Privacy Policy

What we collect, why we collect it, who processes it on our behalf, how long we keep it, and what you can ask us to do with it.

Version
3.0
Last updated
26 September 2026
Previous versions
Available on request
Grievance Officer
Ankith Bharadwaj
Contents · 15 sections
  1. 1Who we are and what this covers
  2. 2What we collect
  3. 3Why we use it, and on what basis
  4. 4Who we share it with
  5. 5Security and breaches
  6. 6Accuracy
  7. 7How long we keep it
  8. 8Your rights
  9. 9Your duties
  10. 10Cookies
  11. 11Children
  12. 12Grievance Officer
  13. 13Changes to this Policy
  14. 14Governing law
  15. 15Definitions
1

Who we are and what this covers

#

Tyche Capital is not a company, LLP or other legal entity. It is a name used by three university graduates in Bengaluru: Kushagra Agarwal, Vedansh Mishra and Ankith Bharadwaj (“we”, “us”, “our”). The three of us jointly decide why and how personal data is processed on this site, so we are jointly the “Data Fiduciary” under the Digital Personal Data Protection Act, 2023 (“DPDP Act”). The obligations in this Policy are owed by us personally.

The DPDP Act’s detailed obligations are being brought into force in phases under the Digital Personal Data Protection Rules, 2025. Until they apply in full, Section 43A of the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 continue to apply where relevant. We follow the DPDP framework now, voluntarily, and will update this Policy as further provisions commence.

This Policy covers everyone who visits tychecapital.co.in or its subdomains (the “Site”), creates an account, or contacts us. Read it with our Terms of Service and Risk Disclosure.

2

What we collect

#
What we collect, from whom, and how
WhoWhat we collectHow we get it
All visitorsIP address, browser and device type, pages requested, date and time, in server and security logs. A strictly necessary cookie recording your cookie-notice choice.Automatically
Anyone who opens a research pieceOne view per reader per piece per day. Signed in, the view is recorded against your account. Signed out, we keep only a one-way hash of your IP address and browser, made with a value that changes every day and is deleted after two days, so it can no longer be linked to you. The address itself is never stored.Automatically
Account holders (email sign-in)Email address; the phone number you give when you create your account, and your name if you give it; a password, which is stored only as a salted hash that no one can read, or one-time sign-in codes sent to your email; account creation and last sign-in times; your confirmation that you are 18 or older and the document versions you accepted.From you
Account holders (Google sign-in)Your name, email address and profile photo, as shared by Google when you choose “Continue with Google”. We do not receive your Google password. The phone number you give when you complete your profile.From Google, at your request; your phone number from you
Account holders reading researchWhere you stopped in each piece and how you set up the reader; the highlights, annotations and notes you make, which only your own account can read; research you submit to us.From you
Anyone who contacts usYour name, email address and whatever you write to us.From you

We do not collect Aadhaar numbers, PAN, bank account, UPI, card or other payment details, or any information about your finances or investments from visitors or account holders. We never ask for them. See “We will never ask you for money” in our Risk Disclosure.

3

Why we use it, and on what basis

#

The DPDP Act permits processing on the basis of your consent (Section 6) or for one of the “certain legitimate uses” in Section 7.

Purposes of processing and their legal basis
PurposeBasis
Creating, securing and operating your account and giving you access to the research archiveYour consent (s.6), given at sign-up
Sending sign-in codes, security alerts, and notices of material changes to our documentsYour consent (s.6), given at sign-up
Replying to messages you send usThe data you voluntarily provided for that purpose (s.7(a))
Keeping the Site secure and preventing abuse, including keeping logsYour consent (s.6), given at sign-up; for visitors without an account, the strictly necessary operation of the Site
Responding to a court order, or to a lawful demand from an authority in IndiaCompliance with a legal obligation to disclose information to the State (s.7(d)), or with a judgment, decree or order (s.7(e))
Keeping records where a law requires itRetention required by law (s.8(7))

We do not use your data for advertising, profiling or automated decision-making, and we do not send marketing emails. If we ever start a newsletter, it will be opt-in only, with a separate consent.

4

Who we share it with

#
4.1

We do not sell, rent or trade your personal data, and we do not share it with advertisers.

4.2

Data Processors. These providers process data on our instructions, under their standard data processing terms, to run the Site:

Data Processors and where they may process data
ProviderWhat it doesWhere data may be processed
Vercel Inc.Hosts and serves the SiteGlobal edge network; server functions in India
Supabase Inc.Database and account authenticationIndia
ResendSends sign-in codes and our emailsIndia
4.3

Google. If you choose “Continue with Google”, Google LLC processes your sign-in as an independent data fiduciary, under Google’s own privacy policy, and shares with us only the data listed in Section 2.

4.4

Transfers outside India. Where data is processed outside India, the transfer is made under Section 16 of the DPDP Act, which permits transfers except to countries the Central Government has restricted by notification. We will update this table if our providers or their regions change.

4.5

Our responsibility. Under Section 8(1) of the DPDP Act, we remain responsible for processing carried out on our behalf by our Data Processors.

4.6

Authorities. We disclose personal data to courts, law-enforcement agencies or regulators in India only where the law or a lawful order requires it.

4.7

Between us. Only the three of us have administrative access to account data. Each of us uses a separate account, and our hosting and database provider accounts are protected by multi-factor authentication. If any of us stops being involved with the Site, their access will be revoked within 7 days.

5

Security and breaches

#
5.1

What we do:

  • All traffic to the Site is encrypted in transit (HTTPS/TLS).
  • Our database provider encrypts stored data by default.
  • Passwords are stored only as salted hashes by our authentication provider. None of us can see your password.
  • Administrative access is limited to the three of us. Our hosting and database provider accounts are protected by multi-factor authentication.
5.2

No system is completely secure, and we cannot guarantee the security of data sent over the internet.

5.3

Personal data breaches. If a personal data breach affects you, we will inform you and the Data Protection Board of India in the form and within the time required by the DPDP Act and Rules. We will tell you what happened, when, the likely consequences, what we have done, and what you can do to protect yourself.

5.4

Cyber security incidents. Where the CERT-In Directions of 28 April 2022 apply to us, we will retain logs and report cyber security incidents as those Directions require.

6

Accuracy

#

We take reasonable steps to keep your account data accurate and complete. You can correct your details at any time by contacting us (Section 8).

7

How long we keep it

#
  • Account data: while your account is open. If you delete your account, we delete or irreversibly anonymise your account data within 30 days. If it is inactive for 12 months, we delete it, after emailing you a week beforehand and again the day before.
  • Contact messages: 12 months after our conversation ends.
  • Security logs: up to 180 days.
  • Legal exceptions: we keep specific data longer only where a law requires it, or where it is needed for an actual or reasonably expected legal claim, and only for as long as that requires.
8

Your rights

#

You have the following rights under the DPDP Act:

  • Access: a summary of the personal data we hold about you, the processing we carry out, and the identities of the Data Fiduciaries and Data Processors we have shared it with, with a description of what was shared.
  • Correction and erasure: to correct, complete or update your data, or to have it erased. If we must keep something for a legal reason, we will tell you what and for how long.
  • Withdraw consent: at any time, as easily as you gave it, by emailing us from your registered email address. Withdrawing consent means we will close your account. It does not affect processing before you withdrew.
  • Nominate: you may nominate another individual to exercise your rights if you die or become incapable.
  • Grievance redressal: to raise a grievance with us (Section 12) and, if we do not resolve it, to complain to the Data Protection Board of India.

How to exercise them: email ankith@tychecapital.co.in from your registered email address. If we cannot confirm a request comes from you, we will ask you to confirm it from that address. We respond within 30 days.

9

Your duties

#

Section 15 of the DPDP Act requires you, among other things, not to impersonate anyone when providing personal data, not to register false or frivolous grievances, and to provide only verifiably authentic information when seeking correction or erasure.

10

Cookies

#

We use only strictly necessary cookies and similar browser storage: to keep you signed in, to secure your session, and to remember your cookie-notice choice. If you use “Continue with Google”, Google may set its own cookies during sign-in. We do not use analytics, tracking, advertising or social media cookies, and we do not use Vercel Web Analytics or any similar analytics tool. You can block cookies in your browser, but you will then be unable to sign in.

Your browser also keeps a few preferences on your device, not on our servers: whether you chose the light or dark theme, and how you last set up the reader and the notes panel.

11

Children

#

You must be 18 or older to create an account, and you confirm this at sign-up. We do not knowingly process the personal data of anyone under 18, and we do not track, behaviourally monitor, or target advertising at children. If we learn that an account belongs to someone under 18, we will close it and delete its data promptly. Anyone may read the Site’s public pages, which set only strictly necessary cookies.

12

Grievance Officer

#

In accordance with the Information Technology Act, 2000, the rules made under it, and the DPDP Act, our Grievance Officer is:

Grievance Officer

Ankith Bharadwaj
ankith@tychecapital.co.in
Bengaluru, Karnataka, India (correspondence by email only)

We acknowledge grievances within five business days and resolve them within 30 days. If we need longer, we will tell you why and give you a date, and in any case we will stay within the maximum period set by the DPDP Rules, 2025.

13

Changes to this Policy

#

We may update this Policy. The date at the top shows the latest version. We will email account holders about material changes before they take effect and, where the DPDP Act requires fresh consent, we will ask for it rather than assume it. We keep dated copies of all previous versions and will provide them on request.

14

Governing law

#

This Policy is governed by the laws of India. Subject to your right to approach the Data Protection Board of India or any other forum available under law, the courts at Bengaluru, Karnataka have jurisdiction over any dispute arising from it.

15

Definitions

#
Data Fiduciary
The person who, alone or with others, decides the purpose and means of processing personal data. For this Policy, that is Kushagra Agarwal, Vedansh Mishra and Ankith Bharadwaj, jointly.
Data Principal
The individual the personal data relates to. That is you.
Data Processor
A person who processes personal data on behalf of a Data Fiduciary.
Personal data
Any data about an individual who is identifiable by or in relation to that data.
Personal data breach
Any unauthorised processing of personal data, or its accidental disclosure, acquisition, sharing, use, alteration or destruction, or loss of access to it, that compromises its confidentiality, integrity or availability.

Previous versions of this Policy are available on request from ankith@tychecapital.co.in.