White Stallion AI  › Home › Privacy

Privacy Policy

How White Stallion AI handles your data.

Last updated: April 18, 2026

Summary: Your portfolio data stays on your device. We use anonymous analytics to improve the app — you can disable this at any time. We do not sell your data. We comply with India's DPDP Act and the EU GDPR.

1. Data we do NOT collect

White Stallion AI is a client-side application. The following NEVER leaves your device:

All calculations (WSS scores, technicals, risk profile, strategy payoffs) run locally in your browser.

2. Anonymous usage analytics

We use PostHog (EU-hosted, GDPR-compliant) to understand how White Stallion is used in aggregate.

What we capture

What we do NOT capture

Where it's stored

PostHog Cloud EU (Frankfurt, Germany). Data is processed in accordance with GDPR Article 28. You can request deletion any time by contacting whitestallionai@gmail.com.

How to disable

Open White Stallion → SettingsAnalytics → toggle off. Once disabled, no events will be sent. Already-captured data can be deleted on request.

3. Google Sign-In (optional)

If you choose to sign in with Google:

3.5. Broker connections (optional)

White Stallion supports connecting your broker account for live prices, option chains, and portfolio sync. Supported brokers are listed inside the app and change over time. This is fully optional — every core feature works without a broker connection using free price feeds.

When you connect a broker, here's exactly what happens:

What we ask brokers for

What we never do with broker access

Token expiry and disconnection

If you sync to Google Drive

If you've enabled Google Drive sync (see §3), portfolio snapshots derived from broker data are saved to your own Drive in a private app folder. Broker tokens themselves are never synced to Drive.

4. Third-party data services

The app makes real-time requests to third-party data services to fetch market data for the stocks, funds, and indices you view. Specific providers change over time as we optimize for reliability and cost; categories below are durable:

Category of servicePurposeData sent
Market data providersStock and index prices, OHLCV historyTicker symbol or ISIN
Mutual fund data providersNAV lookups for the schemes you viewScheme code
Fundamentals providersP/E, P/B, ROE, and company financialsStock symbol
AI providersResponses for the "Ask Stallion" featureYour query text; portfolio summary only if you opt in
Broker APIsLive quotes, option chains, holdings sync (when you connect a broker)See §3.5 above

We do not send portfolio amounts, personal identifiers, or financial account numbers in any of these requests.

4.5. Infrastructure providers

The app runs on standard cloud infrastructure. The following categories of providers may process request metadata (IP address, request path, timestamp) in the normal course of serving the site:

None of these providers receive your portfolio data, broker tokens, or personal financial information. They handle only the normal request metadata any website generates.

5. Advertising

We use Google AdSense to display ads. AdSense may use cookies to serve relevant ads. You can manage ad personalization via Google Ads Settings.

6. Your rights (GDPR + DPDP Act)

To exercise any right, email whitestallionai@gmail.com. We'll respond within 30 days.

7. Cookies

White Stallion uses browser localStorage (not cookies) for its own state. AdSense and PostHog may set cookies as described above. PostHog's cookie usage can be disabled entirely by opting out of analytics in Settings.

8. Children's privacy

White Stallion is not directed at children under 18. If you are under 18, please do not use the service. If we become aware that personal data of a minor has been collected, we will delete it promptly.

9. Changes to this policy

We may update this policy. Material changes will be announced via in-app banner. The "Last updated" date at the top of this page always reflects the current version.

10. Contact

For any privacy question, email whitestallionai@gmail.com.

11. Grievance Officer (DPDP Act 2023)

In compliance with Section 8 of India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, White Stallion AI has designated a Grievance Officer for the redressal of complaints related to personal data processing.

DesignationGrievance Officer, White Stallion AI
Emailwhitestallionai@gmail.com
Response SLA30 days from receipt of complaint
Submit a complaint/grievance form
Track a complaint/grievance/track

12. Data Retention

Data classRetention periodLocation
User portfolio (CSV uploads)Browser-only · cleared on cache clearUser device (IndexedDB)
Anonymous product analytics365 daysPostHog EU Cloud
Rate-limit counters1 minute (sliding)Upstash KV (Mumbai)
Encrypted backups90 days rollingSupabase Storage (Mumbai)
Grievance tickets3 years (legal retention)Supabase Postgres (Mumbai)
Server access logs30 daysVercel logs

13. Your Rights as a Data Principal

Under DPDP Act 2023, you have the right to:

To exercise any right, email our Grievance Officer or use the grievance form.

14. Policy Version & Updates

Current version: 1.1.0

Last updated: 2026-04-27

If this policy materially changes, registered users will be prompted to re-confirm consent on next visit. The changelog below records material changes.

Version history