Legal / Privacy notice
LaabhAI privacy notice
Version 1.0 — 27 Sep 2026 — draft prepared in-house at the founder's instruction; not a substitute for advice from a qualified Indian lawyer.
Status: not yet in force. Replaces the earlier draft privacy.md. This notice is written to
meet the Digital Personal Data Protection Act, 2023 (the "DPDP Act").
Who we are. AgentCo (Aman Garg, sole proprietor), India ("we", "us"). For the optional telemetry in clause 3 we are the "Data Fiduciary" under the DPDP Act. Contact and grievance officer: Aman Garg, hello@agentco.in.
1. The short version
1.1 LaabhAI runs on your own computer. By default, nothing it handles is sent to us.
1.2 You can choose to switch on telemetry (run and order records linked to a random install id, not your name) to help us support you and improve the software. It is off unless you say yes, you can switch it off at any time, and you can ask us to delete it.
1.3 We never sell your data and never use it for advertising.
2. What stays on your computer
2.1 LaabhAI keeps its files in folders in your home directory (~/.laabhai/ and
~/.laabhai-snapshots/). They include:
- your settings, rulebook choices, and the money you told LaabhAI to manage;
- your Zerodha login session, and any API keys you add;
- your Telegram bot token and chat id, and email settings if you use email;
- the ledger of orders and holdings, the audit log, and the reports.
2.2 None of this leaves your computer to us unless you switch on telemetry, and even then only the items listed in clause 3.3. Your broker login and tokens never leave your computer to us. Deleting those folders (see docs/uninstall.md) removes them.
3. Optional telemetry (only if you say yes)
3.1 How you choose. Setup asks a separate question, after you accept the terms: "Share
run and order records (linked to a random install id) with AgentCo to help support and improve LaabhAI?" The default
answer is no. Saying no changes nothing about how LaabhAI works. You can change your answer any
time with laabh telemetry on, laabh telemetry off or laabh telemetry status.
3.2 Identifiers. A random install id created on your computer. Your email address only if you choose to give it (a second, separate question), so that we can reply to you about support.
3.3 What is sent if you say yes:
- install details: operating system, LaabhAI version, the version of this notice you consented to;
- run records: which job ran, when, how long it took, how many AI steps it used, whether the quality checks passed, and a short summary of the plan it proposed;
- risk-kernel decisions: which proposed orders were approved or rejected, and why;
- orders and fills as LaabhAI saw them: share symbol, buy or sell, quantity, price, status and order tag;
- reconciliation results (whether LaabhAI's records matched Zerodha's), alerts and a daily "still running" signal;
- your record of accepting these documents (see acceptance-record.md).
3.4 What is never sent: your broker login, access tokens or API keys; your PAN; your Telegram bot token; passwords; the AI's full research notes. Two items are sent only if you switch on a further, separate option: your full holdings list, and your Zerodha user id (only if you ask for help that needs us to identify your account).
3.5 Purposes. We use telemetry only to (a) give you support, (b) find and fix defects and check the quality of the software, and (c) produce aggregate statistics that identify no one (for example, how many installs ran today). We do not sell it, share it for advertising, or use it to give anyone investment advice.
3.6 Where and how long. Stored with our database provider (Supabase) in its Mumbai, India region. Kept for up to 24 months from when it was collected, then deleted, unless the law requires us to keep it longer.
3.7 Who processes it for us. Supabase, as our data processor, and Google Workspace for the hello@agentco.in mailbox. We give access to no one else, except where the law requires it.
4. Services your computer talks to directly
4.1 LaabhAI connects to services you set up, under your own accounts. Each is responsible for what it receives under its own privacy policy; we receive none of it.
| Service | Why | What it receives |
|---|---|---|
| Zerodha (Kite MCP or Kite Connect) | Prices, holdings, orders | Your requests and orders, under your login |
| Anthropic (Claude Code, your own login) | AI research | On each research run: your holdings and open positions, capital, mode and loss-limit settings, cash, and that run's market data and news; also anything you type into Claude Code |
| Telegram (your own bot) | Alerts, reports, and approvals in Confirm mode | The text of alerts and reports sent to your own bot and chat, and your replies such as approve <tag> or /halt |
| Your email provider (optional) | Reports by email | Report text |
| Public market-data and news sites | Research | Ordinary web requests |
4.2 Telegram. LaabhAI sends messages from your own bot to your own chat, and reads your replies to that bot. These messages pass through Telegram's servers, not ours. We cannot read them.
5. Your rights under the DPDP Act
For any personal data we hold (clause 3), you have the right to:
5.1 be told what we collect and why, before you agree (section 5), and to give or refuse consent that is free, specific and clear (section 6);
5.2 withdraw consent at any time, as easily as you gave it (section 6(4)): run
laabh telemetry off;
5.3 access a summary of the personal data we hold about you and what we did with it (section 11);
5.4 correct, complete, update or erase it (section 12). Run laabh telemetry delete-my-data,
or email hello@agentco.in from the address you gave us, or with your install id (shown by
laabh telemetry status). We delete it within 7 days;
5.5 complain to us (section 13). We acknowledge within 7 days and respond within 30 days. If you are not satisfied, you may then complain to the Data Protection Board of India; and
5.6 nominate another person to exercise these rights if you die or become unable to (section 14). Email us with the nominee's name and contact details.
5.7 Commencement. The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025 (G.S.R. 846(E)) and come into force in phases: some provisions at once, consent-manager provisions after one year, and most duties of Data Fiduciaries (notice, security, breach reporting, erasure, rights handling) 18 months after notification. We follow this notice now, whether or not a particular provision has commenced yet.
6. Security and breaches
6.1 We protect telemetry with access controls (row-level security keyed to each install), encryption in transit, and a strict list of allowed fields that rejects anything else.
6.2 If a personal data breach affects your data, we will tell you and the Data Protection Board without delay, and in any case give the Board a detailed report within 72 hours of becoming aware of it, as the DPDP Rules, 2025 (rule 7) require. We will tell you what happened, what it may mean for you, and what you can do.
7. Website
7.1 The LaabhAI website sets no cookies and has no tracking pixels. If we measure visits, it will be with a cookie-free tool that counts pages without identifying you. Our hosting provider may keep standard server logs (such as IP addresses) for security for a short period.
8. Children
8.1 LaabhAI is not for anyone under 18. We do not knowingly collect data from children. If you think a child's data has reached us, email us and we will delete it.
9. If you report a bug
9.1 If you open a public GitHub issue, you choose what to paste, and GitHub's policy applies.
Remove tokens, account ids and holdings first; check laabh doctor output before posting.
10. Changes
10.1 This notice has a version number and date. If we change what we collect or why, we will publish a new version and ask for your consent again before collecting anything new. The version you consented to is stored in your acceptance record.
LaabhAI executes the rules you configured in your own account; it is not investment advice; losses are possible.