We do not sell personal information or use it for cross-context behavioral advertising.
The current Schwab connection reads authorized account data and does not place orders.
AI and market-data providers are identified by function, and unavailable evidence is not invented.
Who this policy covers
This Privacy Policy applies to asknaksha.com, the Naksha Finance private-beta application, and related support communications (collectively, the “Service”). “Naksha,” “we,” “us,” and “our” refer to Naksha Finance.
Naksha is currently an invite-only research and decision-support platform for options and futures traders. This policy does not govern the independent privacy practices of a broker, market-data provider, payment processor, AI provider, or external site that you choose to use.
Information we receive
Account and profile information
When you sign in with Google, we receive the Google account identifier, email address, name, and profile image made available by Google. We do not receive your Google password. We use this information to create and secure your Naksha account, administer private-beta access, and communicate about the Service.
Portfolio, research, and workspace information
- Watchlists, saved symbols, scanner settings, saved levels, and display preferences.
- Portfolio snapshots, positions, balances, trade campaigns, fill reviews, notes, and risk-monitor outputs you save or import.
- Consultant questions, research prompts, feedback, and the context needed to answer them.
- Generated scans, reports, source-quality diagnostics, and audit records associated with your workspace.
Device, security, and usage information
We may collect IP address, browser and device details, timestamps, pages or features used, error records, rate-limit events, and security logs. Essential cookies and local storage support authentication, preferences, and safe operation.
Billing information
If paid access is offered, Stripe processes checkout and payment-card information. Naksha may receive your billing email, Stripe customer and subscription identifiers, plan, payment status, and related transaction metadata. Naksha does not receive or store complete payment-card numbers.
Charles Schwab portfolio data
The current Schwab integration is read-only. It can retrieve authorized account identifiers, balances, positions, orders or transactions, and market data for portfolio monitoring and fill review. Naksha does not expose a Schwab order-entry method.
You authorize Schwab directly through Schwab’s OAuth flow. Naksha does not receive your Schwab password. Access and refresh tokens, together with linked-account identifiers, are stored as an encrypted connection payload. Public application responses mask account numbers.
You can disconnect Schwab from Naksha. Disconnecting removes the stored Schwab connection and authorization-state records from Naksha, but it does not automatically delete portfolio snapshots, fill records, or research you previously chose to save. Those records may be managed separately or removed by request.
Why we use information
- Provide authentication, private-beta access, support, and account administration.
- Run scanners, portfolio monitoring, position-management, risk, and research workflows.
- Retrieve and ground AI-assisted explanations in your requested portfolio and market context.
- Maintain source quality, diagnose stale or missing evidence, and prevent unsupported conclusions.
- Protect the Service, enforce usage limits, investigate abuse, and maintain audit records.
- Operate billing and subscription administration when paid plans are enabled.
- Improve reliability, usability, and feature design using aggregated or de-identified patterns where practicable.
For users in jurisdictions that require a legal basis, processing may rely on performance of our agreement, consent, compliance with law, or legitimate interests such as security, support, and product improvement. You may withdraw consent where consent is the applicable basis.
How AI processing works
When you intentionally use an AI-assisted feature, Naksha may send the question and the minimum relevant market, strategy-playbook, portfolio, or position context to an AI model provider. Retrieval-augmented features may first select relevant playbook material from Naksha’s knowledge base. Deterministic rules and evidence gates may validate inputs or candidate packages before an AI model explains them.
Do not enter broker passwords, API secrets, Social Security numbers, payment-card numbers, or information that is not needed for the requested analysis. AI output may be incomplete or incorrect and must be independently evaluated.
Naksha’s automated publisher
Naksha uses an operator-controlled X developer application to publish Naksha’s own morning research graphics and accompanying captions. The app is configured for Read and Write access because posting requires write permission.
- It does not request email addresses from X users.
- It does not request Direct Message permission or read or send Direct Messages.
- It does not invite Naksha users to connect their personal X accounts.
- It does not use browser scraping, stored browser cookies, or simulated clicks to post.
We retain publication status, Post and media identifiers, caption, and operational error details as needed to prevent duplicates and monitor the publisher. X processes the published content under X’s own terms and privacy policy.
Cookies and local storage
Naksha uses essential authentication cookies, including secure HttpOnly session cookies in production, and functional browser storage for preferences and non-sensitive interface state. Disabling essential cookies may prevent sign-in.
Naksha does not currently use third-party advertising cookies, social-media tracking pixels, or cross-site behavioral advertising. If this changes, this policy and any required consent controls will be updated.
Safeguards and storage periods
We use technical and organizational measures appropriate to the Service, including HTTPS/TLS, restricted infrastructure access, secure authentication cookies, application access controls, signed webhook validation, and encrypted storage of Schwab connection credentials. No security method is perfect, and we cannot guarantee absolute security.
We retain information for as long as reasonably necessary to provide the Service, preserve user-requested research and portfolio records, meet legal or contractual duties, resolve disputes, prevent fraud, and maintain security. Retention varies by record and provider. Backups and audit records may remain for a limited period after active deletion.
- Schwab connection credentials remain until disconnection, expiry, or removal.
- Saved portfolios, trade campaigns, and research remain until removed, the account is closed, or a valid deletion request is completed, subject to required exceptions.
- Billing records may be retained as required for tax, accounting, dispute, and fraud-prevention purposes.
Your privacy choices
Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, or objection, and to appeal or complain to a regulator.
- Disconnect Schwab using the Portfolio interface.
- Delete supported watchlists, portfolios, campaigns, and saved records in the Service.
- Request access, correction, or deletion using the contact information below.
- Manage Google authorization through your Google account and Stripe billing through the available billing portal.
California residents may request information about collection, use, and disclosure and may request correction or deletion as applicable. Naksha does not sell personal information or share it for cross-context behavioral advertising. We will not discriminate against you for exercising applicable privacy rights.
Cross-border processing
Naksha and its providers primarily process information in the United States and may process it in other countries where a provider operates. Those countries may have different data-protection laws. Where required, transfers are supported by contractual or other lawful safeguards.
Not intended for children
Naksha is intended only for people who are at least 18 years old. We do not knowingly collect personal information from children. Contact us if you believe a child has provided personal information through the Service.
Updates to this policy
We may update this policy as the private beta, providers, or legal requirements evolve. The effective date and version at the top identify the current policy. Material changes may also be communicated by email or in-product notice when appropriate.
Questions or requests
For privacy questions or rights requests, contact:
Please identify the account email and describe the request. We may need to verify your identity before acting.