This Privacy Policy governs data processing by Crucible ("Data Fiduciary", Public Beta Edition, engineered by Priyankit Raj), acting in compliance with the Digital Personal Data Protection (DPDP) Act, 2023 and applicable SEBI guidelines.
Contact Desk: support@crucible.trade
Last Updated: August 2026 • Formulated under India's DPDP Act, 2023, IT Rules 2021, and SEBI Cybersecurity Guidelines.
Crucible collects and processes personal digital data only on the following statutory grounds:
Crucible implements authenticated AES-256-GCM encryption for storing broker API secrets, permanent OAuth access tokens, and TOTP secrets. Raw credentials are encrypted client-side/in-memory prior to database insertion.
In strict observance of data minimization principles under the DPDP Act 2023 alongside regulatory retention laws, Crucible bifurcates data retention:
| Data Category | Specific Data Elements | Retention Period | DPDP Erasure Eligibility |
|---|---|---|---|
| Non-Regulatory User Data | Account profile, email, UI settings, session tokens, optional preference tags. | Active account duration + 90-day grace period post-cancellation. | 100% Eligible upon verified erasure request. |
| SEBI Statutory Telemetry & Audit Logs | SHA-256 strategy hash audit trail, Algo-ID tags, trade timestamps, order fill/rejection telemetry. | 5 Years Mandatory (as required by SEBI Algo Circulars & PMLA rules). | Exempt from erasure until 5-year statutory period lapses. |
We strictly do NOT sell, rent, monetize, or broker your trading data, strategy algorithms, order logs, or performance metrics to third-party hedge funds, high-frequency traders, brokerages, or proprietary desks.
Under Chapter III of the Digital Personal Data Protection Act, 2023, you possess the following enforceable rights:
To exercise any of the above rights, send a written request from your registered email address to our Data Protection & Grievance Officer at support@crucible.trade. Please include your User ID and specify the right being invoked.
SLA: Receipt acknowledged within 24 to 48 business hours; completed within 15 to 30 business days.
In compliance with Section 12 of the Digital Personal Data Protection Act, 2023 and Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021: