BROKER LOGIN ASSISTANT / PRIVACY

Privacy, without
the small-print fog.

Effective 27 August 2026 · Publisher, seller, and data controller: Rekh · Contact: hello@rekh.dev

1. Scope

This policy applies to Rekh's Broker Login Assistant Chrome extension, its authentication API at broker-extension-auth.rekh.dev, and these product pages. The extension supports Zerodha and ICICI Direct, but Rekh is independent and is not endorsed by either broker.

2. Data we handle

Google sign-in data

When you choose Google sign-in, we request only openid, email, and profile. Better Auth stores your Google provider identifier, name, email address, email-verification status, profile image when supplied, and the OAuth tokens and scope needed to maintain that sign-in. We do not request access to Gmail, Drive, contacts, calendar, or other Google services.

Broker credential data

For each record you save, we store the broker, friendly account name, broker login ID, password, Base32 TOTP secret, record revision, and creation/update timestamps. When you start a login, the extension retrieves the selected record and fills it into the broker's website in your browser.

Billing and subscription data

If you start or maintain Pro, Rekh stores the selected provider, Rekh user identifier, provider plan and subscription identifiers, checkout approval URL while needed, subscription status, latest payment reference, provider update time, and access end date. Signed webhook event identifiers and provider resource identifiers are retained to prevent duplicate processing and reconcile entitlement state.

Razorpay or PayPal collects and processes the payment, account, billing, card, bank, UPI, tax, and fraud-prevention information required by the checkout you select under its own privacy policy. Rekh does not receive or store card numbers, CVVs, bank credentials, UPI PINs, or PayPal passwords.

Session and operational data

Better Auth stores session identifiers, expiration and refresh timestamps, IP address, and browser user-agent information for session security. Cloudflare and Rekh's Worker process ordinary network metadata. Rekh application logs are restricted to request ID, route, status, duration, and opaque record identifiers; they do not contain emails, broker login IDs, passwords, TOTP secrets or codes, or request bodies.

Data kept in Chrome

The extension retains the secure HttpOnly auth cookie plus UI preferences and non-secret login-attempt state. It does not persist broker login IDs, passwords, or TOTP secrets in Chrome storage. Sensitive form drafts and access responses remain in memory and are discarded when the action or page ends.

3. How we use data

  • Authenticate you and maintain your Rekh sessions.
  • Create, list, update, access, and delete the broker records you request.
  • Sync those records between Chrome profiles signed into the same Rekh account.
  • Start the broker login you explicitly select and generate its current TOTP code.
  • Create the provider checkout you request, reconcile subscription events, and enforce Free or Pro account limits.
  • Protect the service from abuse, diagnose availability, and comply with applicable law.

We do not use this data for advertising, behavioral profiling, credit decisions, product analytics, or training machine-learning models. We do not sell personal data or broker credentials.

Broker Login Assistant's use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.

4. Services and sharing

Google provides authentication. Cloudflare runs the Worker, D1 database, network, and provider-managed recovery history. Razorpay and PayPal provide hosted recurring checkout and subscription processing. Rekh sends the selected provider an opaque Rekh user identifier and the plan information needed to create and reconcile the subscription. When you start a broker login, the extension sends the selected login values to the relevant Zerodha or ICICI Direct page in your browser; those sites handle the login under their own policies.

We may disclose information if required by applicable law or to protect users, Rekh, or the service. We do not share credential data with advertisers, data brokers, or unrelated third parties.

5. Storage, location, and security

Data is transmitted over HTTPS. Cloudflare states that D1 data is encrypted at rest with AES-256 using GCM and that transfers between Workers and D1 use TLS. Encryption keys are managed by Cloudflare.

This is provider-level encryption, not end-to-end encryption.

Authorized Rekh or Cloudflare infrastructure operators can technically query plaintext broker credential values. Broker Login Assistant is not a zero-knowledge password vault.

Cloudflare operates a global network. We use an APAC placement hint for D1 but do not promise India-only storage or processing. No method of storage or transmission is perfectly secure.

See Cloudflare's current D1 data-security documentation.

6. Retention and deletion

Broker records remain until you delete them or delete your Rekh account. Sessions are valid for up to seven days and roll while active; signing out deletes the current session, and “sign out everywhere” revokes all sessions.

User-linked subscription records remain while needed to provide Pro, reconcile provider state, resolve payment issues, and meet legal or accounting obligations. Webhook event identifiers may remain after account deletion to prevent duplicate event processing. Payment providers retain their records under their own policies.

Deleting your Rekh account removes its active broker credentials, sessions, Google account linkage, Better Auth user record, and user-linked subscription state. It does not cancel provider billing, so active Pro renewal must be canceled first. For safety, deletion requires a Google-authenticated session created within the preceding five minutes.

Cloudflare D1 Time Travel is always on. Under the initial Workers Free plan, deleted records may remain in provider-managed recovery history for up to seven days before falling outside that recovery window. See Cloudflare's Time Travel documentation.

7. Your choices

  • Do not accept the disclosure or sign in if this storage boundary is unsuitable.
  • View, edit, copy, or delete individual broker records from the extension.
  • Sign out in one Chrome profile or revoke every active session.
  • Delete the complete Rekh account from extension settings.
  • Cancel Razorpay renewal in extension Settings or manage PayPal renewal through PayPal Automatic Payments.
  • Contact us to ask about your data or report a privacy concern.

Because there is no persistent local credential cache, saved broker credentials are unavailable when the network or Cloudflare service is unavailable.

8. Children and changes

The product is not directed to children. We may update this policy when the product or legal requirements change. Material changes to data practices will be disclosed before the changed handling begins, and the effective date above will be updated.

9. Contact

Email privacy or data requests to hello@rekh.dev. Do not include a broker password, TOTP secret, current TOTP code, or real account credentials in support email.