Clartha - Privacy Policy

Last Updated: July 22, 2026

This Privacy Policy explains how Clartha collects, uses, stores, shares, and protects personal data when you use our AI investment research and portfolio intelligence platform.

Clartha is designed for informational research workflows. We do not sell personal data, execute trades, or request bank-account access.

1. Data We Collect

Account and profile data

Name, email address, phone number if provided, profile preferences, subscription status, authentication metadata, and support communications.

Research and AI interaction data

Prompts, uploaded portfolio files, watchlists, saved portfolios, conversation history, feedback, issue reports, and generated research outputs.

Broker and portfolio data

If you connect a broker or upload holdings, we process read-only holdings snapshots such as symbols, names, quantities, average prices, valuations, and sync metadata.

We do not place trades, move funds, request trading permissions, or access bank accounts.

Device, usage, and security data

IP address, browser and device metadata, log events, feature usage, rate-limit events, telemetry, error diagnostics, and security audit information.

Billing data

Subscription plan, invoice identifiers, payment status, and billing metadata. Full card or payment credentials are handled by our payment processor and are not stored by Clartha.

2. How We Use Data

  • Operate accounts, authentication, subscriptions, invoices, and support workflows.
  • Generate AI research, summaries, portfolio intelligence, watchlist context, and market explanations.
  • Maintain security, prevent misuse, enforce limits, debug failures, and protect the platform.
  • Improve product quality, reliability, search relevance, and user experience.
  • Comply with legal, tax, accounting, regulatory, and dispute-resolution obligations.
  • Send product updates, newsletters, and promotional communications only where you have opted in; you can withdraw that consent at any time.

3. Legal Basis and Consent

We process personal data based on your consent where required and for certain permitted legitimate uses under Section 7 of India’s Digital Personal Data Protection Act, 2023 (DPDP Act), including providing requested services, maintaining security, preventing fraud or misuse, and complying with law.

Consent is specific, informed, and limited to personal data necessary for the stated purpose. You may withdraw consent as easily as you gave it through My Account → Privacy & Security where that control is available, or by contacting the Grievance Officer. Withdrawal does not affect processing already carried out lawfully before withdrawal and may affect features that require the relevant data.

4. Marketing Communications

We send marketing emails, newsletters, product promotions, and similar communications only after obtaining a separate opt-in consent. Marketing communications are distinct from essential account, security, billing, and transactional service emails, which may be sent while your account or requested service is active.

Every marketing email will include a one-click unsubscribe option. You may also manage or withdraw marketing consent through My Account where available or by contacting the Grievance Officer. We do not send marketing communications to children under 18.

5. Children’s Data

Clartha is intended for people aged 18 and above. We do not knowingly process children’s personal data without verifiable consent from a parent or lawful guardian as required by the DPDP Act. We do not knowingly track, behaviourally monitor, or serve targeted advertising to children. If you believe a child has provided personal data to us, contact the Grievance Officer so we can review and take appropriate action.

6. AI Processing

Clartha uses automated systems and AI models to process your queries, portfolio context, uploaded files, public-market data, and interaction history so the platform can produce research outputs.

Important boundary

  • AI outputs are informational research and may be incomplete, delayed, or inaccurate.
  • AI outputs are not investment, tax, legal, or financial advice.
  • You are responsible for verifying outputs before relying on them.

7. Vendors and Processors

We use vendors and processors to provide hosting, databases, authentication, AI processing, analytics, payments, email, storage, monitoring, and broker connectivity. These providers process data only for platform operations, security, support, payment, and legal-compliance purposes.

Broker connections and payment flows may be subject to the relevant broker, account aggregator, payment, or data provider terms and privacy notices.

8. Sharing and Disclosure

  • We do not sell personal data.
  • We share data with service providers and processors needed to operate Clartha.
  • We may disclose data for legal compliance, fraud prevention, security investigations, dispute handling, or business transfers.
  • We may share aggregated or de-identified information that does not identify you.

9. Cross-Border Processing

Clartha may process and store data in India, the United States, and other jurisdictions where our vendors, infrastructure, AI processors, or support providers operate. When data is transferred across borders, we use contractual, technical, and organizational safeguards appropriate to the service and data category.

10. Retention

  • Account profile data is retained while your account is active and as needed for support, billing, tax, legal, and security records.
  • AI conversations, portfolio context, watchlists, feedback, and issue reports are retained until deletion is requested or the data is no longer needed for the product purpose.
  • Broker tokens and read-only sync metadata are retained while the broker connection is active, then removed or disabled after disconnect according to operational and legal requirements.
  • Billing, security, audit, fraud-prevention, and legal records may be retained longer where required by law or legitimate business needs.

11. Security

We use access controls, encryption in transit, restricted production access, logging, monitoring, and operational safeguards. No internet service can be guaranteed completely secure, so you should use strong credentials and protect your account access. If a personal data breach occurs, we will notify the Data Protection Board of India and each affected user as required by Section 8(6) of the DPDP Act.

12. Your Rights

Under applicable law, including the DPDP Act, you may request a summary of your personal data and how it is being processed, correction, completion, updating, or erasure of inaccurate or unnecessary data, and withdrawal of consent where processing is consent-based. You may also raise a grievance about our processing and nominate another person to exercise rights on your behalf where permitted.

Requests are handled by contacting the Grievance Officer; the current backend does not provide self-service export or account deletion controls. We will verify identity as reasonably necessary, respond within 30 days or the period required by applicable law, and may retain limited data where necessary for security, legal, tax, billing, fraud-prevention, regulatory, or dispute purposes.

13. Cookies and Similar Technologies

Strictly necessary cookies and local storage support authentication, security, account sessions, and core product functionality and do not require consent. Analytics and other non-essential cookies are used only with consent and can be managed or withdrawn through the available cookie controls or your browser settings. Disabling required storage may affect platform functionality.

14. Changes to This Policy

We may update this Policy as the platform, vendors, legal requirements, or operational practices change. The fixed “Last Updated” date above shows when this version became effective.

15. Grievance Officer and Contact

For privacy questions, requests, or grievances, contact our Grievance Officer: Nishant Jain at nishant@clartha.com. We will acknowledge your grievance within 30 days and provide a response within the timeline required by applicable law. If you are not satisfied, you may complain to the Data Protection Board of India.