Orbis · Effective 4 June 2026
Orbis is a personal investing platform operated by an individual operator currently in the process of obtaining a SEBI Research Analyst registration. This Privacy Policy explains what data we collect, why we collect it, and how we protect it, in compliance with India's Digital Personal Data Protection Act 2023 (DPDP Act).
By using Orbis, you consent to the practices described here. If you do not agree, please do not use the platform.
Account data – your email address and password (hashed, never stored in plain text), collected when you sign up via Supabase Auth.
Profile data – your role (paper_only / live_user / admin), disclaimer acceptance timestamp and version, and display name if provided.
Trading activity – strategy configuration, paper trade history, and an append-only order audit log. This data is linked to your account and visible only to you and operational admins.
Usage data – error events and performance traces captured by Sentry (anonymised where possible). We do not use third-party analytics or advertising trackers.
Market data – we fetch live prices from NSE India and Dhan APIs on your behalf. We do not store your raw broker credentials beyond what you explicitly configure in the application settings.
We do not sell, rent, or share your personal data with third parties for marketing purposes.
The following sub-processors handle data on our behalf:
| Service | Purpose | Data region |
|---|---|---|
| Supabase | Authentication + database | AWS ap-south-1 (Mumbai) |
| Dhan / Tradehull | Broker API – live quotes & orders | India |
| NSE India | Market data | India |
| Yahoo Finance (yfinance) | Historical price data for backtesting | US |
| Sentry | Error monitoring | US (anonymised) |
Account and profile data is retained as long as your account is active. Trade history and audit logs are retained for 7 years to meet financial record-keeping norms. Error logs are purged after 90 days by Sentry. You may request deletion of your account and all associated data at any time (see Section 8).
All data in transit is encrypted via TLS. Database access is protected by Supabase Row Level Security – each user can only read their own records. Broker credentials are stored only in your local .env file and are never sent to our servers. We rotate access tokens daily.
Under the DPDP Act you have the right to:
For any privacy-related request or grievance, email hello@vriddhix.ai with the subject line "Privacy Request – <your registered email>". We respond within 7 working days.
We may update this policy as the platform evolves. Material changes will be communicated via the in-app disclaimer modal (which requires re-acceptance). The effective date at the top of this page will always reflect the latest version.