Back to algoagent.in

Privacy Policy

Algoagent Corealgoagent.in

Last updated: September 5, 2026

1. Introduction

This Privacy Policy explains what information Algoagent Core ("we", "us", or "our") collects, what we deliberately do not collect, and how we handle the little data we do touch. It describes Algoagent Core as a local-first portfolio research tool, provided free of charge.

Here is the short version: Algoagent Core is a local-first macOS application. It runs on your machine. Your keys, your holdings, your research, and your prompts never reach our servers. The app is free, and it asks you to sign in once so we can answer your support mail and tell you about updates. We keep one record: an email address and a sign-in identifier — nothing else.

By downloading, installing, or using Algoagent Core, or by creating an account, you agree to this policy. Visiting algoagent.in is not acceptance.

2. What We Collect

2.1. Your account record

Signing in is required to open the app, and it is still free. There is no subscription, no trial, no paid tier, and no usage limit — the account is not a licence and unlocks no features, because no feature is locked. It exists so that a support request can be tied to a real person and so we can tell you about updates.

You sign in once. The session is stored in the macOS Keychain on your Mac and is never re-checked against our servers, so the account gate opens locally on later launches, including offline. The app contacts the account server at sign-in and sign-out. The macOS app checks the public update feed shortly after its window opens, without a session token or system profile. The request exposes ordinary connection information such as the IP address and app user-agent/version to our hosting provider. An available update is downloaded and installed only after you choose Update. Closing the notice defers it until a later launch. Sessions expire 90 days after creation, not last use. Expired rows are deleted by a daily job (and also opportunistically on the next sign-in). The copy in your Keychain is independent of the server row, so deleting an expired row does not sign you out.

When you sign in with Google or Apple, our account server stores:

  • A sign-in identifier — the stable subject ID from Google or Apple that identifies your account.
  • Your email address, as provided by the sign-in provider. If you use Apple's private relay, this is your relay address.

Alongside those we store which provider you used, whether that provider told us the address was verified, when the account was created, and — for the session itself — when it was created, when it was last used, when it expires, and whether it has been revoked.

That is the entire contents of our user database. Two small tables: your account, and your sign-in session. Nothing in it describes your research, your holdings, or your keys, and there is no row anywhere that records what you looked at. There is no payment record, because there is nothing to pay. Signing out revokes the session and returns the app to its sign-in screen; it deletes nothing on your Mac — your research, holdings, and keys are untouched.

2.2. Website data

  • Standard server logs. When you visit algoagent.in, our hosting provider (Cloudflare) may record minimal, standard log data such as your IP address, browser user-agent string, the pages or update files you request, and the date and time of the request, for security and abuse prevention.
  • Download metrics. We may count how many times our .dmg installer is downloaded. These are aggregate counts only.
  • Correspondence you send us. If you email us (for example at contact@algoagent.in or bugs@algoagent.in), we keep the content of your message and your email address so that we can respond.

2.3. Payment data (there is none)

Algoagent Core is free. We operate no billing system, use no payment processor, and never collect card details, billing addresses, or any financial information about you.

3. What We Do NOT Collect

  • Your keys. The keys the app holds — your LLM research key, your optional fundamentals-data key, your optional news-provider keys, and your optional broker keys — are stored locally on your Mac and never transmitted to us. They are sent only from your machine directly to the respective provider. The app only ever calls read-only endpoints, and order paths are blocked at the network layer — so even a key that could trade elsewhere can never place an order here.
  • Your trading and portfolio data. Your holdings, synced portfolio data, and research dossiers are processed and stored locally. We do not receive, monitor, or log any of it.
  • Your prompts and LLM traffic. Research is generated on your machine by your own LLM provider account. None of it passes through us.
  • What the app reads while researching. Filings, announcements, prices, and news are fetched by the app from your machine, using your own keys and your own connection, and are stored locally. None of it is fetched by us, routed through us, copied to us, or redistributed by us.
  • Documents and figures you supply. If a source is unavailable and you choose to upload a document or type in a figure, it stays on your Mac and becomes part of your local research data. It is never transmitted to us.
  • Usage telemetry. There is no telemetry. The app contacts the account server at sign-in and sign-out. The macOS app checks the public update feed shortly after its window opens, without a session token or system profile. The request exposes ordinary connection information such as the IP address and app user-agent/version to our hosting provider. An available update is downloaded and installed only after you choose Update. Closing the notice defers it until a later launch. There is no periodic check-in, because there is nothing to verify. No usage statistics, no dossier content, no crash reports, no device fingerprints.
  • Tracking cookies. We do not use cookies for tracking or advertising. If any cookies are present, they are strictly necessary ones required for basic website functionality or security.

In short: the things this terminal knows about you stay with you. The most our server ever knows is an address to reach you at, and only if you offered one.

4. What the App Stores on Your Mac

We describe this not because we can see it — we cannot — but because you should know what is on your own disk.

  • Your research database. Alongside your dossiers and their revision history, the app keeps a fetch ledger: for every page, filing, or statement it retrieves while researching, it records the URL, a checksum, a timestamp, and the retrieved text itself. This is what makes a citation checkable rather than decorative — a claim can be verified against the page it came from, months later, without re-fetching. It also means a copy of the source material you researched lives on your machine.
  • Your news cache. Headlines, short summaries, links, source names, and publication timestamps — not full article bodies.
  • Documents and figures you supplied, if you used that path, together with the label and date you gave them.
  • Your holdings and portfolio history, and your keys, in the app's local storage.

All of it is on your Mac, under your control, and removable by you: uninstalling the app and deleting its data folder removes the lot. None of it reaches us, and none of it is synchronised anywhere by default.

There is one way for a dossier to leave your Mac, and only you can switch it on. If you configure a delivery channel — your own Telegram, Slack, Discord, Matrix, Signal, IRC or ntfy account, or an SMTP server you supply — then exporting a dossier also sends it to that destination. Every channel is off unless you enter your own credentials for it, the dossier goes to the account you chose rather than to us, and we neither receive a copy nor can read what was sent. Configure no channel and nothing leaves the machine.

5. How We Use the Data We Have

We use the data described in Section 2 only to: respond to your emails and fix bugs you report; send you notices about updates to the software; operate and secure algoagent.in and the account server; and measure broad interest in the product in aggregate. We do not use this data for advertising, profiling, selling, or automated decision-making about you.

6. Third-Party Services

Algoagent Core and algoagent.in rely on a few third parties. When you interact with them, their own privacy policies apply:

  • Cloudflare. Our website and account API are served and protected by Cloudflare, which processes standard request data for security and delivery, and hosts our account database.
  • Google / Apple. Sign-in providers. When you sign in, you authenticate with them directly; they tell us only your subject ID and email address.
  • Your LLM provider. When Algoagent Core calls an LLM API using your own key, your prompts and related data are sent directly from your machine to that provider, governed by that provider's privacy policy.
  • Broker (read-only). The app connects to your broker (Zerodha Kite) only through a read-only connection you configure, to sync your holdings and, where your broker account is entitled to it, to read prices. Your holdings data is exchanged directly between your machine and that broker, governed by your broker's privacy policy.
  • Delivery channels you configure (off by default). If you switch on a messaging or email destination for dossier exports, the provider operating it — Telegram, Slack, Discord, Matrix, Signal, IRC, ntfy, or your own mail server — receives the dossier you sent and processes it under its own privacy policy. You supply the credentials, you choose the destination, and we are not in the path.
  • Exchanges, regulators, publishers, and data vendors. While researching, the app reads exchange disclosure endpoints (bseindia.com), a price-history lookup, news publishers over RSS, and — where you supply a key — a fundamentals-data provider. It does not crawl regulator websites; where a regulator is named in a dossier, that name came from a document the app retrieved from one of the sources just listed. These requests originate from your machine: they carry your IP address and, where a key is involved, your credentials, exactly as if you had opened the page yourself. We are not in the path, receive nothing from these requests, and keep no record that they happened. Each of those sites has its own privacy practices, which apply to your visit and not to us.

We are not responsible for the privacy practices of these third-party providers. We have no access to the data you send to them through your own keys.

7. Data Retention & Account Deletion

  • Account data is kept while your account exists. Delete your account and it is removed.
  • Deleting your account: email contact@algoagent.in from your account email address and we will delete your account record — sign-in identity, email address, and sessions. Because the app requires a sign-in to open, deleting your account means the app will ask you to sign in again the next time it starts; signing in with the same provider simply creates a new record. Deletion never touches your Mac — your research, dossiers, holdings, and keys live only on your device, we hold no copy of them, and they remain entirely yours whether or not an account exists.
  • Server logs are kept for a limited period consistent with security needs; email correspondence as long as necessary to resolve your matter.
  • Your keys, research, fetch ledger, news cache, and anything you supplied yourself live on your machine, so their retention is entirely under your control — uninstalling the app and deleting its data folder removes them. We cannot delete them for you, because we never had them.

8. Data Security

We take reasonable measures to protect the limited data we hold: HTTPS everywhere, Cloudflare's security infrastructure, and hashed session tokens (the token itself is never stored). The most important security fact is architectural: because your keys, holdings, and research never leave your machine and never reach us, the strongest protection we offer is that we simply do not have them. You remain responsible for securing your own Mac and your locally stored credentials.

9. Your Rights; Governing Law & Data Protection

Depending on where you live, you may have rights regarding the personal data we hold about you, commonly including the right to access, correct, delete, or restrict processing of that data. To make a request, email us at contact@algoagent.in. These rights apply to data we hold; your keys and trading data are stored locally and are fully under your own control.

Governing law. This Privacy Policy is governed by and construed in accordance with the laws of India, without regard to conflict-of-law principles, consistent with our Terms of Service.

Data-protection framework. For users in India, we handle the personal data we hold in line with the Digital Personal Data Protection Act, 2023 (DPDP Act). Where applicable, we also honour comparable rights under the EU/UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). Because we collect almost nothing — and never receive your keys, holdings, or research — there is typically very little personal data for us to process.

Data controller. The data controller for the data described in Section 2 is the operator of Algoagent Core, reachable at contact@algoagent.in.

10. Children's Privacy

Algoagent Core and algoagent.in are not directed at minors. The Software is intended for users who are at least eighteen (18) years of age (or the age of majority in their jurisdiction), consistent with our Terms of Service, and we do not knowingly collect personal information from minors.

11. Changes to This Policy

We may update this Privacy Policy from time to time, including as new capabilities ship. When we do, we will revise the "Last updated" date at the top of this page. Material changes will be noted within the Software or on algoagent.in where practicable.

12. Contact

If you have any questions about this Privacy Policy, or if you would like to exercise your rights (including account deletion), please reach out:

  • General inquiries: contact@algoagent.in
  • Bug reports: bugs@algoagent.in
  • Website: algoagent.in