Skip to content

LEGAL

Privacy Policy

This Privacy Policy explains what personal data DalalOS collects, why, how long we keep it, who we share it with, and the choices you have. It applies to https://dalalos.in and the DalalOS MCP server / API.

Living document — not legal advice

This page is written and maintained by the DalalOS team to describe our actual data practices as plainly as possible. It has not yet been reviewed by outside counsel and is not a substitute for professional legal advice — it will be revised as the product, our vendors, or applicable law change. Last updated: 2 September 2026.

Who we are

DalalOS (https://dalalos.in) is a hosted MCP (Model Context Protocol) server and API that gives AI assistants read-only access to Indian (NSE/BSE) stock-market data — raw disclosed figures and mechanically-computed ratios only, never investment advice. This policy covers the landing site, the sign-in / API-key dashboard, and the underlying MCP server and REST API that the dashboard talks to.

Information we collect

We collect the following categories of data:

  • Identity data, via WorkOS AuthKit. When you sign in, WorkOS authenticates you (email/password, Google, or another supported method) and passes us your WorkOS user ID and the email address associated with your account. We don't receive or store your password — that's handled entirely by WorkOS.
  • Account, access, and product data. We store an internal account record linked to your WorkOS identity, subscription and usage counters, your watchlist symbols, and API-key metadata (prefix, status, and a hash used to authenticate future requests). The full plaintext key is shown once at creation time and is not retrievable afterward.
  • Usage and analytics data — only if analytics are enabled. If the operator has configured PostHog, product events and pageviews use the DalalOS account UUID as their identifier. We do not send your WorkOS user ID or email as a PostHog person property. PostHog may still receive standard web-analytics data such as pages visited, referrer, device/browser type, and approximate location derived from IP address. If it is not configured, no analytics events are captured.
  • Request and log data. Like most hosted services, our hosting provider (Cloudflare) and our own server logs record basic technical data for every request — IP address, timestamp, requested path, and response status — for reliability, rate-limiting, and abuse prevention.

We do not knowingly collect any brokerage, demat, trading, or financial-account credentials — DalalOS never asks for those, and read-only market data does not require them.

Why we collect it

  • To provide the service. Identity and account data are required to authenticate you, provision your account, issue and validate API keys, and enforce your plan's rate limits and usage quota.
  • To prevent abuse. Request logs and rate-limit counters let us detect and block excessive or automated abuse of the free tier and the underlying NSE/BSE-sourced data.
  • To improve the product. Where analytics are enabled, aggregate usage patterns (which tools get called, where users drop off during sign-up) help us prioritize what to build next.
  • To communicate with you. We may email you about your account (for example, a security-relevant change) at the address WorkOS provides us. We don't run a marketing mailing list today.

Who we share data with

We don't sell personal data. We share it only with the service providers that operate the product, each processing data on our behalf and only for the purpose described:

  • WorkOS — authentication (AuthKit sign-in) and session management. WorkOS is the source of truth for your login credentials.
  • Supabase — stores your account record, API-key metadata, and usage counters in a Postgres database. This is the same Supabase project the DalalOS MCP server reads and writes to.
  • PostHog — optional product analytics, described above. Only receives data when an operator has configured it for a given deployment.
  • Cloudflare — hosts the site. Every page and API route runs as a Cloudflare Worker, static files are served from Cloudflare's edge network, and cached page and market-data responses are stored in a Cloudflare R2 bucket. Serving a request necessarily means Cloudflare processes its metadata (IP address, headers).

We may also disclose data if required to by law, regulation, legal process, or a governmental request, or where we believe in good faith it's necessary to protect the rights, property, or safety of DalalOS, our users, or the public.

Links out to our community

Some pages carry a link to our community on a third-party messaging service (currently WhatsApp). That link is an ordinary outbound link: following it hands you off to that service, where their privacy policy and terms apply, not ours. DalalOS does not ask for, receive, or store your phone number, and joining is not connected to your DalalOS account in any way — we cannot tell which member of the community is which account holder.

Please understand what joining exposes before you join. A WhatsApp Community is a group messaging space, not a one-way feed. Your phone number and WhatsApp profile name are visible to the community's administrators and to other members of any room you join, and other members can message you directly. That visibility is a property of the messaging service, not something we control, switch off, or can undo for you after the fact. If you would rather not share a number with other members, don't join — everything we announce there is also on this site, and you can reach us at hello@dalalos.in instead.

We run the community as an announcement space plus a room for reporting data problems and feature requests. Posting investment tips, target prices, buy/sell calls, or promotions for paid advisory services is not allowed there, and we remove that content. If analytics are enabled, we record that the link was clicked and which page it was clicked from; we do not and cannot see whether you went on to join.

How long we keep data

Account records, API-key metadata, watchlist symbols, and usage data are kept while your account is active. Deleting the account removes those account-scoped records from the control plane and revokes access. Request/server logs are kept for a limited operational window and rotated out; we don't keep an indefinite raw log archive. Where analytics are enabled, PostHog event data follows the retention settings configured for that deployment. Provider backups or records we must retain for security, fraud prevention, or legal compliance may persist for longer.

Your rights and choices

Depending on where you're located, you may have rights to access, correct, export, or delete the personal data we hold about you, or to object to or restrict certain processing. Concretely, today:

  • API keys can be created and revoked yourself, self-serve, from /dashboard/keys at any time — no need to contact us for that.
  • Deletion is available self-serve from the delete-account control on your dashboard. It removes the account-scoped control-plane data described above and signs you out. If you cannot sign in, email hello@dalalos.in from the address associated with your account for deletion help or to request access, correction, or export. We'll action the request as soon as reasonably possible.

Cookies and similar technologies

WorkOS AuthKit sets a session cookie to keep you signed in. Where PostHog analytics are enabled, PostHog may set cookies or local-storage identifiers for anonymous pageview measurement; the signed-in account identifier is the DalalOS UUID, not your email. We don't use third-party advertising cookies.

Children's privacy

DalalOS is not directed at children and we don't knowingly collect personal data from anyone under the age required by applicable law to consent to data processing on their own behalf. If you believe a child has provided us with personal data, contact us and we'll remove it.

International data transfers

DalalOS is an Indian product, but our service providers (WorkOS, Supabase, PostHog, Cloudflare) operate global infrastructure, so data may be processed on servers outside India. Each provider maintains its own safeguards for cross-border transfers; we haven't layered a separate contractual mechanism on top of theirs at this stage.

Vendors are not the only reason data leaves India. The market-data backend this site reads from is a DalalOS system rather than a third party's, and it runs on server infrastructure we rent outside India. Every page that shows market data, and every market-data API call, is therefore a request from us out to a host outside the country. Those requests carry what is being asked for — a symbol, a screen, a date range — plus a first-party service credential, not your identity; the one exception is your dashboard, where listing, creating, or revoking an API key forwards your WorkOS access token to that same backend. Because this is our own infrastructure and not a vendor's, no provider's cross-border safeguard covers it, and we haven't put a separate mechanism of our own in its place either.

Changes to this policy

We'll update the "Last updated" date above whenever this policy changes, and for material changes we'll make reasonable efforts to give more prominent notice (for example, on the dashboard). Continued use of DalalOS after a change means you accept the updated policy.

Contact us

Questions, requests, or concerns about this policy or your data: hello@dalalos.in.

FAQ

Common questions

Do I need to sign in to use DalalOS?

Browsing the site and the public read-only pages (tools, docs, screener, heatmap, calendar, FII/DII, IPOs, discovery, individual stock pages) doesn't require an account. Signing in via WorkOS is only required to reach your dashboard and create an API key.

Does DalalOS sell my data?

No. DalalOS does not sell personal data to third parties. Data is shared only with the service providers described below, strictly to operate the product (authentication, storage, hosting, optional analytics).

Can I delete my account and data?

Yes. Use the delete-account control in your dashboard, or email hello@dalalos.in if you cannot sign in.

Is analytics tracking always on?

No. Product analytics (PostHog) only runs when the operator has configured it for a given deployment. If it isn't configured, no analytics events are captured at all — this follows the same graceful-degradation pattern used throughout the product.

Connect your AI to Indian stock market data

Sign in to DalalOS and connect your AI in one line of config. Free to start.

KEEP EXPLORING