01
In short
Cortex is an AI financial brain for Indian residents. It unifies accounts you choose to link, computes insights from that data, and lets you ask questions in natural language. Cortex is an education and intelligence product — not a SEBI-Registered Investment Adviser, an IRDAI-licensed insurance broker, a Chartered Accountant, or a bank.
We collect only what the product needs: your email to authenticate you, financial information fetched through RBI-regulated Account Aggregator rails with your explicit consent, the messages you send to Ask Cortex, and the records the law requires us to keep. We do not sell personal data. We do not use it to train third-party foundation models under our commercial API terms. We take no commission, referral fee, or revenue share from any bank, broker, insurer, or card issuer.
Financial payloads are encrypted. Decryption happens on your device. Account data is stored in India. You can export or delete your account at any time. You must be 18 or older. Write to support@trycortex.live.
02
Who is responsible
Under the Digital Personal Data Protection Act, 2023 (DPDPA), Cortex is the Data Fiduciary for personal data processed through the Cortex web application, marketing website, and related services.
- Operator
- Cortex Technologies Pvt. Ltd., Bengaluru, Karnataka, India. Registered address to be confirmed in this section before public launch.
- Role
- Data Fiduciary (DPDPA Sec 2(i)). Grievance Officer and Data Protection contact: the same desk until we appoint a separate DPO.
- Contact
- support@trycortex.live
- Applies to
- trycortex.live, the Cortex web application, and any subdomains we operate.
03
What we collect
Categories, purpose, and source — purpose limitation under DPDPA Sec 4. We do not collect a category unless a listed purpose needs it.
- Identity
- Email address and an 18+ attestation. Used to sign you in, enforce the age gate, and contact you about the account. Source: you, at onboarding.
- AA data
- Deposit accounts, term deposits, mutual funds, equities, credit cards, loans, transactions, balances, masked account numbers, and FI-type metadata fetched over Account Aggregator after you grant consent. Source: the AA ecosystem (Setu and participating FIPs), not screen-scraping and not SMS.
- Derived data
- Net-worth totals, category spend, detected subscriptions, forecasts, CIBIL-oriented utilisation signals, and deterministic insights the engine computes from AA data. Source: our systems, from data you already consented to share.
- Ask Cortex
- Your prompts and our replies. Identifying patterns (PAN, Aadhaar, card numbers, IFSC, UPI VPA, email, phone, long account numbers) are redacted before any model call where we can detect them. Source: you and the model.
- Consents
- Each consent granted or revoked, with version, timestamp, and FI types. Required as an audit trail under DPDPA Sec 6(4) and AA consent artefacts.
- Security logs
- Sign-ins, exports, deletions, failed authorisation, and similar events. Used for fraud defence and to prove our DPDPA processes ran. We store a coarse network range, not a precise home address.
- Waitlist
- Name, Indian mobile number, and email if you join from the marketing site. Used only to notify you of access. Source: you.
- Diagnostics
- Anonymous product analytics and crash reports, only if you allow them. No advertising identifiers.
04
What we never collect
- SMS. Cortex does not request SMS permission and does not read your messages to infer spends.
- Bank passwords, OTPs, MPIN, or card CVV. Linking uses the Account Aggregator consent artefact. Access is read-only. We never receive or store FI login secrets.
- Aadhaar, PAN, passport, or other government ID as onboarding fields. If those patterns appear in a narration or a chat you type, they are redacted before storage in model-bound payloads where technically feasible.
- Photos, contacts, calendar, precise location, microphone, camera, or biometrics.
- Data about anyone under 18. Sign-up requires an adult attestation; suspected under-age accounts are deleted.
05
Why we process it
Each purpose is limited to what the product actually does:
- Account integrity — authentication, session management, age gate, and SIM-swap / inbox-takeover defences.
- Core product — showing linked accounts, transactions, net worth, spending, investments, forecasts, and insights.
- Account Aggregator sync — fetching FI data you consented to, refreshing it while consent is active, and honouring revocation.
- Ask Cortex — generating replies grounded in your data. Requires a separate AI-processing consent.
- Cross-border AI processing — sending a redacted snapshot to our model provider. Requires a separate transfer consent. See Cross-border below.
- Legal obligation — consent ledger (DPDPA Sec 6(4)), security logs, and responses to lawful requests.
We do not sell personal data. We do not show advertising against it. We do not share it with brokers or issuers to originate products for a fee.
06
How we protect it
These are the safeguards we apply as “reasonable security practices” under IT Act Sec 43A, stated as they are designed to operate:
Encryption
- In transit — TLS on every network call between your browser, our servers, Account Aggregator, and processors.
- At rest — infrastructure encryption on database and object storage.
- On device — financial payloads are decrypted on your device. Cleartext keys are not retained by Cortex in the clear. A stolen server-side dump is not a usable statement of your money.
Access control
- Row-level security on every table that holds user data. Isolation is enforced in the database, not left to application code to remember.
- Server-side authorisation on export, deletion, sync, and Ask — not only a client check.
- Sign-in via emailed one-time code or magic link. There is no reusable Cortex password to leak. Signing out revokes sessions.
Minimisation
- Account Aggregator access is read-only for the FI types you approved.
- PII pattern redaction before model calls (PAN, Aadhaar, card PAN, IFSC, UPI VPA, email, phone, long account numbers) where detection is reliable.
- Prompt-injection hygiene on merchant names and user text before they reach a model, including look-alike and hidden-character forms where we detect them.
What we do not claim
No system is perfectly secure. Cortex has not published a named third-party penetration-test report or ISO/SOC certification on this page. If that changes, we will name the auditor and the date here. If a personal-data breach affects you, we will notify you and the Data Protection Board as required by DPDPA Sec 8(6).
Found a vulnerability? Email support@trycortex.live. We acknowledge in good faith, we will not pursue good-faith researchers, and we will credit you if you want that.
07
How long it stays
You control the clock. Almost everything is kept while the account exists and is deleted when you ask — per item where the product allows it, or all at once.
- Account
- Life of the account. Deleted when you close it.
- AA records
- Life of the account, or until you revoke AA consent and we drop the linked entities. Deleted with the account.
- Insights & Ask
- Life of the account. Wiped on account deletion.
- Waitlist
- Until we notify you of access, or you ask us to remove you.
- Consents
- Life of the account, then retained in anonymised form. DPDPA Sec 6(4) requires us to be able to prove a consent existed.
- Audit logs
- Retained for fraud and security, anonymised on account deletion. Not individually erasable — a legal/security minimum.
- Model logs
- Prompts at the AI provider may be held for a limited abuse-detection window (typically up to 30 days under that provider’s published policy), then deleted. They are not used to train models under our commercial terms.
When you delete your account
- Live systems erase your rows — identity, linked financial entities, insights, chats — within seconds of a successful request.
- Consent artefacts and security logs are anonymised. The link to you is severed; the fact that a process ran remains.
- Encrypted backups roll off on their normal cycle. Deleted data is not restored to live systems.
- Provider-side prompt copies age out on that provider’s schedule.
If in-app deletion fails, email support@trycortex.live from your account address and we will complete it.
09
Cross-border transfer
Ask Cortex may send a redacted snapshot to our model provider in the United States (DPDPA Sec 16). That snapshot is a summary of recent activity, category totals, and the current question — not your bank password, not a full statement PDF, and not government ID. Identifying patterns are stripped first where we can detect them.
Honest limitation: once data is processed in the United States it is subject to US law, and Indian statutory rights are harder to enforce against a foreign processor. If you do not consent to this transfer, tracking, insights, and forecasting remain available; Ask Cortex does not.
10
Your rights under DPDPA
- Access / port
- Sec 11. Export a machine-readable copy of the categories we hold, or email us.
- Correct / erase
- Sec 12. Edit in-product where the field is yours to edit. Delete the account to erase the rest.
- Nominate
- Sec 13. Email support@trycortex.live if you need someone appointed to act on death or incapacity. There is no in-app screen for this yet.
- Withdraw
- Sec 6(4). Revoke optional consents in settings. Essential consents (terms, privacy, 18+, AA for linked data, AI for Ask) mean you cannot keep using that part of the product if you withdraw them.
- Grievance
- Sec 14. Email support@trycortex.live. We acknowledge within 72 hours and aim to resolve within 30 days, not exceeding the DPDP Rules maximum. You may escalate to the Data Protection Board of India.
11
Children
Cortex is for adults aged 18 and over. We require an attestation at sign-up and enforce it server-side. If we learn an account belongs to someone under 18, we delete it. Report a suspected under-age account to support@trycortex.live.
13
Regulatory position
- SEBI — Cortex is not a Registered Investment Adviser. We do not give personalised investment advice. Replies that use a model are labelled as such; Cortex remains accountable for output, including under SEBI (Investment Advisers) Regulations 18(9) where that disclosure logic applies.
- RBI / AA — Cortex is not a bank, NBFC, or payment system. We do not hold funds. Financial data enters through Account Aggregator with your consent, or through a demo profile you choose to load.
- IRDAI / PFRDA / ICAI — we do not sell insurance, open NPS accounts, or file tax returns. Calculators and insights are educational.
14
When this page changes
We update this policy when the product or the law changes. Material changes are posted here, and notified in-product, at least 7 days before they take effect. The “Updated” date in the header is authoritative.
Cortex is an educational personal-finance product, not a SEBI-Registered Investment Adviser. Nothing here is investment, tax, or insurance advice. Questions — support@trycortex.live.