MAYABack to MAYA →

MAYA BETA 1 · LEGAL

Privacy Policy

How MAYA collects, uses, and protects your data.

Last updated 7 August 2026

1. What MAYA is

MAYA is a private market-intelligence workspace for Indian equities (NSE and BSE), built and operated by Satyajit Mishra. MAYA is read-only: it has no order-placement or fund-transfer capability of any kind, on any account.

2. Data we collect

  • Account data: your email address and a salted hash of your password. We never store your password in plain text.
  • Portfolio data you enter or import: stock symbols, quantities, average prices, and the broker report rows you choose to import.
  • Zerodha Kite connection: if you connect your Zerodha account, MAYA stores your personal Kite access token so it can fetch quotes on your behalf. This token is scoped to your account only and expires automatically (Kite invalidates it daily). MAYA never asks for, sees, or stores your Zerodha login password.
  • Feedback you submit through the in-app feedback form.
  • Session cookies used only to keep you signed in — no cross-site tracking or advertising cookies.
  • Optional notification settings (an email address and/or WhatsApp number) if you choose to enable dividend alerts.

3. Data we deliberately do not collect

  • PAN numbers and broker-report passwords. When you import a password-protected broker PDF (for example, an SBI Securities ledger report), the file is decrypted entirely inside your own browser. The PAN or password you enter is used only in memory for that one operation and is never sent to, or logged by, MAYA's servers.
  • Your Zerodha login credentials or API secret (the API secret is configured once by the account owner and is never exposed to the browser or to other users).
  • Bank account numbers, card details, or any payment information — MAYA does not process payments.

4. How your data is isolated

Every account's data — holdings, reports, settings, Zerodha token — is stored under a key unique to that account and is never readable by another user. Report links you explicitly choose to share are the only data made available outside your account, and only for the scope, expiry, and password you set when creating the link.

5. Third parties MAYA talks to

ServicePurposeWhat it receives
Zerodha Kite ConnectLive and historical market quotesYour Kite access token, requested instrument symbols
NSE / BSE public data feedsOfficial index, corporate-action and market-breadth dataNo personal data — public market requests only
ResendSending dividend-alert emails, if you enable themThe email address you configure and the alert content
Meta WhatsApp Cloud APISending WhatsApp alerts, if you enable themThe phone number you configure and the alert content
CloudflareHosting, database, and content deliveryAll application data — Cloudflare is MAYA's infrastructure provider, not a separate recipient

6. Data retention and deletion

Your data is retained for as long as your account exists. You can disconnect Zerodha at any time from Setup, which deletes your stored access token immediately. To delete your account and all associated data, contact us via the Contact page.

7. Security

Passwords are hashed, not stored in plain text. All traffic is served over HTTPS. Access to production data is restricted to the Founder account and logged.

8. Changes to this policy

If this policy changes materially, the "Last updated" date above will change accordingly. Continued use of MAYA after an update means you accept the revised policy.

9. Contact

Questions about this policy or your data can be sent through the Contact page.