Privacy Policy
🔐 The short version: Your API keys never leave your browser. Your portfolio data is stored in your own Supabase account. We don't sell or share your investment data. We use minimal analytics and respect your privacy.
1. Who We Are
Crito Investments ("Crito", "we", "us", "our") operates the website at crito.in and the application at app.crito.in. We are an online platform providing AI-powered stock research tools for individual investors.
For privacy-related queries, contact us at: privacy@crito.in
2. The BYOK Architecture and Your API Keys
Crito operates on a Bring Your Own Key (BYOK) architecture. This means:
- Your Anthropic (Claude) and Perplexity API keys are stored only in your browser's local storage on your device
- Your API keys are never transmitted to Crito's servers
- When you run an AI analysis, your browser communicates directly with Anthropic and Perplexity — Crito's backend is not involved in these API calls
- Crito cannot access, read, or recover your API keys under any circumstances
If you clear your browser's local storage or use a different device, you will need to re-enter your API keys. This is by design — it ensures maximum security.
3. Information We Collect
Account information: When you create a Crito account, we collect your email address and name (if provided). This is stored in your Supabase account associated with our project.
Portfolio data: Your investment baskets, stock watchlists, and analysis preferences are stored in your Supabase account. This data is associated with your user ID and protected by Supabase's row-level security policies.
Usage analytics: We use privacy-respecting analytics to understand how features are used. This data is aggregated and does not identify individual users. We do not use Google Analytics. We do not track individual user behavior across sessions.
Market data requests: When you view stock charts or prices, our backend queries Yahoo Finance on your behalf. We log these requests for debugging purposes but do not associate them with your personal investment decisions.
Log data: Standard web server logs including IP addresses, browser type, and requested URLs. These are retained for 30 days for security and debugging purposes.
4. Information We Do Not Collect
- Your AI API keys (Anthropic, Perplexity) — these are browser-only
- The content of your AI analysis requests or responses
- Your actual brokerage holdings or transaction data
- Payment information (Crito is free; we process no payments)
- Device location data
5. How We Use Your Information
- To provide and operate the Crito service
- To authenticate your account and maintain session security
- To store and sync your portfolio baskets across devices
- To send essential service emails (account confirmation, password reset)
- To improve product features based on aggregated usage patterns
- To detect and prevent fraud or abuse
We do not use your data for advertising, and we do not sell your data to third parties.
6. Data Sharing
We share your data only with:
- Supabase: Our database and authentication provider. Your account and portfolio data is stored in Supabase's infrastructure (hosted on AWS). Supabase's privacy policy applies to this data.
- Cloudflare: Our CDN and infrastructure provider. Network traffic passes through Cloudflare. Cloudflare's privacy policy applies.
- Google Cloud: Our application backend runs on Google Cloud Run. Request logs are processed there.
- Law enforcement: When legally required by a court order or applicable law in the jurisdictions we operate in.
We do not share your data with advertisers, data brokers, investment firms, or any third party for commercial purposes.
7. Data Retention
- Account data: Retained until you delete your account
- Portfolio baskets: Retained until you delete them or your account
- Server logs: 30 days
- Analytics data: Aggregated, retained indefinitely; individual data points are not retained beyond 90 days
8. Your Rights
You have the right to:
- Access: Request a copy of the data we hold about you
- Correction: Correct inaccurate personal data
- Deletion: Delete your account and all associated data
- Portability: Receive your portfolio data in a machine-readable format
- Objection: Object to specific uses of your data
To exercise these rights, email privacy@crito.in. We will respond within 30 days.
9. Security
We implement appropriate technical and organizational measures to protect your data:
- All data in transit is encrypted using TLS 1.3
- Database access is protected by Supabase's row-level security (RLS) policies
- API keys are never stored server-side by design
- Regular security audits of our application code
- Limited employee access to production data (principle of least privilege)
10. Cookies
Crito uses minimal cookies:
- Authentication cookies: Supabase session tokens to keep you logged in. These are strictly necessary and cannot be disabled.
- Preference cookies: Storing your market preferences and UI settings. These are functional and can be cleared via your browser.
We do not use advertising cookies, tracking pixels, or third-party marketing cookies.
11. Children's Privacy
Crito is not intended for users under 18 years of age. We do not knowingly collect personal information from minors. If you believe we have inadvertently collected information from a minor, contact us immediately at privacy@crito.in.
12. International Data Transfers
Crito's infrastructure is primarily located in the United States (Google Cloud us-central1) and managed by Supabase (AWS). If you are located outside the United States, your data will be transferred to and processed in the United States. By using Crito, you consent to this transfer.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or a prominent notice on our website. Continued use of Crito after changes are posted constitutes acceptance of the updated policy.
14. Contact
For privacy questions or to exercise your rights:
- Email: privacy@crito.in
- Website: https://crito.in