Legal

Privacy Policy

We built Kanalyst on a simple belief — your financial data belongs to you. This policy explains exactly what we collect, why we collect it, and what we never do with it.

Last updated May 2026
· Version 2.0
· Applies to Kanalyst web and Android app
On this page
Section 01

What We Collect

Kanalyst collects only the data necessary to provide you with automated financial tracking. Nothing more.

Account information. When you sign up, we collect your name, email address, and authentication credentials. If you sign in with Google, we receive your name and email from Google — we never see your Google password.

Financial identifiers (optional). To unlock password-protected CAS and NPS PDFs, you can optionally provide your PAN number and date of birth in Settings. These are encrypted at rest and used only to derive PDF passwords.

Transaction data. From SMS messages (Android app) or parsed broker emails (web), we extract and store: merchant name, transaction amount, bank name, last 4 digits of account, date and time, and transaction type. Raw SMS text and raw email bodies are never stored.

Portfolio data. From your CAS statements and NPS documents, we store ISIN codes, quantities, NAV values, fund names, and holding values — exactly the information needed to display your portfolio dashboard.

Usage data. Anonymous, aggregated usage statistics to help us improve the product. This data cannot identify you.

Section 02

SMS Data Processing

The Kanalyst Android app requests permission to read SMS messages on your device.

How it works

SMS processing happens locally on your device. Kanalyst uses pattern matching to identify bank transaction messages — all other SMS messages are silently ignored. Only the extracted transaction data (merchant, amount, date) is transmitted to our servers. The raw SMS text is never sent to or stored on our servers.

Section 03

Gmail Access — Limited Use Disclosure

The Kanalyst web application optionally connects to your Gmail account to automatically import your investment portfolio from CAS and NPS statement emails. This section complies with Google's API Services User Data Policy and the Limited Use requirements.

Scope requested. We request gmail.readonly — read-only access. We cannot send emails, delete emails, or make any changes to your Gmail account.

Which senders we access. We search only for emails from these specific financial institutions:

Sender / InstitutionPurposeWhat We Extract
NSDL / nsdl.co.inCAS — equity holdingsISIN, quantity, purchase price, current value
CDSL / cdslstatement.comCAS — equity holdingsISIN, quantity, purchase price, current value
CAMS / camsonline.comMutual fund CASFund name, folio, units, NAV, value
Protean / protean-tinpan.comNPS statementsPRAN, scheme values, XIRR, contributions
What we do
  • Read subject lines and PDF attachments from listed senders only
  • Extract portfolio holding data (ISIN, units, values)
  • Store only extracted portfolio data in your account
  • Encrypt OAuth tokens with AES-256-GCM before storing
  • Allow you to disconnect and revoke access instantly
What we never do
  • Read emails outside the listed financial senders
  • Store raw email bodies or full email content
  • Use Gmail data for advertising or profiling
  • Sell, transfer, or share Gmail data with third parties
  • Allow any human to read your email messages
  • Access Gmail without your explicit authorisation

PDF processing. Some NPS statements are image-based PDFs. In these cases, the PDF may be processed using Google's Gemini AI (via Google's own API) for optical character recognition. This is covered by Google's own privacy terms and Limited Use requirements.

Token security. Your Gmail OAuth tokens are encrypted with AES-256-GCM before being stored in our database. The encryption key is held separately in a secured environment.

Google Limited Use Compliance

Kanalyst's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect Gmail at any time from Settings → Data & Privacy → Disconnect Gmail inside the app. Disconnecting immediately revokes the token at Google and deletes all stored credentials from our database. You can also revoke directly at myaccount.google.com/permissions.

Section 04

How We Use Your Data

We do not use your personal or financial data for advertising, marketing, credit scoring, or any purpose beyond providing the Kanalyst service to you.

Section 05

Storage & Security

Your data is stored on secure servers hosted by Supabase (PostgreSQL) in compliance with SOC 2 Type II standards. All data is transmitted over HTTPS/TLS 1.3.

On your Android device

The Android app uses AES-256-GCM encryption for any sensitive credentials stored locally. SMS data never leaves your device — only extracted transaction fields are synced to the cloud.

Section 06

Data Sharing

We do not sell, trade, rent, or share your personal or financial data with any third party for any commercial purpose.

Infrastructure providers we use to operate Kanalyst:

Each provider processes only the data necessary to provide their specific service and is bound by their own data processing agreements.

Legal requirements. We may disclose data if required by Indian law or a valid court order. We will notify you where legally permitted.

Section 07

Your Rights

You have full control over your data at all times.

Section 08

Data Deletion

You can delete all your data directly inside the app — no email required:

Delete from the app

Go to Settings → Data & Privacy → Delete Account & All Data. Type DELETE to confirm. All data is permanently erased and Gmail access is revoked immediately.

Alternatively, email us at hello@kanalyst.in with subject "Data Deletion Request". We will process your request within 30 days.

Deletion is permanent and cannot be undone. Everything is erased: your account, holdings, portfolio snapshots, transactions, income, expenses, goals, bank deposits, NPS data, sync logs, family data, rules, and Gmail OAuth tokens.

Section 09

Children's Privacy

Kanalyst is intended for users 18 years and older. We do not knowingly collect, store, or process personal data from anyone under 18. If you believe a minor has created an account, please contact us at hello@kanalyst.in and we will delete the account immediately.

Section 10

Changes to This Policy

We may update this policy from time to time. For significant changes, we will notify you via email or in-app notification at least 14 days before the change takes effect. The "Last updated" date at the top of this page always reflects the most recent revision.

Section 11

Contact Us

Questions about this policy, data rights, or privacy concerns — we are here.

Get in touch

We aim to respond to all privacy-related enquiries within 2 business days. For data deletion requests, we will confirm receipt immediately and complete deletion within 30 days.

✉ hello@kanalyst.in