Privacy
What the Tax & Reporting Pack reads, where it goes, and how long it's kept. Grounded in what the code actually does.
What it reads
With your consent, the Tax & Reporting Pack reads — read-only — your exchange reports (gain/loss and GST/TDS across spot, futures and options) and transaction history, plus your basic profile (to identify whose data to read). It uses only the OAuth scopes you grant. It cannot place an order, withdraw, or change anything in your account.
Where it goes
Your access and refresh tokens are held server-side only, in a session store, and are never sent to your browser — the browser holds only an opaque session cookie. Reports are fetched on demand and cached briefly to avoid re-reading on every page; the cache is keyed to your account and expires on its own.
How long it's kept
When you disconnect, the app revokes the token with the exchange and deletes everything it held — session, tokens, and any cached reports. Sessions also expire on their own after a period of inactivity.
Contact
Questions about this app and its data handling go to the developer who publishes it, not to the exchange.
