At signup, you confirm you are 18 or older via checkbox — we do not collect a date of birth. Paid subscriptions additionally require a valid payment instrument, which in India is issued only following the provider's own identity verification, giving a second practical barrier.
We are aware that the Digital Personal Data Protection Rules, 2025 define "verifiable" parental consent for minors concretely — for example, via government-backed digital identity tokens. That framework governs platforms that admit users under 18 with parental consent. It does not apply to Oalgo, because we do not offer a pathway for anyone under 18 to use the Platform at all, with or without parental consent. If we discover that an account belongs to someone under 18, that account will be terminated and the associated personal data deleted.
13. If There Is a Data Breach
In the event of a personal data breach, we will notify the Data Protection Board of India and all affected users without undue delay, and in any case within 72 hours of becoming aware of the breach, in accordance with the Digital Personal Data Protection Act, 2023. Affected users will be told the nature of the breach, the types of data affected, and the steps they can take to protect themselves.
Separately, and on a faster timeline, we report qualifying cybersecurity incidents to the Indian Computer Emergency Response Team (CERT-In) within 6 hours of detection, as required under the CERT-In Directions, 2022. This 6-hour clock and the 72-hour DPDP clock run in parallel, not sequentially.
Our internal incident response plan — covering detection, containment, regulator notification, and user notification — is an internal operational document, not published here, consistent with standard practice among comparable platforms.
14. Your Rights
You have the following rights over your personal data, all exercisable free of charge:
Right What It Means How to Exercise It Response Time
Access Request a copy of all data we hold about you In-app data request button (account settings) 30 days
Know who your data was shared with Obtain the identities of the third parties with whom your personal data has been shared In-app data request button (account settings) 30 days
Correction Request correction of inaccurate data Self-serve via your profile settings 30 days
Erasure Request deletion of your data In-app account deletion (account settings) Processed immediately; 30-day policy window
Data portability Receive your data in a machine-readable format Research data: in-app CSV/XLSX export (self-serve, no waiting period). Full personal data: in-app data request button Research data: immediate. Full data: 30 days
Withdraw consent Withdraw marketing consent at any time Unsubscribe link in any marketing email, or in-app settings Immediate
Grievance redressal File a complaint with us Email our Grievance Officer (Section 15) Acknowledged within 48 hours, resolved within 30 days
Complain to the regulator Escalate to the Data Protection Board of India Via the Data Protection Board's official channels Governed by the Board's own process
Your full personal data request is rate-limited to once every 30 days.
15. Grievance Officer and Privacy Contact
In accordance with the Consumer Protection Act, 2019 and the Digital Personal Data Protection Act, 2023, we have designated a Grievance Officer to receive and act on privacy-related complaints and requests:
Grievance Officer
Vardhan Netawate, Founder \& CEO
Email: grievance@oalgo.trade
Address: 102, Gurukrupa Apt, Lokmanya Nagar, Thane, 400606
We are not currently a "Significant Data Fiduciary" under the Digital Personal Data Protection Act, 2023 — the Government of India has not yet published the thresholds that would trigger that designation, and we do not expect to meet them at launch. If our status changes, we will appoint a Data Protection Officer and update this Section accordingly. Until then, our Grievance Officer serves as your privacy contact.
16. Cookies and Tracking
We use cookies and similar technologies, categorized as follows:
Category Purpose Your Choice
Strictly necessary Session management, login state, security (CSRF protection) Always on — essential to the Platform working
Functional Remembering your preferences (e.g., language, theme) You can manage this in cookie settings
Analytics Understanding how the Platform is used, with IP anonymization enabled. Includes session recording — see Section 2.8 Requires your consent — off by default
Marketing / advertising Measuring how our marketing campaigns perform, if and when advertising is introduced (see Section 17) Requires your consent — off by default
Each of these categories is independently acceptable or rejectable. Accepting one does not accept the others, and rejecting one does not affect your ability to use the Platform.
Cookie consent is managed by us directly, using our own first-party consent system — we do not use a third-party consent management provider, and no external consent vendor receives your data or sets a cookie on your device. When you first visit the Platform, you'll see a banner offering equally prominent options to Accept All, Reject Non-Essential, or Manage Preferences. You can change your choice at any time via the cookie settings link in the footer. Full detail on individual cookies used is available in our separate Cookie Policy.
17. Advertising
We do not currently run advertising or retargeting. No advertising or retargeting technology is placed on the Platform at present, and no data is shared with any advertising platform.
If we introduce advertising in future, this is how it will work. We may use advertising and retargeting technologies — pixels, tags, and similar identifiers placed by third-party advertising platforms — to measure how our marketing campaigns perform and to show you relevant advertising on other websites and platforms.
What would be shared: technical data, usage data, and online identifiers (such as a cookie or advertising ID). We would not share your name, email, strategy content, or research data with any advertising platform.
It would only happen if you accept it
Advertising and retargeting technologies would be placed only after you accept the Marketing category in our cookie consent banner. Marketing is off by default. If you reject it — either individually or by choosing "Reject Non-Essential" — no advertising technology is placed and no data is shared with any advertising platform. You can change your choice at any time using the cookie settings link in our footer; see Section 16.
We identify advertising providers by category rather than by name in this Policy. You have the right to obtain the identities of the specific third parties with whom your personal data has been shared — see Section 14.
18. Your Strategies and Other Users
Currently, all of your strategies, backtests, screens, and research data are private and are not visible to any other user of the Platform.
If we introduce social, marketplace, or sharing features in the future — allowing you to optionally publish a strategy for others to see — this Policy will be updated first, and you will be notified of the change before it takes effect. Nothing about your existing strategies will become visible to others without an explicit action on your part.
19. Referral and Rebate Arrangements
The Company may participate in referral or rebate programs with third parties, including exchanges, brokers, and data or service providers, and may receive fees in connection with referrals originating from the Platform or Website. This is disclosed here for transparency, and in more detail in our Terms of Service, Section 6A.
These arrangements do not involve sharing your personal data with any such third party. We do not report individual user activity to any referral partner. If you choose to follow a link and open an account with a third party, your relationship with them is governed by their own terms and privacy policy, not ours.
20. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, services, or applicable law. When we do, we'll post the updated version here and update the "Effective Date" at the top.
For non-material changes — clarifications, formatting, or a change of vendor within a service category already described in this Policy — we'll notify registered users by email around the effective date.
For material changes — anything that changes what data we collect, how we use it, or who we share it with — we'll notify registered users by email before the change takes effect.
Continuing to use the Platform after a change takes effect means you accept the update. If you don't agree, you may stop using the Platform and delete your account.
21. Language
This Privacy Policy is available in English. If you require this Policy in a language listed in the Eighth Schedule of the Constitution of India, please contact us at grievance@oalgo.trade and we will provide it. We plan to publish a Hindi version of this Policy ahead of the Digital Personal Data Protection Act's 13 May 2027 enforcement date.
22. Contact Us
If you have any questions about this Privacy Policy or how we handle your data, contact us at contact@oalgo.trade, or reach our Grievance Officer directly using the details in Section 15.