Privacy policy
AllPaisa collects as little as it can get away with. This page says exactly what that means, for both the website and the Android app, in terms you can check against how they behave.
Last updated 22 Aug 2026
The short version
You can read everything on AllPaisa without an account, and most people do. Signed out, nothing about you is stored on our side: your theme, your recent searches and your local watchlist stay on your own device.
An account is optional, and exists for one reason: so the holdings you enter and the alerts you ask for follow you between devices. Creating one means giving an email address and a password. If you never create one, there is nothing here to look up about you.
AllPaisa does not sell data, does not run advertising, and does not share what you hold with anyone. The Android app contains no analytics or tracking SDK of any kind.
If you create an account
Signing up stores your email address and a hashed password with Supabase, our database provider. A display name is optional. You can add two-factor authentication, in which case the second-factor secret is stored too.
What you enter afterwards is stored against that account: portfolios and the transactions in them, the holdings derived from those transactions, watchlists, dividend receipts you record, savings goals and allocation targets, alert rules, in-app notifications, and a log of account events such as sign-ins and imports. If you import a statement, the import batch is kept so a bad import can be undone.
This is the data you asked us to keep. It is used to show you your own holdings and to send the alerts you turned on, and for nothing else. It is not used to build an advertising profile, and it is not shared with any third party beyond the processors named below.
Email and push notifications
If you turn on alerts, AllPaisa emails you about ex-dates and payouts for instruments you follow. Those emails are sent through Resend, which receives your email address and the contents of the message. A record of each send is kept so a failed delivery can be retried and so the same alert is not sent twice.
If you use the Android app and allow notifications, the app registers a device push token. That token is stored against your account and sent to Expo's push service, which hands it to Google's Firebase Cloud Messaging for delivery. A push token identifies a device installation, not a person, and it is deleted when the device tells us the app has been uninstalled or you sign out.
You can turn either off. Turning off alerts stops the mail; revoking the notification permission or signing out stops the push.
Analytics, and the notice
Google Analytics 4 is used on the website to see which pages people find useful. It loads on every visit, and the notice at the foot of the page tells you so rather than asking permission first. Pressing OK records that you have seen the notice; it is not a consent choice, and there is no in-page way to switch analytics off.
Google receives the usual web-analytics signals: pages viewed, approximate location derived from IP, device and browser type, referring site, and a pseudonymous client identifier used to distinguish browsers and visits. The tag may set Google Analytics cookies such as _ga and _ga_<measurement-id>. AllPaisa does not send Google your name, your email address, your holdings, your watchlist contents or a custom user ID — signed in or not.
If you would rather not be measured, a tracker-blocking extension or your browser's built-in blocking will stop the Google script loading, and the site works normally without it. Clearing this site's data brings the notice back but does not turn analytics off. The Android app has no analytics at all.
What is stored on your own device
The website keeps a few small values in your browser's local storage: whether you have seen the analytics notice, your light or dark theme preference, whether payout amounts are shown as filed or split-adjusted, your recent searches, and — if you are signed out — the instruments on your local watchlist. Signed out, none of that reaches an AllPaisa account.
Signing in changes one of those: your watchlist then lives against your account so it is the same list on every device. The others stay local.
The Android app stores your sign-in session in the operating system's encrypted keystore, so it survives closing the app without keeping your password anywhere.
Search text is sent to Supabase while you search. Opening recent searches sends up to five saved instrument IDs to Supabase solely to verify that they still identify active public instruments and to refresh their public names and symbols. Opening your watchlist sends its saved instrument IDs to Supabase to fetch current public payout figures — signed out that is the only thing those IDs are used for, and no record of the request is kept against you. Clearing site data removes the local values; it may also remove the separate Google Analytics cookies described above.
Server logs and processors
The website runs on Cloudflare Workers. The database and authentication are Supabase, hosted in Mumbai. Alert email is sent through Resend. Android push is delivered through Expo's push service and Google Firebase Cloud Messaging. Website analytics is Google Analytics 4.
Each of those keeps standard operational request logs — IP address, timestamp, requested URL, user agent — for security and reliability. Those logs are held by those providers under their own terms and are not combined by AllPaisa into any profile.
The corporate-action record itself — companies, payouts, prices, filings — contains nothing about visitors and never has. Account data is stored separately and is readable only by the account it belongs to, enforced in the database rather than only in the application.
Your rights
India's Digital Personal Data Protection Act gives you rights over personal data held about you. If you have no account, AllPaisa holds nothing to access, correct, export or erase, though operational logs and Google Analytics may still contain online identifiers as described above, under the processors' retention controls.
If you do have an account, you can export everything in it from Account → Export, which produces a machine-readable file of your portfolios, transactions, receipts, goals and watchlists. You can correct anything you entered by editing it. Deleting your account removes the account and the data attached to it.
If you have a question or request about any of this, write to the address below and it will be investigated and answered.
Children
AllPaisa is general-purpose financial reference material and is not directed at children. Accounts are intended for adults managing their own holdings. No age is requested and there is no age-gated feature, so please do not create an account for a child.
Changes
If this policy changes in substance — a new processor, a new category of data — the date at the top changes with it. Cosmetic edits do not move the date.