VestumBack to Vestum

Effective 2 September 2026 · Version 1.0

Privacy Policy

What Vestum does with your personal and financial data, who else ever sees it, how long we keep it, and what you can require of us.

Draft — pending legal review

A lawyer has not reviewed or approved this document yet. It describes how Vestum is built and how it is meant to work. It is not a final or binding legal document, and you should not rely on it as one.

1.Who we are

Vestum is a family wealth-management application. You record your household's investments, loans, insurance and goals in it, and it values, analyses and reports on them for you.

For the purposes of the Digital Personal Data Protection Act, 2023 (“DPDP Act”), Vestum is the Data Fiduciary for the personal data described in this policy, and you are the Data Principal. This policy explains what we do with that data and what you can require of us.

2.What we collect

We hold four kinds of data about you, and nothing else:

  • Account data — your name, email address, phone number, date of birth, and the profile photo you choose to upload. Your password is never visible to us; it is held as a hash by our authentication provider.
  • Household data — the family members you add, their relationship to you, and their dates of birth and PAN where you enter them.
  • Financial data — the holdings, transactions, deposits, retirement accounts, loans, insurance policies, goals and tax records you enter, import from a file, or sync from a connected broker account.
  • Operational data — sign-in timestamps, device and session records, and error logs, kept so we can secure your account and fix faults.

What we do not collect

We do not collect Aadhaar numbers, bank account credentials, or card details. Vestum cannot move money: it has no payment rails and never asks for the credentials that would give it any. We do not buy personal data from data brokers, and we do not build advertising profiles.

3.Why we process it

Each purpose below is separate, and each is something you can review and — except where it is essential to running the account at all — withdraw at any time from Consent Management.

  • Running your account (essential) Storing the holdings, goals, loans and insurance you enter, and the profile and family roster the app is built around.
  • Live market pricing Sending the ticker symbols and scheme codes you hold to market-data providers (Alpha Vantage, AMFI) to fetch prices and NAVs. Only the identifiers go out — never your quantities, values or identity.
  • Connected broker accounts Linking a broker or MFCentral account and pulling your holdings and transactions from it on your behalf.
  • Analysis and recommendations Deriving tax estimates, rebalancing plans, goal projections and action tasks from your portfolio.
  • Product analytics Which screens get used, and where people get stuck. It helps us decide what to build next. Nothing identifies you, and no financial figures are included.
  • Product emails Occasional email about new features and offers. This is separate from essential mail. Security alerts, deletion notices and password resets are always sent.

Withdrawing a consent stops that processing from the moment you withdraw it. It does not undo processing that already, lawfully, happened — but it does mean we stop, and the consequences of stopping are spelled out next to each switch before you flip it.

4.Who else sees it

We do not sell your data, and we do not share it for anyone else's marketing. These are every party that receives anything, and what each one gets:

  • Infrastructure providers — our database, authentication and file storage run on Supabase, and the application is served from Vercel. They process data on our instructions as Data Processors, under contract, and for no purpose of their own.
  • Market-data providers — to price your portfolio we send the ticker symbols and mutual-fund scheme codes you hold to Yahoo Finance (share prices and price history), Tickertape (sector and company size), mfapi.in (mutual-fund NAVs) and, only when Yahoo does not answer, Alpha Vantage as a fallback. We also ask Frankfurter for exchange rates, which involves no identifier of yours at all — just a currency pair.
    Only the instrument identifiers go out. Your quantities, your valuations and your identity do not, and those providers therefore cannot tell what you own or who you are.
  • Email delivery — confirmation links, password resets and family invitations are sent through Resend, which therefore receives the recipient's email address. Nothing about your holdings is in those messages.
  • Error reporting — when something breaks, the error is sent to Sentry so we can fix it. It is configured not to attach your IP address or request headers, and every report is passed through a filter that removes PAN numbers, email addresses, account and folio numbers and any figure of six digits or more before it leaves your browser. What remains is the fault, not your finances.
  • Brokers you connect yourself — if you link Zerodha or Groww, or request a statement from MFCentral, we exchange credentials and fetch holdings with that provider on your instruction. Access tokens are stored encrypted and are never exposed to the browser.

Public reference data is a download, not a disclosure. We fetch the AMFI scheme master and the NSE and BSE security lists so that a fund or a share can be identified by name. Those are public files and the request contains nothing about you.

We will disclose data to a public authority where the law compels it. Where we are permitted to tell you that we have, we will.

5.What your family can see

Vestum is built for households, so some of your data is visible to the other members of your family account by design. You should know exactly where that line falls:

  • Everyone in the family can see the household's financial records — holdings, transactions, goals, loans and insurance — including yours. That is the point of a shared household view.
  • The family administrator can additionally edit any member's financial records.
  • Nobody but you can see or change your consents, your password, your sessions, or your deletion request. These are yours alone, and no administrator role reaches them.

6.How we protect it

Every table in our database enforces row-level security: authorisation is applied by the database itself on every single query, so a bug in the application cannot return another household's rows. Data is encrypted in transit (TLS) and at rest. Broker access tokens are encrypted with a separate key and are only ever decrypted server-side.

No system is perfectly secure. If a personal data breach affects you, we will notify you and the Data Protection Board of India as the DPDP Act requires.

Known limitation

PAN numbers are currently stored unencrypted. This is a recorded gap that must be closed before general release. We are telling you rather than waiting to be asked.

7.How long we keep it

We keep your data for as long as your account exists, because the whole value of the app is a financial history that goes back years.

When you delete your account, it is deactivated immediately and every session is signed out. Your data is then permanently erased 30 days later. During those 30 days, signing in again cancels the deletion and restores everything — after that it is gone and cannot be recovered, by you or by us.

We may retain a minimal record of the deletion itself, and anything a law specifically requires us to keep, for as long as that law requires.

8.Your rights

Under the DPDP Act you have the following rights, and all of them work today:

  • Access — get a copy of everything we hold. Settings → Export My Data builds it as a spreadsheet and downloads it immediately. No request form, no waiting.
  • Correction — every field you have given us is editable in the app.
  • Erasure Settings → Delete Account, subject to the 30-day grace window above.
  • Withdrawal of consent Consent Management, one switch per purpose. The Act requires withdrawal to be as easy as giving consent, and it is the same control in the same place.
  • Grievance redressal — write to us at the address in §10. If we do not resolve your complaint, you may escalate it to the Data Protection Board of India.
  • Nomination — you may nominate someone to exercise these rights on your behalf if you die or become incapacitated. Contact us to record a nominee.

9.Children's data

Vestum is not for use by anyone under 18. Where you add a child to your household roster — to plan an education goal, for instance — you are entering data about them as their parent or lawful guardian, and you confirm that you are entitled to do so. We do not track children, profile them, or serve them advertising.

10.Contact and changes

For any question about this policy, to exercise a right the app does not already give you a button for, or to raise a grievance, contact our Grievance Officer at privacy@vestum.app. We answer within 30 days.

If we change this policy materially, we will raise the version number and ask you to review your consents again rather than assuming an answer given against older terms still stands. This is version 1.0, effective 2 September 2026.