Skip to content

Legal

Privacy Policy

What Sentra collects, why, and how it's used — described as the product actually works today.

Not yet in effect

This page describes Sentra's actual data practices as implemented, but isn't published as a final, effective policy yet. Publication is pending a few facts this draft can't supply on its own: the registered legal entity operating Sentra, its registered address, a governing jurisdiction, and a working privacy contact. This page isn't indexed by search engines until those are in place.

1. Introduction

This policy describes what information Sentra (“we,” “us”) collects through the Sentra mobile app and this website, why, and how it's used. Sentra is an informational market-intelligence app — see our Disclaimer for what that means.

2. Information you provide

When you create an account, we collect your email address via Firebase Authentication. Your password is handled directly by Firebase — we never see or store it ourselves. You can optionally set a display name. As you use the app, you choose which companies to add to your watchlist, and you can set preferences like your timezone, notification digest time, and app theme.

3. Information collected automatically

We automatically receive: your Firebase user identifier; a push-notification token (FCM) and general device platform (e.g. Android or iOS) if you enable notifications; app version and basic device information used for analytics and crash diagnostics; and your IP address, which we use transiently to rate-limit requests and which otherwise appears only in our infrastructure's default request logs, governed by our hosting provider's own log retention rather than a separate retention decision we make.

4. Watchlist and product activity

We store the companies on your watchlist, the notification type you've chosen for each, and product state like which sentiment-change or event notifications you've already been shown, so we don't repeat them.

5. Notifications

We use Firebase Cloud Messaging to deliver notifications. If you enable them, we store your device's push token (never exposed to you or any third party in raw form) and your notification preferences — a master on/off switch plus per-type choices for watchlist alerts, high-materiality alerts, and your Daily Brief. Notifications you receive are also kept in an in-app inbox. Notification content never includes sensitive, financial, or account data — only enough to route you to the right screen.

6. AI features

Sentra uses OpenAI to power two features, and bounds what each sends deliberately:

Automatic summaries. For notable articles and events, we send a ticker symbol, a sentiment label our own system computed, and the article's headline and description — never the full article text, which we don't store at all.

Ask Sentra. When you ask a supported question, we send a bounded, server-built summary of information Sentra has already gathered about the relevant company, event, or your watchlist — never open-ended free text you type, never your profile or payment information, and never article source URLs. We keep a record of each Ask Sentra request for quota and cost tracking (which model was used, token counts, cost, timing) but deliberately do not store the prompt or answer text alongside your account; a separate cache stores the generated answer itself, keyed to a fingerprint of the question and context, not to raw prompt text.

Every AI-generated summary or answer is checked by an automated filter before it's shown to you, and anything resembling a buy/sell/hold recommendation or price prediction is discarded rather than shown. OpenAI processes what we send it under its own terms; we don't make promises about its practices beyond what it publishes itself.

7. Analytics, diagnostics and performance

We use Firebase Analytics to understand how the app is used, Firebase Crashlytics to diagnose crashes, and Firebase Performance Monitoring to track load times for key screens. Analytics events pass through an automatic filter that strips anything that looks like an email, token, or other sensitive value before it's sent. Crash reports carry only a small, fixed set of labels (which feature, screen, and operation were involved, and your plan) — never your email, name, or any content. None of this runs in our own local development builds.

8. Market and news data

To build your watchlist feed, Sentra pulls market and news information from third-party providers (including Marketaux, NewsData, GFDL, and select RSS feeds). This is information flowing into Sentra to power the product — we don't send these providers your personal information, and they don't process it on our behalf.

9. Payments and subscriptions

If you subscribe to a paid plan, we store your plan, billing cycle, subscription status, the amount charged, and a reference ID from the payment provider. We do not store your card number, bank details, or other payment credentials — those are handled directly by Razorpay, Google Play, or Apple, whichever you paid through, under their own privacy terms.

10. Advertising

Sentra's free plan is designed to show ads, but as of this writing no live advertising network is integrated — ad placements in the app show no real ad content today. If we integrate a real ad network in the future, we'll update this policy before that happens, not after.

11. How information is used

We use the information above to:

  • provide your account and keep you signed in;
  • maintain your watchlist and show relevant developments for it;
  • send notifications and Daily Briefs you've opted into;
  • power AI summaries and Ask Sentra;
  • administer your subscription and confirm entitlements;
  • detect and prevent fraud, abuse, and security issues;
  • diagnose problems and understand how the app is used; and
  • improve Sentra over time.

12. Information sharing

The services that process information on our behalf, and why:

  • Google / Firebase — authentication, push notifications, analytics, crash reporting, performance monitoring;
  • OpenAI — generating AI summaries and Ask Sentra answers, as described above;
  • Razorpay — processing payments made through Razorpay;
  • Google Play / Apple — processing in-app purchases made through those stores;
  • Google Cloud Platform — hosting our backend infrastructure and database.

Market/news data providers (§8) are not on this list — they supply content to us, they don't process your personal information. We don't sell your information to anyone.

13. Retention

We keep most information for as long as your account is active. We don't yet have a formally published retention schedule with fixed time periods for every data category, and we won't invent one here — this is flagged as something to finalize before this policy takes effect. Subscription and payment records are kept longer than other data, for financial record-keeping.

14. Account deletion

You can delete your account at any time from within the app — see Delete Account for exact steps. Deletion deactivates your account and immediately blocks further access; it doesn't instantly erase every record. Permanent erasure of your data is a separate, internal process gated on your account already being deactivated. As explained on the Delete Account page, our in-app confirmation currently points you to contact support to request that — a direct support contact isn't publicly available yet.

15. Security

We use reasonable technical and organizational measures to protect your information — encrypted connections, access controls scoped by role, and secret management for credentials, among others. No method of transmission or storage is perfectly secure, and we don't claim otherwise.

16. User rights

Sentra is built primarily for users in India. India's Digital Personal Data Protection Act, 2023 is being brought into force in phases; once its data-fiduciary obligations are in effect, it's expected to give you rights including access to, correction of, and erasure of your personal data, the ability to withdraw consent, and a way to raise a grievance. We intend to honor requests along these lines; this section will be expanded with concrete request instructions once our privacy contact (§20) is in place. This isn't a substitute for reading the Act itself, and isn't legal advice.

17. Children / minimum age

Requires human decision

Sentra doesn't currently have a defined minimum age for use. This needs a product/legal decision before this policy can responsibly state one — we won't invent a number here. If Sentra is used by anyone under 18, India's DPDP Act imposes specific obligations (including limits on tracking and targeted advertising to children) that this policy doesn't yet address.

18. International processing

Our backend infrastructure runs on Google Cloud in India. Some of the services we rely on (Firebase, OpenAI) may process information on servers outside India as part of their own global infrastructure, under their own terms.

19. Changes to this policy

We may update this policy as Sentra changes. Material changes will be reflected here with an updated effective date once this policy is in effect.

20. Contact

A dedicated privacy contact isn't published yet. In the meantime, see Support.