Privacy Policy
Last updated 13 September 2026
This policy describes what CAPITA1 collects when you use https://www.capita1.in, why, how long it is kept, and who else sees it. It is written from an audit of the application's own code rather than from a template, so it describes this site specifically — including the parts that are not flattering.
Most of the site can be read without an account, without submitting anything, and without telling us who you are. The sections below are grouped by what you actually do, so you can read only the one that applies to you.
1. Who we are, and how to reach us
CAPITA1 publishes market data, IPO information, calculators and educational material about Indian securities markets at https://www.capita1.in. We are not a SEBI-registered investment adviser or research analyst, and nothing on the site is investment advice.
For any question about this policy, about what we hold on you, or to ask that we delete it, write to support@capita1.in. A request to delete personal data is answered by a person, not a form.
2. If you only read the site
You do not need an account and we do not ask for your name. What is collected is the following, and nothing else.
- Google Analytics 4 (measurement ID G-E187N83RJQ) records the page you viewed, the page you came from, your approximate location, your device and browser, and your IP address as Google sees it. It sets its own cookies in your browser. Google is the controller of that data and its handling is governed by Google's own policies.
- Our own analytics record the name of an event (for example, that a call-to-action was clicked), the time, the page path, and whether you were signed in. There is no third-party code in this path and no advertising identifier. These records are deleted automatically after 180 days.
- Your IP address is used as a short-lived rate-limiting key so that automated traffic cannot exhaust the AI features. It is held for one hour and is not stored alongside anything that identifies you.
- Your theme preference (light or dark) is stored in your browser only. It is never sent to us.
One thing worth stating plainly: if you use the site search, the words you type appear in the page URL, and Google Analytics records page URLs. If you would rather a search term not reach Google, do not type it into the site search.
3. If you send feedback
The feedback form stores your message, the topic and sentiment you chose, and the page you were on when you opened it. An email address is optional and is asked for only so that someone can reply to you.
Feedback is deleted automatically after 365 days. Your IP address is used to limit how many times the form can be submitted in an hour and is not stored on the feedback record itself.
4. If you request access to the members area
The request form collects your name, email address, optionally your company or college, and whatever you write in the "use case" box. This is used to decide whether to approve the request and to email you the outcome.
Those emails are sent through Resend, an email delivery provider, which therefore receives your address and the contents of the message. Your IP address is recorded with the request.
We should be straightforward about the retention here: access requests are currently kept indefinitely and there is no automatic deletion. If you would like yours removed, email support@capita1.in and it will be deleted.
5. If you have a member or staff account
Accounts are created by an administrator, not by self-signup. The account holds your name, email address, a hashed password, your role and designation, and workspace information such as your department and reporting line. Passwords are stored only as a bcrypt hash and are never returned by any part of the site.
Signing in sets a session cookie so that the site knows who you are between pages. It is used for authentication and for nothing else.
Inside the workspace, tasks, comments, meetings and their attendance records are retained until deleted, and an audit trail of changes to a task is retained indefinitely. Profile photographs and task attachments are stored on Vercel Blob and are served from URLs that are not behind the login gate — anyone holding the URL can open the file.
6. If you use the Android app
The CAPITA1 Android app shows the same public information as the site and needs no account. Most of what you do in it stays on the phone: the IPOs you track, the applications you add to them and their reminder settings, calculator inputs and results, mock-test answers and your display preferences are kept in the app’s own storage on the device and are not sent to us. Android backups and device-to-device transfers leave all of that out, so a new phone starts empty.
If you place the app’s home-screen widget, the app also keeps a small copy of what the widget shows in its own storage on the phone: a few of the IPOs you track, each with its name, what is due and when. Anyone who can see your home screen can see them. The widget never shows or stores a PAN, an application’s name or an amount, that copy is left out of Android backups, and uninstalling the app deletes it.
If you tap “Add the dates to my calendar”, the app writes each IPO’s name and dates, with its board, its price band and a link to its page on this site, into a calendar on your phone. To do that it reads the list of calendars on the phone, to pick the one to write into, and that day’s entries in that calendar, only to avoid adding the same one twice. If that calendar belongs to an account, such as a Google account, the entries sync to that account’s provider like any other entry, and uninstalling the app does not remove them.
- Screen analytics stay on until you turn them off with the “Which screens are opened” switch in the app’s Privacy settings. While on, the app sends the same first-party analytics described in section 2 (the event name, the time, the screen and whether you were signed in) together with the platform, the app version and a few details of the event, such as which calculator was shared or which research symbol was opened, and they are deleted after 180 days. The app reads no advertising identifier and contains no advertising or third-party analytics code.
- The app has a crash-report setting, off by default, but no crash-reporting service is connected to it, so no crash report leaves the phone.
- If you sign in to the members area, the app keeps the session cookie on the phone, as a browser would, and remembers the email address of your last successful sign-in so the field is filled in next time. That address is kept in the phone’s secure keystore storage. Your password is never stored.
- Whether or not you use IPO alerts, the Firebase SDK in the app registers the app installation with Google when the app starts. That registration sends Google an installation identifier, a messaging token, the app version and the versions of Android, Google Play services and the SDK. The app never reads them, and none of them is sent to us.
- If you allow notifications and keep “IPO date reminders” on, the app subscribes the phone to Firebase Cloud Messaging topics: one for each mainboard IPO you track, ipo-wake-<name>, named after that IPO. Messages on it carry no text to show; they let the app set that IPO’s reminders again. Tapping “Self-test alarms” in “Check alert delivery” also subscribes the phone to ipo-wake-selftest for 30 minutes. That topic carries a test message and nothing about any IPO, and if the app is not open when the 30 minutes end, the phone stays subscribed to it until the app is next opened. Google, which operates Firebase, can therefore see which topics the phone follows, and so which IPOs you track, together with an identifier Firebase assigns to the app installation. The app never sends that identifier to us, and we cannot see who follows a topic. Turning “IPO date reminders” off unsubscribes the phone from every one of these topics, and stopping tracking an IPO unsubscribes it from that IPO’s topic. If you withdraw notification permission in Android settings instead, the app unsubscribes the phone from all of them at the latest the next time the app starts.
- When you pick the UPI app a mandate arrives in, the app reads the list of UPI apps installed on the phone to show you the choices. That list is read on the phone only and is never sent anywhere.
Adding a PAN to an IPO application is optional. A PAN you add is kept only in the phone’s secure keystore storage, and the app shows it back to you only as its last four characters. It is never sent to us, and it never appears in a notification, in analytics or in a crash report. Android backups leave it out, so it does not move to a new phone. “Forget my PANs” in the app’s Privacy settings deletes every PAN stored on the phone and the list of saved PANs, and uninstalling the app deletes them too. A saved PAN is kept once per person: the PAN itself in the phone’s secure keystore storage, and, in the app’s own storage on the phone, its last four characters and a name, the application’s, which you can change in Privacy settings.
If you use the app to check an IPO allotment at a registrar it supports, it opens the registrar’s own allotment page inside the app, and asks for your agreement before it first opens that registrar’s page. You type the PAN into that page yourself, and the registrar and the security or CAPTCHA services its page uses see what you type, as they would in a browser. In this version the app types nothing into that page, so a PAN you type there goes to the registrar and never to us. “Revoke”, in the app’s Privacy settings, withdraws that agreement, and the app then asks again before the next check.
The app’s About screen also holds a tool used to build the allotment check. Tapping the version row five times within four seconds offers to export a registrar’s page: after you agree, the app opens that registrar’s own page as the allotment check does, and when you press Export it cuts the page down on the phone to its structure and visible text, removing hidden fields, typed values, scripts and tokens, and replacing names, PANs, application numbers and DP IDs printed beside a label. A name printed without a label can remain. What is left is handed only to Android’s share sheet: the app writes no file, copies nothing to the clipboard and sends it nowhere itself, so it goes only where you choose to share it.
Uninstalling the app deletes everything it stored on the phone, except entries it added to your calendar.
7. Advertising
The site does not currently display advertising, and no advertising cookies are set beyond the Google Analytics cookies described above.
If advertising is introduced, third-party vendors including Google may use cookies to serve ads based on your prior visits to this or other websites. Google’s use of advertising cookies enables it and its partners to serve ads based on your visit to this and other sites, and you may opt out of personalised advertising through Google’s Ads Settings. Where required — including for visitors in the European Economic Area, the United Kingdom and Switzerland — consent will be collected through a certified consent management platform before any such cookie is set, and this section will be updated at the same time.
8. Who else your data reaches
We do not sell personal data and we do not share it for anyone else’s marketing. The processors below are the only third parties involved, and each receives only what its function requires.
- Vercel — hosts the site, and therefore sees request logs including IP addresses.
- MongoDB Atlas — stores the records described above.
- Google — Analytics, as described in section 2.
- Upstash — holds short-lived rate-limiting counters keyed by IP address.
- Resend — delivers email to people who requested access or who hold an account.
- Google Gemini and Groq — process the text of an AI request when an AI feature is used. Requests are not sent with your identity attached.
- Google Firebase Cloud Messaging — delivers notifications to the Android app, receives the identifiers its SDK registers when the app starts, and holds that phone’s topic subscriptions, as described in section 6.
Some of these providers operate outside India, so data reaching them is processed abroad.
9. Your choices
- You can block or delete cookies in your browser. The site remains readable; only your theme preference and analytics are affected.
- You can opt out of Google Analytics using Google’s browser add-on.
- You can ask what we hold on you, ask for it to be corrected, or ask for it to be deleted, by writing to support@capita1.in.
- You can use the site without an account. Almost all of it is public.
- In the Android app, screen analytics can be switched off in its Privacy settings, and IPO notifications with the “IPO date reminders” switch in its Settings. “Forget my PANs”, in the same Privacy settings, deletes every PAN stored on the phone. Uninstalling the app deletes what it stored on the phone, except entries it added to your calendar, which you delete in your calendar app.
10. Children
The site is intended for adults making their own decisions about securities markets. It is not directed at children, and we do not knowingly collect personal data from anyone under 18.
11. Changes to this policy
This policy changes when the site does. The date at the top is the date it last changed. Material changes are described here rather than announced separately, so the top of this page is the place to check.
Last updated 13 September 2026. This policy sits alongside the Terms of Use and Website Disclaimer, which govern your use of the site.
See also the Terms of Use & Website Disclaimer. To ask what we hold on you or to have it deleted, write to support@capita1.in.

