Legal

Privacy Policy

Last updated: June 15, 2026  •  Effective: June 15, 2026

🔐 The short version: Your API keys never leave your browser. Your portfolio data is stored in your own Supabase account. We don't sell or share your investment data. We use minimal analytics and respect your privacy.

1. Who We Are

Crito Investments ("Crito", "we", "us", "our") operates the website at crito.in and the application at app.crito.in. We are an online platform providing AI-powered stock research tools for individual investors.

For privacy-related queries, contact us at: privacy@crito.in

2. The BYOK Architecture and Your API Keys

Crito operates on a Bring Your Own Key (BYOK) architecture. This means:

If you clear your browser's local storage or use a different device, you will need to re-enter your API keys. This is by design — it ensures maximum security.

3. Information We Collect

Account information: When you create a Crito account, we collect your email address and name (if provided). This is stored in your Supabase account associated with our project.

Portfolio data: Your investment baskets, stock watchlists, and analysis preferences are stored in your Supabase account. This data is associated with your user ID and protected by Supabase's row-level security policies.

Usage analytics: We use privacy-respecting analytics to understand how features are used. This data is aggregated and does not identify individual users. We do not use Google Analytics. We do not track individual user behavior across sessions.

Market data requests: When you view stock charts or prices, our backend queries Yahoo Finance on your behalf. We log these requests for debugging purposes but do not associate them with your personal investment decisions.

Log data: Standard web server logs including IP addresses, browser type, and requested URLs. These are retained for 30 days for security and debugging purposes.

4. Information We Do Not Collect

5. How We Use Your Information

We do not use your data for advertising, and we do not sell your data to third parties.

6. Data Sharing

We share your data only with:

We do not share your data with advertisers, data brokers, investment firms, or any third party for commercial purposes.

7. Data Retention

8. Your Rights

You have the right to:

To exercise these rights, email privacy@crito.in. We will respond within 30 days.

9. Security

We implement appropriate technical and organizational measures to protect your data:

10. Cookies

Crito uses minimal cookies:

We do not use advertising cookies, tracking pixels, or third-party marketing cookies.

11. Children's Privacy

Crito is not intended for users under 18 years of age. We do not knowingly collect personal information from minors. If you believe we have inadvertently collected information from a minor, contact us immediately at privacy@crito.in.

12. International Data Transfers

Crito's infrastructure is primarily located in the United States (Google Cloud us-central1) and managed by Supabase (AWS). If you are located outside the United States, your data will be transferred to and processed in the United States. By using Crito, you consent to this transfer.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or a prominent notice on our website. Continued use of Crito after changes are posted constitutes acceptance of the updated policy.

14. Contact

For privacy questions or to exercise your rights: