S Scrivo.pro
Sign In Terms Disclaimer
DPDP Act 2023 Compliance

Privacy Policy & Cryptographic Data Rights

Effective Date: September 11, 2026 • Version 2.0

Zero-Knowledge Commitment

Scrivo is engineered around client-side envelope encryption (AES-256-GCM). Your sensitive trading parameters—including entry prices, exit prices, trade quantities, and transaction costs—are stored as encrypted cryptographic ciphertexts. Scrivo cannot read, analyze, sell, or commercialize your personal financial trade logs.

1. Data Fiduciary Identity

Scrivo.pro operates as a Data Fiduciary pursuant to the Digital Personal Data Protection Act, 2023 (DPDP Act, Act No. 22 of 2023 of the Republic of India). This Privacy Policy explains our practices regarding the collection, processing, envelope encryption, and erasure of personal data provided by users of our journaling software.

2. Categories of Data Collected

  • Identity & Authentication Data: Email address, Firebase Authentication UID, and optional display name.
  • Encrypted Financial Records: Stock and derivative trade details, including entry/exit prices, contract quantities, execution dates, and broker charges. All financial values are protected at rest via AES-256-GCM envelope encryption.
  • Taxonomical Metadata: Custom behavioral tags, strategy categories, and canonical symbols managed in your personal workspace.
  • Telemetry & Security Logs: IP addresses and request timestamps used exclusively for rate limiting and brute-force prevention.

3. Zero-Knowledge Envelope Encryption (AES-256-GCM)

To guarantee absolute confidentiality, Scrivo implements a two-tier cryptographic envelope:

  • A global 256-bit Master Encryption Key (MEK) secured in isolated server environments.
  • A unique 256-bit Data Encryption Key (DEK) provisioned for each individual user account and stored encrypted.
  • Each financial field is encrypted using authenticated AES-256-GCM with a distinct 12-byte initialization vector (IV) and 16-byte authentication tag, ensuring cryptographic integrity.

4. Right to Erasure & Cryptographic Shredding (Section 12, DPDP Act)

You possess an absolute, statutory right to request erasure of your personal data at any time. When you initiate account deletion from your Account & Privacy settings:

  • Live Key Shredding: Your unique Data Encryption Key (DEK) is instantly and permanently deleted from our live database. Once deleted, no live system process possesses the capability to decrypt your trading records.
  • Domain Deletion: All trades, symbols, and tags associated with your user ID are immediately and permanently removed from the active database within an atomic transaction.
  • Cloud Revocation: Upon providing re-authenticated credentials, your identity record is deleted from Google Firebase Authentication via the Identity Toolkit API. If cloud re-authentication is unavailable, local cryptographic shredding and domain purging proceed unconditionally, permanently severing and destroying all local application data.
  • Resurrection Prevention: An irreversible, salted SHA-256 HMAC tombstone of your identity is recorded in our deleted accounts registry. If a historical disaster recovery backup containing your data is ever restored into the application, the system detects the tombstone and automatically purges the restored zombie records at the point of restoration or login attempt, preventing unintended resurrection.

5. 30-Day Backup Lifecycle Disclosure

Encrypted database snapshots are maintained solely for disaster recovery purposes on a maximum rolling cycle of thirty (30) days. While an older backup snapshot taken prior to deletion may contain your encrypted records and encrypted key material, such backups are isolated from live operations. Upon reaching the end of their 30-day retention cycle, snapshots are permanently overwritten and purged from storage, after which no copies of your historical data remain.

6. Right to Data Portability

Under Section 12 of the DPDP Act 2023, you can download your complete trading journal, performance statistics, and tags at any time in structured, machine-readable formats (CSV and JSON) directly via your Account & Privacy modal or the export API.

7. Grievance Redressal & Contact

In accordance with the DPDP Act 2023, inquiries or grievances regarding data protection may be addressed to our designated Data Grievance Officer:

Data Protection & Grievance Officer: Vikrant Apte
Email: privacy@scrivo.pro / vikrantapteofficial@gmail.com
Jurisdiction: Pune / Mumbai, Maharashtra, Republic of India