Privacy Policy
Last updated: 18 August 2026
This policy explains what personal data MF Lens processes and why. It is written with India's Digital Personal Data Protection Act, 2023 (DPDP Act) in mind.
1. What we collect
- Account data: email address (Google sign-in) or mobile number (OTP sign-in), and a user identifier.
- Subscription data: plan, status and payment-processor references. Card details are handled by our payment processor and never reach our servers.
- Usage data: analyses run, AI analyst queries and counts, error logs, and coarse technical data (timestamps, request metadata) needed to operate and secure the Service.
2. Why we use it (purpose)
- To authenticate you and keep your session secure.
- To deliver the analytics you request and enforce plan limits and fair use.
- To prevent abuse, SMS pumping and fraud.
- To handle billing, support and legal obligations.
We do not sell personal data and we do not use your mobile number for marketing SMS. OTP messages are transactional only.
3. Retention
- One-time passcodes: deleted on use, and in any case expire within minutes.
- Account and subscription records: kept while the account exists, plus the period we are legally required to retain financial records.
- Usage and diagnostic logs: retained for a limited operational period, then deleted or aggregated.
4. Processors
We rely on infrastructure and service providers to run the product: our cloud/database and authentication provider, our SMS gateway for OTP delivery, our payment processor for subscriptions, and an AI provider that powers the analyst feature. They process data only on our instructions.
5. Your rights
You may request access to, correction of, or erasure of your personal data, withdraw consent, or nominate another person to exercise your rights on your behalf. Deleting your account removes your profile and usage history. To exercise any right, or to raise a grievance, contact support@mutualfundlens.app. We respond within 7 working days.
6. Security
Access to data is protected by row-level authorisation, encrypted transport (HTTPS/HSTS), content-security and anti-clickjacking headers, rate limiting on the OTP endpoint and server-side entitlement checks. No system is perfectly secure; report suspected issues to the contact above.
7. Children
The Service is not intended for users under 18.
8. Changes
Material changes are reflected in the "last updated" date at the top of this page.