EdgeHabit Privacy Policy
Last updated: 28 July 2026 • Effective date: 28 July 2026
Last updated: 28 July 2026
Effective date: 28 July 2026
Website/App: EdgeHabit
Operator status: Founder-operated early-stage product from India
Public support email: [email protected]
Privacy and data-deletion email: [email protected]
Business correspondence: Operated from India; formal notices and verified requests may be sent by email to [email protected]
1. Introduction
EdgeHabit is currently a founder-operated early-stage product from India. It is being tested and improved with early users. It is not currently incorporated as a company, LLP, or partnership. This does not reduce our responsibility to handle account data, trading data, and uploaded trade files carefully.
This Privacy Policy explains how EdgeHabit collects, uses, stores, processes, shares, protects, retains, and deletes personal data and related trading information when you use our website, app, import tools, analytics, replay tools, AI-assisted features, and related services (together, the "Service").
"EdgeHabit", "we", "us", and "our" mean the founder/operator of the EdgeHabit product. EdgeHabit is currently an early-stage, founder-operated product from India and is not currently incorporated as a company, LLP, or partnership. If EdgeHabit is later incorporated, assigned, transferred, or operated through a registered entity, this Policy may be updated to reflect the new operator.
By using EdgeHabit, creating an account, uploading files, subscribing to a plan, or using any feature, you acknowledge this Privacy Policy.
If you do not agree, do not use EdgeHabit.
2. Scope of this Policy
This Policy applies to:
- EdgeHabit account holders;
- users of a broker connection that EdgeHabit may enable in the future after broker-specific review;
- users who upload trade data, files, screenshots, or journal records;
- users who use charting, replay, analytics, AI-assisted, or coaching features;
- visitors to our website;
- people who contact support, sales, or grievance channels.
This Policy does not apply to third-party brokers, exchanges, data vendors, payment processors, authentication providers, or external websites that have their own privacy policies.
3. What EdgeHabit does
EdgeHabit is a private trading journal, analytics, replay, and behavioral-review platform. Users may upload or manually enter their own trading data, review their own trades, view analytics, create notes and tags, use chart/replay tools, and receive AI-assisted or rule-based review prompts. Public broker sync is currently coming soon and is not generally available.
EdgeHabit is not a broker, exchange, investment adviser, portfolio manager, research analyst, depository participant, or custodian unless separately and expressly stated in writing.
4. Personal data we collect
Depending on how you use EdgeHabit, we may collect the following categories of information.
4.1 Account information
This may include:
- name;
- email address;
- mobile number, if provided;
- username or account identifier;
- password hash or authentication-provider identifier;
- profile photo, if provided;
- timezone and language;
- account settings;
- plan and feature preferences;
- support and grievance communications.
4.2 Broker connection information
EdgeHabit does not currently offer public broker connections unless a broker-specific screen expressly says that the integration is enabled. If an integration is enabled after broker-specific review, we may collect or process only the information required by that broker's approved connection method, such as:
- broker name;
- broker client ID or user ID;
- broker account alias;
- broker-issued authorization, access, refresh, or session tokens;
- an API key, client ID, app code, or API secret only where the broker expressly permits that method for a third-party service;
- token expiry time;
- connection status;
- sync settings;
- rate-limit status;
- broker error messages;
- metadata needed to maintain the integration.
The exact fields vary by broker and connection method and will be disclosed on the relevant connection screen before collection. A broker name or logo on EdgeHabit does not mean that the broker has approved, endorsed, or partnered with EdgeHabit.
4.3 Trade and account data
When you import data from a broker, upload files, or manually enter records, we may collect or process:
- orders;
- trades;
- executions;
- positions;
- holdings;
- margins or funds data, where supported;
- symbol and instrument details;
- quantities and prices;
- charges, taxes, brokerage, and P&L;
- trade IDs and order IDs;
- timestamps;
- exchange and segment;
- trade notes;
- tags;
- screenshots;
- journal entries;
- playbooks;
- rules;
- mistake labels;
- review responses;
- performance analytics;
- behavioral analytics.
4.4 Market data and chart/replay data
Where supported and authorized by you, EdgeHabit may process:
- historical candles;
- OHLCV data;
- live or delayed quotes;
- option-chain data;
- instrument metadata;
- chart overlays;
- replay windows;
- indicator inputs and outputs;
- derived candles or aggregated intervals;
- cache metadata, coverage status, and data-quality flags.
Market data may be subject to broker, exchange, API, or data-vendor terms.
4.5 Uploaded files and media
We may collect files you upload, including:
- CSV files;
- spreadsheets;
- contract notes;
- tradebooks;
- orderbooks;
- screenshots;
- images;
- exports from brokers or trading platforms;
- documents submitted for support or debugging.
4.6 Device, usage, and technical data
We may collect:
- IP address;
- browser type;
- device type;
- operating system;
- app version;
- pages visited;
- feature usage;
- login events;
- API request metadata;
- crash logs;
- error logs;
- security logs;
- cookies or local storage identifiers;
- approximate location derived from IP address;
- referral source;
- performance and diagnostic data.
4.7 Billing and payment information
We may collect:
- plan type;
- subscription status;
- invoice details;
- tax details where required;
- payment provider customer ID;
- transaction reference;
- billing email;
- refund and cancellation records.
We normally do not store full card, UPI, bank, or wallet credentials. Payments are processed by third-party payment providers subject to their own policies.
4.8 AI and coaching interaction data
If you use AI-assisted or coaching features, we may process:
- prompts;
- selected trades or notes sent for analysis;
- AI-generated summaries;
- coaching responses;
- review questions;
- behavioral labels;
- feedback on outputs;
- metadata required to improve safety, quality, and reliability.
5. Broker passwords, OTPs, and TOTP
Do not submit your broker login password, PIN, MPIN, OTP, TOTP code, or TOTP seed to EdgeHabit. EdgeHabit will not launch a public broker connection that requires us to collect or retain those login factors.
Where a future integration uses a broker-hosted login or redirect flow, you will enter those factors directly on the broker's own page. EdgeHabit will receive only the authorization data that the broker provides for the approved integration.
If a broker expressly permits a different method for third-party services, the connection screen will identify the fields, purpose, storage, retention, and revocation method before you connect. EdgeHabit will not treat a personal retail API flow as permission for a public SaaS integration.
6. How we collect information
We collect information from:
- you directly, when you sign up, enter details, upload files, write notes, or contact support;
- your authorized broker or trading platform, if you use a future broker-approved integration;
- third-party authentication, payment, hosting, analytics, monitoring, support, or communication providers;
- your device and browser, through logs, cookies, and technical telemetry;
- automated calculations inside EdgeHabit.
7. Why we use your data
We use your data to:
- create and manage your account;
- authenticate you and secure your session;
- provide file import and manual-entry features, and broker import only where an approved integration is enabled;
- fetch, normalize, store, and display your own trading data;
- provide charts, candles, replay, analytics, statistics, reports, rules, playbooks, and dashboards;
- generate AI-assisted summaries, behavioral insights, coaching prompts, and review tools;
- process subscriptions, invoices, payments, refunds, and plan limits;
- provide customer support and resolve bugs;
- maintain security, prevent abuse, detect fraud, and investigate incidents;
- comply with legal, tax, accounting, audit, security, regulatory, and dispute-resolution obligations;
- improve product quality, reliability, and user experience;
- send service messages, alerts, and important account notices;
- send marketing messages where permitted and subject to opt-out rights.
8. Legal basis and consent
Where consent is required, we request it for a specified purpose at the relevant action. Acknowledging this Policy alone does not authorize optional broker access, marketing, or another unrelated purpose.
Consent may be requested when you:
- create an account;
- connect a future broker-approved integration;
- upload files;
- enable optional features;
- subscribe to communications;
- submit support or grievance requests.
You may withdraw consent for optional processing by disconnecting the relevant integration, changing settings, closing your account, or contacting us.
Withdrawal of consent does not affect processing already completed before withdrawal. It may also prevent us from providing the related feature.
We may also process data where necessary to provide the Service, perform our contract with you, secure the platform, prevent fraud, comply with law, maintain records, or defend legal claims.
9. How we use broker credentials
Public broker sync is currently coming soon. EdgeHabit will enable a broker connection only after confirming that the proposed method is permitted for EdgeHabit's third-party, read-only use case. Availability may differ by broker and may be withdrawn.
If an approved integration is enabled and you authorize it, EdgeHabit will use the broker-issued authorization data only for the disclosed functions.
This may include:
- connecting your broker account;
- generating or refreshing authorized sessions;
- importing your own trades, orders, positions, holdings, and related data;
- fetching your own chart/replay/candle data where your broker and subscription allow it;
- checking connection status;
- debugging failed syncs;
- respecting broker rate limits and session expiry.
Any retained broker-issued token or permitted credential will be encrypted in transit and encrypted at rest. Temporary verification factors will not be retained.
We do not intentionally use one user's broker credentials or broker data for another user.
We do not sell broker authorization data.
We do not intentionally expose broker authorization data in client-side source code, public pages, normal frontend responses, or ordinary logs.
10. India data hosting and data residency
For Indian users, EdgeHabit follows an India-first hosting and storage approach for core product data.
Unless we clearly disclose otherwise for a specific feature, the following categories of data are intended to be stored and processed in India for ordinary production use:
- account and profile data;
- authorization data and broker-connection metadata if a broker-approved integration is later enabled;
- imported trades, orders, positions, holdings, and related broker account data;
- trading journal notes, tags, screenshots, playbooks, rules, behavioral-review records, and analytics;
- uploaded trade files, CSV files, spreadsheets, contract notes, and broker exports;
- user-scoped historical candle, chart, and replay caches fetched through the user's own broker/API entitlement;
- database backups, security logs, audit logs, access logs, and incident-response records where technically supported.
If a broker-approved integration is enabled, we do not intend to use foreign servers for ordinary storage of its authorization data, raw broker-fetched trading data, or user-scoped candle/replay cache for Indian users.
We may still use limited third-party providers for support, email delivery, customer communication, analytics, error monitoring, payment processing, or similar operational needs. Where we do this, we minimise the personal data shared and avoid sending raw trading journal data or future broker authorization data unless necessary for the feature, required by law, or separately disclosed.
If a future feature requires processing outside India, we will provide notice where required, use reasonable safeguards, and comply with applicable Indian law, broker terms, exchange rules, and government notifications.
11. User-scoped data and no public market-data display
EdgeHabit is designed as a private user workspace.
This means:
- your broker-connected trading data is intended for your own account;
- your market-data cache, where used, is intended to serve your own private workspace;
- EdgeHabit does not intentionally display your private broker-connected data to other users;
- EdgeHabit does not sell your raw trading history;
- EdgeHabit does not sell broker authorization data;
- EdgeHabit does not use your market-data entitlement to serve market data to other users;
- EdgeHabit does not grant any independent right to redistribute market data.
If you choose to use an optional sharing, export, mentor, public-link, screenshot, team, or classroom feature, you are responsible for ensuring that you have the right to share the content.
12. Market data and third-party rights
Market data may be owned, licensed, restricted, or controlled by brokers, exchanges, data vendors, or other third parties.
EdgeHabit may display or process market data only as part of the Service and subject to your own entitlements, broker/API permissions, and applicable third-party terms.
You should not use EdgeHabit to:
- publicly display restricted market data;
- resell or redistribute market data;
- build a shared data feed;
- scrape or export market data in violation of third-party terms;
- bypass broker, exchange, or vendor controls.
EdgeHabit may limit, block, delete, or disable market-data features where required by law, broker terms, exchange rules, vendor terms, or risk controls.
13. AI-assisted features and third-party processors
If you use AI-assisted features, selected data may be processed by EdgeHabit and/or third-party AI infrastructure providers to generate summaries, review prompts, coaching suggestions, or other outputs.
We aim to send only the data reasonably needed for the feature. However, the exact data may depend on the feature you use.
AI outputs may be inaccurate or incomplete and are not financial, investment, legal, tax, or trading advice.
Where possible, we configure processors and internal controls to protect user data, but no AI system is perfect.
14. Cookies and similar technologies
We may use cookies, local storage, pixels, device identifiers, and similar technologies to:
- keep you logged in;
- secure your session;
- remember preferences;
- analyze usage;
- improve performance;
- detect abuse;
- support payments, analytics, or customer support.
You can control some cookies through your browser settings. Disabling cookies may affect functionality.
15. How we share information
We do not sell your personal data or private trading journal data.
We may share data only in the following situations:
15.1 Service providers
We may share data with vendors who help us operate EdgeHabit, such as:
- cloud hosting providers;
- database and storage providers;
- authentication providers;
- payment processors;
- email and communication providers;
- monitoring and logging providers;
- analytics providers;
- customer-support tools;
- AI infrastructure providers;
- security and incident-response providers.
These providers may process data only as needed to provide services to us, subject to contractual and technical safeguards where applicable.
15.2 Brokers and third-party integrations
If you use a future broker-approved integration, we may exchange information with that broker or platform only as needed to provide the disclosed connection.
15.3 Legal and safety reasons
We may disclose information if required or reasonably necessary to:
- comply with law;
- respond to lawful requests;
- enforce our Terms;
- prevent fraud or abuse;
- investigate security incidents;
- protect rights, safety, or property;
- defend legal claims.
15.4 Business transfers
If EdgeHabit is involved in a merger, acquisition, financing, restructuring, sale of assets, or similar transaction, user data may be transferred subject to reasonable confidentiality and continuity protections.
15.5 With your direction
We may share data when you intentionally use a feature that shares, exports, publishes, or sends information.
16. Data retention
We retain data only for as long as reasonably necessary for the purposes described in this Policy, unless a longer period is required or permitted by law.
Our general retention approach is:
| Data category | Typical retention |
|---|---|
| Account profile | While your account is active |
| Trading journal data | While your account is active, unless deleted earlier |
| Broker authorization data | Not collected while an integration is unavailable; if enabled, only while needed for the active connection |
| Access tokens/session tokens | Until expiry, disconnection, deletion, or replacement |
| Uploaded files | While needed for import, review, support, or your account history |
| Candle/replay cache | While needed for your private workspace, subject to cache expiry, deletion, or retention settings |
| Billing records | As required for accounting, tax, dispute, and legal purposes |
| Support records | As needed for support, dispute, quality, and legal purposes |
| Security and audit logs | Stored in India where required and retained for security, incident response, and applicable legal obligations |
| Backups | Until overwritten or expired in the ordinary backup cycle |
Security and audit logs are maintained within Indian jurisdiction where required. CERT-In directions may require covered entities to retain ICT logs securely for 180 days. Additional periods under the Digital Personal Data Protection framework apply only as and when the relevant provisions become effective and apply to EdgeHabit.
17. Broker disconnection
If a broker-approved integration is enabled, disconnecting it will stop future syncing from that broker.
Disconnection will delete or render unusable the stored authorization data for that broker connection, subject to short-lived operational copies and legal or security retention requirements.
Previously imported trades, journal entries, analytics, or derived records may remain in your EdgeHabit account unless you separately delete them or request account/data deletion.
If a broker-approved integration is enabled and you want its authorization data, imported broker data, and related user-scoped cache removed, use the available deletion controls or contact us at [email protected]. Deletion of the connection will remove or render unusable its stored authorization data, subject to legal, security, backup, and short-lived operational retention.
18. Account deletion and data deletion
You may request deletion of your account or personal data by using in-app controls or contacting us at [email protected].
Using Clerk's in-app Delete account control triggers signed deletion of the linked active EdgeHabit database records and user-owned files. Failed webhook deliveries are retried; you may contact us if deletion does not complete.
After verifying the request, we will delete or anonymize eligible data within a reasonable period, subject to:
- legal obligations;
- tax and accounting requirements;
- fraud prevention;
- security investigation;
- dispute resolution;
- chargeback handling;
- backup cycles;
- technical limitations;
- compliance with broker, exchange, or regulatory obligations.
Deletion may not be immediate across backups, logs, and archives, but such retained data will be protected and removed according to normal retention cycles unless legally required to keep it longer.
19. Your rights
Subject to applicable law and reasonable verification, you may request:
- confirmation of whether we process your personal data;
- access to a summary of your personal data;
- correction of inaccurate personal data;
- completion or updating of incomplete personal data;
- deletion of personal data that is no longer necessary;
- withdrawal of consent for optional processing;
- grievance redressal;
- nomination of another person to exercise your rights in case of death or incapacity, where applicable under law.
To exercise rights, contact [email protected].
We may ask for information to verify your identity before fulfilling a request.
20. Marketing choices
You may opt out of marketing emails by using the unsubscribe link or contacting us.
Even if you opt out of marketing, we may still send service messages such as security alerts, account notices, payment notices, broker-connection warnings, policy updates, and important operational communications.
21. Data security
We use reasonable administrative, technical, and organizational safeguards designed to protect your data.
These may include:
- encryption in transit;
- encryption at rest for sensitive fields where supported;
- access controls;
- authentication controls;
- logging and monitoring;
- infrastructure security;
- backup procedures;
- incident-response processes;
- least-privilege internal access;
- secret masking where practical;
- vendor security review where appropriate;
- Indian-region hosting for core Indian-user production data where technically supported.
No method of transmission or storage is completely secure. We cannot guarantee absolute security.
22. Internal access to user data
EdgeHabit personnel, contractors, or support providers may access user data only where reasonably needed for:
- support requested by you;
- debugging;
- security investigation;
- abuse prevention;
- legal compliance;
- product maintenance;
- billing or account administration.
Access may be logged and limited based on role and necessity where technically supported.
23. Data accuracy
We rely on data from you, your broker, uploaded files, APIs, and third-party providers.
We do not guarantee that imported or derived data is always complete, accurate, or up to date.
You are responsible for verifying data before relying on it for trading, tax, accounting, or legal purposes.
24. International transfers and limited non-India processing
EdgeHabit's core production data for Indian users is intended to be hosted in India as described in the India data hosting section above.
We do not treat international processing as the default for raw trading data, uploaded trade files, security/audit logs, or future broker authorization data.
However, limited non-India processing may occur where:
- a non-core operational provider is used for email delivery, customer support, analytics, payment routing, error monitoring, or similar business operations;
- you intentionally use a feature that requires an external provider;
- the transfer is required for legal, security, abuse-prevention, incident-response, or dispute-resolution purposes;
- the transfer is permitted under applicable Indian law and is not prohibited by any government notification, broker term, exchange rule, or sector-specific rule that applies to us.
Where international processing occurs, we use reasonable contractual, technical, and organisational safeguards. We may modify, restrict, or disable any feature if we believe a transfer or processing arrangement creates legal, regulatory, broker, exchange, or security risk.
Payment data may be processed by payment gateways or payment processors. EdgeHabit does not intend to store full card numbers, UPI PINs, net-banking passwords, or similar payment credentials. Payment-system providers remain responsible for their own regulatory and data-localisation obligations where applicable.
25. Children's privacy
EdgeHabit is not intended for children or persons below the legal age required to enter into these Terms.
We do not knowingly collect personal data from children.
If you believe a child has provided personal data to us, contact us and we will take appropriate steps.
26. Data breach and incident response
If we become aware of a personal-data breach or security incident affecting your data, we will take steps consistent with applicable law and our incident-response procedures.
This may include investigation, containment, remediation, notification to affected users, and notification to authorities where required.
27. Third-party links and services
EdgeHabit may contain links to third-party websites, brokers, exchanges, documentation, payment pages, or other external services.
We are not responsible for the privacy practices, security, content, or policies of third-party services.
Review their policies before using them.
28. Changes to this Privacy Policy
We may update this Privacy Policy from time to time.
If changes are material, we will provide notice through the Service, email, or another reasonable method.
Your continued use of EdgeHabit after the updated Policy becomes effective means you accept the updated Policy.
If you do not agree, you should stop using the Service and may request account deletion.
29. Contact and grievance details
For privacy questions, rights requests, data deletion, consent withdrawal, broker credential concerns, or grievances, contact:
Privacy / Grievance contact: Founder / Operator of EdgeHabit
Email: [email protected]
Support email: [email protected]
Business correspondence: Operated from India; formal notices and verified requests may be sent by email to [email protected]
Response target: We aim to respond within 30 days, or earlier where required by applicable law.
Please include enough information for us to identify your account and understand your request. For security reasons, we may ask you to verify your identity before processing account deletion, broker credential deletion, export, or access requests.
30. Final privacy summary
In simple terms:
- EdgeHabit is a private trading journal and analytics platform.
- You may connect your own broker/API account or upload your own trading data.
- We use your data to provide your private workspace and the features you enable.
- If a broker-approved connection is enabled, we do not use its authorization data or private broker data for another user.
- We do not sell your private trading journal data.
- Market data rights remain subject to broker, exchange, API, and vendor terms.
- You can disconnect integrations and request deletion, subject to legal, security, and retention exceptions.
- You remain responsible for your own trading decisions and third-party subscriptions.