1. Scope
This policy applies to Rekh's Broker Login Assistant Chrome extension, its authentication API at broker-extension-auth.rekh.dev, and these product pages. The extension supports Zerodha and ICICI Direct, but Rekh is independent and is not endorsed by either broker.
2. Data we handle
Google sign-in data
When you choose Google sign-in, we request only openid, email, and profile. Better Auth stores your Google provider identifier, name, email address, email-verification status, profile image when supplied, and the OAuth tokens and scope needed to maintain that sign-in. We do not request access to Gmail, Drive, contacts, calendar, or other Google services.
Broker credential data
For each record you save, we store the broker, friendly account name, broker login ID, password, Base32 TOTP secret, record revision, and creation/update timestamps. When you start a login, the extension retrieves the selected record and fills it into the broker's website in your browser.
Session and operational data
Better Auth stores session identifiers, expiration and refresh timestamps, IP address, and browser user-agent information for session security. Cloudflare and Rekh's Worker process ordinary network metadata. Rekh application logs are restricted to request ID, route, status, duration, and opaque record identifiers; they do not contain emails, broker login IDs, passwords, TOTP secrets or codes, or request bodies.
Data kept in Chrome
The extension retains the secure HttpOnly auth cookie plus versioned consent, UI preferences, and non-secret login-attempt state. It does not persist broker login IDs, passwords, or TOTP secrets in Chrome storage. Sensitive form drafts and access responses remain in memory and are discarded when the action or page ends.
3. How we use data
- Authenticate you and maintain your Rekh sessions.
- Create, list, update, access, and delete the broker records you request.
- Sync those records between Chrome profiles signed into the same Rekh account.
- Start the broker login you explicitly select and generate its current TOTP code.
- Protect the service from abuse, diagnose availability, and comply with applicable law.
We do not use this data for advertising, behavioral profiling, credit decisions, product analytics, or training machine-learning models. We do not sell personal data or broker credentials.
5. Storage, location, and security
Data is transmitted over HTTPS. Cloudflare states that D1 data is encrypted at rest with AES-256 using GCM and that transfers between Workers and D1 use TLS. Encryption keys are managed by Cloudflare.
Authorized Rekh or Cloudflare infrastructure operators can technically query plaintext broker credential values. Broker Login Assistant is not a zero-knowledge password vault.
Cloudflare operates a global network. We use an APAC placement hint for D1 but do not promise India-only storage or processing. No method of storage or transmission is perfectly secure.
See Cloudflare's current D1 data-security documentation.
6. Retention and deletion
Broker records remain until you delete them or delete your Rekh account. Sessions are valid for up to seven days and roll while active; signing out deletes the current session, and “sign out everywhere” revokes all sessions.
Deleting your Rekh account removes its active broker credentials, sessions, Google account linkage, and Better Auth user record. For safety, deletion requires a Google-authenticated session created within the preceding five minutes.
Cloudflare D1 Time Travel is always on. Under the initial Workers Free plan, deleted records may remain in provider-managed recovery history for up to seven days before falling outside that recovery window. See Cloudflare's Time Travel documentation.
7. Your choices
- Do not accept the disclosure or sign in if this storage boundary is unsuitable.
- View, edit, copy, or delete individual broker records from the extension.
- Sign out in one Chrome profile or revoke every active session.
- Delete the complete Rekh account from extension settings.
- Contact us to ask about your data or report a privacy concern.
Because there is no persistent local credential cache, saved broker credentials are unavailable when the network or Cloudflare service is unavailable.
8. Children and changes
The product is not directed to children. We may update this policy when the product or legal requirements change. Material changes to data practices will be disclosed before the changed handling begins, and the effective date above will be updated.
9. Contact
Email privacy or data requests to hello@rekh.dev. Do not include a broker password, TOTP secret, current TOTP code, or real account credentials in support email.