Privacy Policy
Last updated: 2026-10-07
Invite-only private beta. Not legal advice. This Policy describes how Vajra Astra handles information during private beta.
1. Overview
This Privacy Policy explains what information Vajra Astra may collect, store, process, and share to operate the Service for invited users.
It is written for clarity and trust during private beta. It is not a claim of institutional compliance certification.
2. Information we may collect
Depending on how you use the Service, we may collect and store:
Account and security
- email address and authentication credentials (password hashes; not plaintext passwords)
- invite, signup, session, and password-reset metadata. Submitting a password-reset request does not email you a link right away. After someone reviews the request, we send you a link with the reset token.
- study-session and survey-progress records (tokens and completion times, not the questionnaire answers; which research-session link you opened, including an operator-chosen posting location name)
- auth / security event logs
Portfolio and research
- portfolio names, account types, broker metadata, and holdings imports
- open and closed positions, including lifecycle fields used for history and charts
- position history used for performance charts
- watchlists, notes, and related symbol context
- signals and workflow status fields you interact with
- company news headlines and related sentiment for symbols you hold or research. These come from public news feeds.
AI and analysis artifacts
- prompts and selected context flags (for Idea Copilot / related flows)
- position audits, debate transcripts and scores
- Research Desk reports and related run metadata
- Idea Copilot conversation history (stored per portfolio where enabled)
Configuration and keys
- model routing preferences
- encrypted third-party provider API keys if you choose to save them (BYOK)
- product settings needed to run the platform for you
Activity and operations
- the activity log you see in the product, so you can follow what it is doing and spot errors
- application logs and usage metadata needed to operate, debug, and secure the beta
3. How we use information
We use information to:
- authenticate users and protect accounts
- assign a research-session arm and count signups by posting location
- render portfolios, watchlists, news context, and research workflows
- run Position Audit, Debate Analysis, Research Desk Report, and Idea Copilot when you request them
- improve reliability, diagnose failures, and operate the beta safely
- enforce access control, tenancy isolation, and abuse protections
We do not use your portfolio data to execute brokerage trades. We do not ask for brokerage usernames or passwords, and we do not place orders or move money. We do not ask for payment card numbers, government identification numbers, or health information. We do not train our own models on your portfolio or prompts.
4. Third-party processing
When you run AI or market features, relevant portions of the request (for example symbols, holdings context, or prompts you submit) may be sent to third-party providers so the feature can complete.
This may include:
- model providers / routers (for example Perplexity, OpenAI, Google / Gemini, Anthropic)
- market-data and news providers used by the application
- the host that runs the Service (Amazon Web Services in the United States: the application, the database, and logs)
- the survey host when you open a study survey from the product. Answers are collected on that host. The product stores the account token and that a survey was completed, not the questionnaire text.
If you supply your own API keys, those providers process data under their own policies as well. What is sent is the context for that request, such as symbols, holdings, or the prompt you submit. Those providers' retention and any use of inputs for their own model training follow their terms. We do not control that.
5. API keys (BYOK)
If you paste provider API keys into Settings:
- keys are stored encrypted on the server
- the UI does not show the full stored key after save
- saved keys are removed when the account is deleted
Treat keys as secrets. Prefer provider keys with spend limits for beta use.
6. Cookies, local storage, and similar technologies
The browser UI may store small amounts of data locally to make the product usable, for example:
- authentication session cookie (
advisor_token) when auth is enabled - CSRF double-submit cookie (
advisor_csrf) when auth and CSRF protection are enabled - study visitor cookie (
vajra_study_visitor) when you open a research-session link, so the same browser keeps the assigned arm - UI preferences such as theme (light/dark), page width (standard/wide), table column layouts, privacy blur toggles, and similar interface details
- per-browser state such as last-run timestamps, collapsed deep-dive cards, and navigation/progress flags
This local data is used to operate the Service for you—not for third-party advertising. Clearing site data in your browser may reset preferences and require you to sign in again.
7. Sharing, sale of data, and platform admins
For the private beta baseline:
- we do not sell your personal or portfolio data
- we do not intentionally expose one invitee’s private workspace to another invitee
- we do not use uploaded portfolio data for unrelated advertising
Platform admins (operator accounts with admin privileges) may view the activity log and sign-in records, manage invites and password-reset assistance, adjust platform settings, and see study-link counts plus posting-location names. That access is for operating and securing the beta—not for selling data or sharing workspaces between ordinary users.
Service operators and subprocessors needed to host or debug the Service may access data only as required to operate the beta.
8. Retention
We retain account, portfolio, AI output, activity, and operational data as needed to run the product, support history/debugging, and secure the Service.
Practical retention expectations are described in Data Retention.
9. Your choices and deletion
You may:
- stop using the Service at any time
- clear browser local data for this site
- delete your account from Settings → Account
Deletion path: In Settings → Account, choose Delete Account and confirm. Access ends immediately and you cannot sign in again. Your login details, portfolio information, and any stored API keys are deleted the next time the delete job is run. Activity-log entries and sign-in records may remain, but they are no longer tied to you. How long each kind of data is kept is described in Data Retention.
10. Security
Reasonable safeguards for private beta include:
- authenticated access and invite-gated registration (auth on by default for hosted-style configs)
- tenancy / ownership checks on portfolio and run data
- encrypted storage for saved provider API keys
- hosted database storage encrypted at rest, and not open to the public internet
- HTTPS for hosted deployments
- operational logging for security review
No system can guarantee absolute security. Report suspected issues promptly to hello@vajrastra.co.
11. Children
The Service is not directed to children under 18. Do not use it if you are under 18.
12. International and regulated use
The Service is an experimental research tool. Do not assume it meets institutional privacy, brokerage, or advisory compliance requirements unless those claims are explicitly added later.
13. Changes
This Policy may change as the product evolves. Material changes should be reflected in the dated in-product version. Continued use after an update means you accept the revised Policy when that update is communicated.
14. Contact
For a question about this Policy, email hello@vajrastra.co.