Privacy Policy
This policy explains what MyStockVision collects when you use the service, why, who it is shared with, and what you can ask us to do with it.
Last updated: 6 August 2026
What we collect
When you create an account, we store:
- Your name and email address, so we can identify your account and send verification and password-reset messages.
- A hashed password. Passwords are hashed with bcrypt before storage. We never store, log, or transmit your password in readable form, and we cannot recover it for you.
- Your account status — tier, email-verification state, and whether the account is restricted.
As you use the product, we also store the content you create:
- Portfolio holdings — the symbols, quantities, and purchase prices you enter. This reveals your financial position, so we treat it as sensitive.
- Watchlists and price alerts — the symbols and thresholds you track.
- Premium access requests, including any reason you supply.
We do not use advertising trackers or third-party analytics, and we do not sell personal data to anyone.
Cookies and local storage
- Authentication cookies (
access_token,refresh_token) keep you signed in. They arehttpOnly, so page scripts cannot read them, and they are transmitted over HTTPS in production. These are strictly necessary — the service cannot keep you signed in without them. - Local storage holds your display name and email so the interface can greet you before the server responds. Signing out clears it.
Who your data is shared with
We share the minimum necessary with the processors that make the product work. Each is bound by its own terms, and we do not authorise any of them to sell your data.
- Google (Gemini API) — powers the AI analysis features. When you run an AI feature, the relevant stock or portfolio context for that request is sent to Google for processing.
- Market data providers (including Financial Modeling Prep, NewsAPI, and exchange sources) — these receive the symbol being looked up, not your identity.
- Email delivery — your email address is passed to our mail provider to send verification, password-reset, and account messages.
- Rate limiting and hosting infrastructure — processes request metadata such as IP address to protect the service from abuse.
We may also disclose data where required by law, or to establish or defend a legal claim.
How long we keep it
- Account data is retained while your account exists.
- Session refresh tokens expire after 30 days, and expired ones are deleted automatically.
- Password-reset tokens are short-lived and single-use.
- When you ask us to delete your account, we remove your personal data except where we are legally required to retain it.
Your rights
Under the Digital Personal Data Protection Act, 2023, you may ask us to give you a copy of your personal data, correct anything inaccurate, delete your account and its data, or withdraw consent for optional processing. Write to support@mystockvision.com and we will respond within a reasonable period.
If you are not satisfied with our response, our Grievance Officer can be reached at grievance@mystockvision.com. You also have the right to complain to the Data Protection Board of India.
Security
We hash passwords with bcrypt, keep session tokens in httpOnly cookies, store refresh tokens only as irreversible hashes, rotate them on every use, serve the site over HTTPS with strict transport security, and rate-limit authentication endpoints against brute-force and credential-stuffing attempts.
No system is perfectly secure. If you believe your account has been compromised, change your password and contact us immediately.
Children
The service is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us personal data, contact us and we will delete it.
Changes and contact
If we change this policy we will update the date at the top of this page, and we will notify you of material changes. MyStockVision can be reached at support@mystockvision.com.