DRAFT — not yet in force. This notice will replace any prior version at the time of public launch. Placeholders (e.g., <your product email>) must be substituted before publication.

REPLACE ALL <your product email> PLACEHOLDERS WITH A DEDICATED PRODUCT EMAIL BEFORE PUBLISHING. Do NOT use any Foundation-context email.

Privacy Notice — kite-mcp-server

Last updated: 2026-04-19

This Privacy Notice describes how personal data is processed by the hosted instance of kite-mcp-server at https://kite-mcp-server.fly.dev. It is written to meet the minimum content requirements of Rule 3(1) of the Digital Personal Data Protection Rules, 2025, read with the Digital Personal Data Protection Act, 2023 ("DPDP").


1. Who we are

The hosted instance is operated by Sundeep Govarthinam, a sole proprietorship based in India ("we", "us", "the Operator"). For DPDP purposes, the Operator is the Data Fiduciary for personal data processed through the hosted instance.

If you self-host the code from the repository, you are your own Data Fiduciary and this notice does not apply to your deployment.


2. Data we collect

We collect only what is necessary to make the service work:

We do not collect: your Kite password, PAN, Aadhaar, bank account details, demat credentials, advertising identifiers, or third-party analytics data.


3. Why we collect it

Data Purpose
Kite API credentials Authenticate to Zerodha Kite Connect on your behalf
Access tokens Keep your session alive during the Kite daily window
OAuth email Identify you across sessions and scope your data
Audit log Security, incident response, regulatory accountability
Telegram chat ID Deliver alerts and briefings you opted into
Transient IP Rate-limit abuse and prevent brute-force attempts

Processing is based on your explicit consent under §6 of the DPDP Act. Consent is captured at two points: (a) when you click Authorize in the OAuth flow, and (b) when you submit your Kite developer-app credentials. You may withdraw consent at any time (see section 8).


5. How we store and protect data


6. Who we share data with

We do not sell, rent, or share your data for marketing or model-training purposes. The only disclosures are:

Explicitly excluded: advertising networks, third-party analytics, AI model training.


7. Your rights under DPDP

You have the right to:


8. Breach notification

If we become aware of a personal-data breach:


9. Cookies

The hosted instance sets a single essential JWT session cookie used to maintain your authenticated dashboard session. We do not set advertising, analytics, or cross-site tracking cookies. Because the only cookie is strictly necessary for service delivery, no consent banner is required under current Indian guidance.


10. Changes to this notice

Revisions to this notice are versioned using semantic versioning. For material changes that affect your rights or the categories of data we process, we will provide at least 15 days' advance notice via email and a banner on the service before the change takes effect.


11. Contact

Self-hosted deployments of the open-source code are outside the scope of this notice; operators of those deployments are their own Data Fiduciary and must publish their own privacy notice.