How White Stallion AI handles your data.
Last updated: April 18, 2026
Summary: Your portfolio data stays on your device. We use anonymous analytics to improve the app — you can disable this at any time. We do not sell your data. We comply with India's DPDP Act and the EU GDPR.
White Stallion AI is a client-side application. The following NEVER leaves your device:
All calculations (WSS scores, technicals, risk profile, strategy payoffs) run locally in your browser.
We use PostHog (EU-hosted, GDPR-compliant) to understand how White Stallion is used in aggregate.
import_committed, tour_completed, stock_detail_openedPostHog Cloud EU (Frankfurt, Germany). Data is processed in accordance with GDPR Article 28. You can request deletion any time by contacting whitestallionai@gmail.com.
Open White Stallion → Settings → Analytics → toggle off. Once disabled, no events will be sent. Already-captured data can be deleted on request.
If you choose to sign in with Google:
White Stallion supports connecting your broker account for live prices, option chains, and portfolio sync. Supported brokers are listed inside the app and change over time. This is fully optional — every core feature works without a broker connection using free price feeds.
When you connect a broker, here's exactly what happens:
localStorage. The encryption key is derived per-session, never transmitted.If you've enabled Google Drive sync (see §3), portfolio snapshots derived from broker data are saved to your own Drive in a private app folder. Broker tokens themselves are never synced to Drive.
The app makes real-time requests to third-party data services to fetch market data for the stocks, funds, and indices you view. Specific providers change over time as we optimize for reliability and cost; categories below are durable:
| Category of service | Purpose | Data sent |
|---|---|---|
| Market data providers | Stock and index prices, OHLCV history | Ticker symbol or ISIN |
| Mutual fund data providers | NAV lookups for the schemes you view | Scheme code |
| Fundamentals providers | P/E, P/B, ROE, and company financials | Stock symbol |
| AI providers | Responses for the "Ask Stallion" feature | Your query text; portfolio summary only if you opt in |
| Broker APIs | Live quotes, option chains, holdings sync (when you connect a broker) | See §3.5 above |
We do not send portfolio amounts, personal identifiers, or financial account numbers in any of these requests.
The app runs on standard cloud infrastructure. The following categories of providers may process request metadata (IP address, request path, timestamp) in the normal course of serving the site:
None of these providers receive your portfolio data, broker tokens, or personal financial information. They handle only the normal request metadata any website generates.
We use Google AdSense to display ads. AdSense may use cookies to serve relevant ads. You can manage ad personalization via Google Ads Settings.
To exercise any right, email whitestallionai@gmail.com. We'll respond within 30 days.
White Stallion uses browser localStorage (not cookies) for its own state. AdSense and PostHog may set cookies as described above. PostHog's cookie usage can be disabled entirely by opting out of analytics in Settings.
White Stallion is not directed at children under 18. If you are under 18, please do not use the service. If we become aware that personal data of a minor has been collected, we will delete it promptly.
We may update this policy. Material changes will be announced via in-app banner. The "Last updated" date at the top of this page always reflects the current version.
For any privacy question, email whitestallionai@gmail.com.
In compliance with Section 8 of India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, White Stallion AI has designated a Grievance Officer for the redressal of complaints related to personal data processing.
| Designation | Grievance Officer, White Stallion AI |
|---|---|
| whitestallionai@gmail.com | |
| Response SLA | 30 days from receipt of complaint |
| Submit a complaint | /grievance form |
| Track a complaint | /grievance/track |
| Data class | Retention period | Location |
|---|---|---|
| User portfolio (CSV uploads) | Browser-only · cleared on cache clear | User device (IndexedDB) |
| Anonymous product analytics | 365 days | PostHog EU Cloud |
| Rate-limit counters | 1 minute (sliding) | Upstash KV (Mumbai) |
| Encrypted backups | 90 days rolling | Supabase Storage (Mumbai) |
| Grievance tickets | 3 years (legal retention) | Supabase Postgres (Mumbai) |
| Server access logs | 30 days | Vercel logs |
Under DPDP Act 2023, you have the right to:
To exercise any right, email our Grievance Officer or use the grievance form.
Current version: 1.1.0
Last updated: 2026-04-27
If this policy materially changes, registered users will be prompted to re-confirm consent on next visit. The changelog below records material changes.