01Information We Collect
We collect information you provide directly and information generated by your use of the service:
Account Information
- Email address and full name (provided at signup, or via Google Sign-In)
- Password (stored as a salted hash — we never store or can view your plaintext password)
- Google profile picture and Google account ID, if you sign in with Google
Trading Configuration
- Strategy selection, quantity, risk limits, and trading hours you configure
- Your Upstox API Key and API Secret (encrypted at rest)
- Your Upstox access token, refreshed daily via OAuth (encrypted at rest)
Trading Activity
- Entry/exit prices, quantities, stop-loss and target levels, P&L, and strategy used for every trade
- Order status updates received from Upstox (fills, rejections, cancellations)
Technical Information
- IP address and browser type, for security and abuse prevention
- Push notification subscription endpoints, if you enable browser push alerts
- Telegram bot token and chat ID, if you configure Telegram alerts (encrypted at rest)
02How We Use Your Information
We use the information we collect to:
- Operate your trading bot — placing, monitoring, and managing orders on your behalf via your Upstox account
- Authenticate you and keep your account secure
- Send transactional alerts you've opted into: Telegram messages, browser push notifications, and email (verification, password reset)
- Display your trade history, P&L, and live position data on your dashboard
- Diagnose errors and improve the reliability of the trading engine
- Comply with legal obligations, if applicable
We do not use your trading data to make investment decisions on behalf of other users, and we do not sell, rent, or share your personal data with advertisers.
03Upstox Account & Trading Data
AlgoBot connects to your personal Upstox trading account using the official Upstox API and OAuth flow. This means:
- Your Upstox API Key, API Secret, and access token are encrypted using industry-standard encryption (Fernet/AES) before being stored in our database
- These credentials are used exclusively to place, modify, and cancel orders according to the strategy and risk settings you configure
- We do not access your Upstox account for any purpose outside of running the trading bot you've enabled
- You can disconnect Upstox at any time from Settings — this immediately stops the bot's ability to place new orders
- Your Upstox access token expires daily (~3:30 AM IST) per Upstox's own security policy — we do not control or extend this
04Third-Party Services
AlgoBot integrates with the following third-party services, each governed by its own privacy policy:
| Service | Purpose | Data Shared |
| Upstox | Order placement & market data | Order instructions, instrument tokens |
| Google OAuth | Sign-in (optional) | Email, name, profile picture |
| Telegram | Trade alerts (optional, user-configured) | Trade event messages, sent to your own bot/chat |
| Email/SMTP provider | Account verification, password reset | Email address, name |
| Browser Push (VAPID) | Push notifications (optional) | Notification payloads via your browser's push service |
05Data Storage & Security
- Your data is stored in a PostgreSQL database. Sensitive fields (API credentials, access tokens) are encrypted at rest.
- Passwords are hashed using Argon2, a modern, salted hashing algorithm — never stored in plaintext.
- Communication between your browser and our servers is encrypted via HTTPS/TLS.
- Internal communication between application processes uses a private Redis instance not exposed to the public internet.
- We restrict database and server access to what is operationally necessary.
No method of transmission or storage is 100% secure. While we use industry-standard safeguards, we cannot guarantee absolute security.
06Cookies & Local Storage
We use browser localStorage (not cookies) to store your session tokens and a small set of UI preferences, including:
- Access and refresh tokens (so you stay logged in)
- Voice alert preferences (volume, voice, enabled events) — stored entirely on your device
- A flag indicating you've accepted the risk disclaimer
This data stays in your browser and is not transmitted to third parties. Clearing your browser's site data will log you out and reset these preferences.
07Data Retention
- Account and trade history data is retained for as long as your account is active.
- If you delete your account, we delete your personal information and encrypted credentials within a reasonable period, except where retention is required for legal or accounting purposes.
- Order/event data cached in Redis (live position snapshots, order updates) automatically expires within hours and is not a permanent record — the permanent trade record lives in PostgreSQL.
08Your Rights & Choices
You can, at any time:
- View and update your profile information in Settings
- Disconnect your Upstox account or revoke API credentials
- Disable Telegram, push, or voice alerts independently
- Request a copy of your data or request account deletion by contacting us (see below)
- Withdraw consent for optional features (Google Sign-In, push notifications) at any time
09Children's Privacy
AlgoBot is not intended for individuals under the age of 18. Trading accounts with Indian brokers such as Upstox require the account holder to be a legal adult. We do not knowingly collect data from minors.
10Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by an updated "Last updated" date at the top of this page. Continued use of AlgoBot after changes take effect constitutes acceptance of the revised policy.
For privacy questions, data requests, or account deletion, reach us at support@algobot.com or +91 12345 67890. You can also message us on Telegram or WhatsApp.