MAYA BETA 1 · LEGAL
Privacy Policy
How MAYA collects, uses, and protects your data.
Last updated 7 August 2026
1. What MAYA is
MAYA is a private market-intelligence workspace for Indian equities (NSE and BSE), built and operated by Satyajit Mishra. MAYA is read-only: it has no order-placement or fund-transfer capability of any kind, on any account.
2. Data we collect
- Account data: your email address and a salted hash of your password. We never store your password in plain text.
- Portfolio data you enter or import: stock symbols, quantities, average prices, and the broker report rows you choose to import.
- Zerodha Kite connection: if you connect your Zerodha account, MAYA stores your personal Kite access token so it can fetch quotes on your behalf. This token is scoped to your account only and expires automatically (Kite invalidates it daily). MAYA never asks for, sees, or stores your Zerodha login password.
- Feedback you submit through the in-app feedback form.
- Session cookies used only to keep you signed in — no cross-site tracking or advertising cookies.
- Optional notification settings (an email address and/or WhatsApp number) if you choose to enable dividend alerts.
3. Data we deliberately do not collect
- PAN numbers and broker-report passwords. When you import a password-protected broker PDF (for example, an SBI Securities ledger report), the file is decrypted entirely inside your own browser. The PAN or password you enter is used only in memory for that one operation and is never sent to, or logged by, MAYA's servers.
- Your Zerodha login credentials or API secret (the API secret is configured once by the account owner and is never exposed to the browser or to other users).
- Bank account numbers, card details, or any payment information — MAYA does not process payments.
4. How your data is isolated
Every account's data — holdings, reports, settings, Zerodha token — is stored under a key unique to that account and is never readable by another user. Report links you explicitly choose to share are the only data made available outside your account, and only for the scope, expiry, and password you set when creating the link.
5. Third parties MAYA talks to
| Service | Purpose | What it receives |
|---|---|---|
| Zerodha Kite Connect | Live and historical market quotes | Your Kite access token, requested instrument symbols |
| NSE / BSE public data feeds | Official index, corporate-action and market-breadth data | No personal data — public market requests only |
| Resend | Sending dividend-alert emails, if you enable them | The email address you configure and the alert content |
| Meta WhatsApp Cloud API | Sending WhatsApp alerts, if you enable them | The phone number you configure and the alert content |
| Cloudflare | Hosting, database, and content delivery | All application data — Cloudflare is MAYA's infrastructure provider, not a separate recipient |
6. Data retention and deletion
Your data is retained for as long as your account exists. You can disconnect Zerodha at any time from Setup, which deletes your stored access token immediately. To delete your account and all associated data, contact us via the Contact page.
7. Security
Passwords are hashed, not stored in plain text. All traffic is served over HTTPS. Access to production data is restricted to the Founder account and logged.
8. Changes to this policy
If this policy changes materially, the "Last updated" date above will change accordingly. Continued use of MAYA after an update means you accept the revised policy.
9. Contact
Questions about this policy or your data can be sent through the Contact page.