MF Mitra

MF Mitra — Privacy Policy

Last updated: 8 September 2026

MF Mitra is an Android app for tracking and analysing an Indian mutual-fund portfolio. It is an analytics tool: it does not give investment advice, and it cannot buy, sell or transact anything. This policy explains what the app handles, where each thing is kept, and how you remove it.

1. What stays on your phone

Your portfolio is stored only on your device, in an encrypted database. It is excluded from Android's cloud backup and from device-to-device transfer, so it does not travel anywhere with your phone's backup.

2. What we hold on our servers

Only what an account needs to exist. Our backend is Supabase, acting as our processor.

Your portfolio is not among them. We cannot see your holdings.

3. Google user data

Two optional features use your Google account. Both are off until you turn them on, and each asks for the narrowest permission that can do the job.

3a. Google Sheet sync — drive.file

Writes your portfolio into a Google Sheet that you own. The drive.file permission lets an app see and edit only files it created itself; it gives no access to anything else in your Drive. Sync happens when you ask for it.

3b. Gmail auto-pickup of your CAS — gmail.readonly

After you request a Consolidated Account Statement, the app can find the registrar's email and download the attached PDF for you, instead of your having to share it across manually.

3c. Limited Use

MF Mitra's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. Data obtained from Gmail is not used, transferred or sold to create, train or improve any generalised or foundational artificial-intelligence or machine-learning model.

Specifically, data obtained through Google APIs is used only to provide or improve the user-facing features described above; is never transferred to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition; is never used for advertising; and is never read by humans unless we have your explicit consent, it is necessary for security purposes, it is required to comply with applicable law, or the data is aggregated and anonymised for internal operations.

4. How we protect your data

Your portfolio stays on your device. Holdings, transactions and any statement you import are stored in an encrypted database on the phone itself, not on our servers.

The local database is encrypted with SQLCipher. Access tokens for Google and for brokers are held in Android's EncryptedSharedPreferences, backed by the device keystore. You can require your phone's fingerprint, face or screen lock before the app will open.

Every network connection the app makes uses HTTPS/TLS. API keys for the services the app depends on are never stored in the app; requests go through a server-side proxy so no credential ever reaches your device.

A CAS statement fetched from Gmail is downloaded to private app storage, unlocked and read on the device, and deleted once it has been imported. It is never uploaded anywhere.

Your account record on our backend holds only your email address, your plan and your role. Every row is protected by row-level security so that no signed-in user can read another user's data. Deleting your account removes that record and erases the local database on the device.

5. Insights written with an AI provider

If you turn on written insights, a summary of your portfolio — category mix, values and returns — is sent through our proxy to a language-model provider. Your name, email, account id, folio numbers and PAN are never part of it. This feature is off unless you turn it on.

6. Crash reports and diagnostics

To find and fix problems during the beta, the app sends crash and error reports through Google's Firebase Crashlytics. A report carries the app version, your device model and Android version, the name of the screen you were on, which features were switched on, an error code from a fixed list, and a rough band for how many holdings you have — never an exact number.

It does not carry your account id, your name, your email, any portfolio value, any scheme or folio, or any part of a statement.

7. Advertising

Google's Mobile Ads SDK is included in the app. It is switched off: no ad is requested and the SDK is never started. We are telling you it is there because it is, and because Google Play's data disclosure lists it.

If advertising is ever turned on, it will be non-personalised, the advertising identifier will stay suppressed, and this page will be updated before it happens.

8. What the app never keeps

9. Age

MF Mitra is for adults. An account declaring an age under 18 is refused and removed at the point of sign-up.

10. Your rights, and deleting your account

You can withdraw any optional permission from More → Privacy & data in the app, at any time, without losing your portfolio.

Deleting your account, from that same screen, removes: your profile, plan, consent records, profile picture and any published snapshot from our servers; any link to an advisor and any invitation addressed to your email; and everything the app has stored on this phone. It also revokes this app's access to your Google account. The app closes when it finishes, because there is nothing left for it to open. This cannot be undone.

One thing is deliberately kept: a metadata-only processing log — which provider was called, when, and whether it succeeded. It never contains the content of any request or response. It is how we can show that a request like yours was actually carried out.

You may also write to us to exercise any right, using the address below. We aim to respond within 7 days.

11. Contact

For privacy questions, data-rights requests or grievances: ejimitrajpr@gmail.com

12. Changes

If what the app does with data changes, this page changes with it, and the date at the top moves. Material changes will be shown in the app.