Skip to content
Punji
NEPSE today
LearnFeaturesHow it works
Search stocks, brokers, pagesSearch stocksSearch/
App StoreGoogle Play
Search stocks, brokers, pagesNEPSE todayHow the market closed

Markets

  • Heat map
  • Screener
  • Compare
  • Stock pages
  • Floorsheet
  • Brokers
  • Dividends

Rates

  • Forex
  • Gold & silver

Tools

  • Calculators
  • IPO
  • Portfolio tracker
  • Virtual trading
  • Learn
  • Features
  • How it works
Download on the App StoreGet it on Google Play
  1. Home
  2. /Privacy

Privacy

What we collect and why.

Punji is built and operated by an independent developer in Nepal. This page lists what the app and this website collect, who else receives it, and how long it is kept. We do not sell or rent your data.

Last updated · 25 September 2026

Also here

  • Terms of useWhat you agree to when you use Punji.
  • Delete your accountWhat deletion removes, what it keeps, and when.
  • SupportCommon problems, and how to reach us.

Questions: [email protected]

1. Who is responsible for your data

Punji ("we", "us") is an independent product operated from Nepal. The data controller for the purposes of this policy is the operator of the Punji mobile app. Contact: [email protected].

2. What we collect

Your account

  • Sign-in: your email address and password (handled by our database provider, Supabase, which stores the password only as a hash), or your Google or Apple sign-in. With Apple we receive your name once; with Google, the name and photo on that account.
  • Preferences: theme, language, and which notifications you have turned on.
  • Activity counters: the last day you used the app and how many days you have been active, used for invite rewards and to understand how the app is used.
  • Sign-up check: when an account is created we keep the provider, your email in a normalised form, its domain, and a keyed hash of your network's address range (never the full IP address), to spot repeated sign-ups. Kept for 120 days.

Your portfolio and records

  • Holdings, transactions and their notes, watchlists, price alerts (including any message you write for an alert), screener presets, and reminders you set.
  • Family portfolios: the names you give the people you track, and their holdings.
  • Other assets you add (bank balances, deposits and similar), your portfolio's daily value history, dividends you confirm, and the weekly digest built from your portfolio.

MeroShare and broker (TMS) accounts

  • Kept only on your phone: your MeroShare password, CRN and transaction PIN, and your TMS password if you choose to save it. They are stored in the phone's secure storage (iOS Keychain or Android Keystore), behind your fingerprint, Face ID or passcode, and are sent only to MeroShare (operated by CDSC) or your broker's own TMS site when you act. Punji's servers never receive them.
  • Sent to Punji when you sync MeroShare: the holdings MeroShare lists (symbol, quantity, average cost, acquisition date and how the shares were acquired), the account's BOID, and an account reference that includes your MeroShare username and DP number. If you use Family auto-setup, the account holder's name as MeroShare shows it and the DP name are also stored.

What other people can see

Your holdings, watchlist, alerts and account details are private. Only what you choose to share in Community and on the virtual trading leaderboard is visible to other Punji users:

  • Your @handle, whenever you post, comment or appear on the leaderboard.
  • Your sign-in name and photo, next to your @handle, only if you agree. You can turn this off at any time from your Community profile. Names that could pass for Punji staff or a market body are not shown.
  • Your posts and comments, and your virtual trading rank and return if you opted into the leaderboard. Virtual trading uses no real money.

Your email address is never shown to other users.

Collected automatically

  • App analytics (PostHog): the app records screens you open and actions you take, tied to your Punji user ID. Some actions carry the stock symbol involved, for example adding a holding or a watchlist entry, creating an alert, or opening a stock's floorsheet. Others carry counts, such as how many holdings a MeroShare sync imported. Quantities, prices and portfolio values are not sent. The address of each screen is recorded, and for the MeroShare and TMS account screens that address can include the account's username. The app has no setting to turn analytics off today.
  • Crash and error reports (Sentry): when the app hits an error, a report with technical details is sent, labelled with your user ID and email address. If you send feedback through the in-app form you can attach a screenshot.
  • Push notifications: your device's push token, platform and app language, so the notifications you turn on reach you.
  • Server logs: each request's address, status and timing. The request log does not record your IP address or user ID. Your IP address is used briefly to limit abusive traffic and is not stored.
  • App updates and performance: the app checks Expo's service for updates and reports load performance to it.

What we do not collect

  • Your MeroShare or TMS password, CRN or transaction PIN (see above).
  • Your contacts, calendar, photos, microphone or precise location.
  • Your date of birth. There is no age check at sign-up (see section 9).

3. How we use your data

  • To run the service: show your portfolio, work out tax and fees, check your alerts on our servers, and send the notifications you turned on.
  • To show ads that pay for the free app: see section 4 (Google AdMob).
  • To fix and improve the app: crash reports, logs and app analytics.
  • To prevent abuse: the sign-up check, rate limits, and the 180-day email hold after deletion (section 6).
  • To contact you: service messages such as password resets. We do not send marketing email to you. If you invite a friend by email, we send that one invite on your behalf (section 4, Resend).

No personal data is sent to any AI service. The daily brief is assembled by rules from your holdings, market data and events, not by an AI model.

4. Who receives data

Each of these receives only what its role needs:

  • Supabase (Supabase Inc.): our database and sign-in service. It stores your account and everything in section 2 that is kept on our servers.
  • Railway (Railway Corp.): runs the server behind the app, including alert checks.
  • Cloudflare (Cloudflare, Inc.): sits in front of our server and this website, and runs the sign-in CAPTCHA (Turnstile).
  • PostHog (PostHog Inc., US cloud): app analytics as described in section 2, tied to your user ID; also this website's analytics (section 11).
  • Sentry (Functional Software, Inc.): crash and error reports, with your user ID and email address.
  • Expo (650 Industries, Inc.), Apple and Google (Firebase): deliver push notifications and app updates. A notification's text, and what it opens, pass through them. Tax alerts leave rupee amounts out of the text so they don't show on a locked screen; the weekly digest shows your portfolio's percentage change.
  • Google AdMob (Google LLC): serves the ads (section 5). It receives standard device signals such as device type, OS version, approximate region and IP address, and your advertising ID where ads are personalised. Your holdings, watchlist, alerts and email are never sent to AdMob.
  • RevenueCat (RevenueCat, Inc.): would process purchases of a paid plan through the App Store or Google Play, using your user ID. No paid plan is on sale today.
  • Resend (Resend, Inc.): sends an invite email when you ask the app to invite a friend. It receives their address and your display name. We then keep only a keyed hash of their address, a masked form of it and its domain, so we don't invite the same person twice.
  • Have I Been Pwned: when you set a password, the app checks it against known leaked passwords by sending only the first five characters of its hash; the password itself never leaves the phone.
  • Discord (Discord Inc.): when an account is created, our private team channel receives the sign-in provider, the first eight characters of the user ID and a masked email (first letter and domain).
  • CDSC (MeroShare) and your broker's TMS site: your credentials go from your phone straight to them when you act. They are the operators of those services, not our processors.

We do not sell or rent personal data, and we do not work with data brokers.

5. Ads

  • One small banner ad appears on a few browse screens: Today, Markets, stock pages, watchlist, news, floorsheet, screener results and Discover lists. There are none on the portfolio, family, MeroShare, sign-in, payment or settings screens.
  • A few actions ask you to watch a short video once you pass a free daily allowance: for example adding MeroShare accounts after 20 a day, a sync after 30 a day, a tax summary refresh after one a day, a backtest after three a day, and each alert beyond 10 active ones. Deeper floorsheet analysis (the full broker list, every Detective case, buy/sell pressure) and the full Price Action scans open for an hour after a video; the top of each list is always free.
  • Personalisation: on first use the app shows Google's consent form where it applies, and on iPhone Apple's tracking prompt. Ads are personalised only if the consent form records consent or is not required where you are, and, on iPhone, you allow tracking. Android has no tracking prompt, so where no consent form is required, Android ads are personalised.
  • Invite rewards (ad-free days) turn ads off for the days earned.

6. How long we keep data

  • Account and portfolio data: while your account exists. Deletion removes much of it after a 30-day grace period, but not all of it today; the delete-account page lists exactly what is removed and what is not.
  • Your email after deletion: 180 days, only to stop the same address opening a new account in that time.
  • In-app notifications: market briefs 7 days, others 90 days.
  • Sign-up check records: 120 days.
  • Analytics, crash reports and server logs: kept by PostHog, Sentry and Railway under their own retention settings. Deleting your account does not yet erase them early.
  • Payments: none today. Punji takes no payments.

7. Your rights

Wherever you live, you can use these rights. EU, UK, California and similar laws name them; we extend them to every Punji user.

  • Access and portability: export your holdings as CSV from the portfolio screen, or ask us for a copy of what we hold about you.
  • Correction: edit any holding, transaction or profile field in the app.
  • Erasure: delete your account in the app (You → Account & device security → Delete account), or follow the delete-account page if you can't sign in. To have data that deletion does not yet cover removed, write to us.
  • Objection and restriction: write to [email protected]; we respond within 30 days.
  • Complaints: EU and EEA residents can complain to their data-protection authority (listed by the EDPB); UK residents to the ICO. California residents have the rights the CCPA describes, including to know and to delete. Punji does not sell personal information.

8. Security

Data is encrypted in transit (HTTPS) and at rest by our database provider. Each user's data is separated by database access rules, so one user cannot read another's. The app can require your fingerprint, Face ID or passcode when it opens, always does before it reads saved MeroShare or TMS credentials, and blocks screenshots on the MeroShare and TMS account screens. Nobody at Punji reads your holdings except to answer a support request you make.

9. Children

Punji is not meant for children under 16. There is no age check at sign-up, so if you believe a child has created an account, write to us and we will delete it.

10. Changes to this policy

When what the app collects changes, we update this page and its date in the same release. For material changes we also tell you in the app.

11. This website (punji.app)

This website runs privacy-focused analytics through PostHog to see which pages are useful and whether they lead anyone to the app. We record page views, clicks on the App Store and Google Play buttons, and a few named interactions on pages with controls: for example that a sector filter was set on the listed-companies page, and to which sector. For a search box we record that a search happened, how many results it returned and how many characters were typed, never the text. We do not set tracking cookies, record sessions, capture what you type, or run advertising scripts. A random visitor identifier is kept in your browser's local storage, not a cookie, and is not linked to your name, email or app account. Events are sent to punji.app itself and passed on to PostHog from there, without your IP address: PostHog receives only an approximate country and city, which Cloudflare works out from the request. Page addresses are recorded without their query strings, apart from campaign tags, and invite links without their code. If your browser sends Do Not Track or Global Privacy Control, we collect nothing. The hosting provider's access logs are kept for operational debugging.

12. Contact

Questions, requests or complaints about this policy: [email protected].

On this page

  1. 011. Who is responsible for your data
  2. 022. What we collect
  3. 033. How we use your data
  4. 044. Who receives data
  5. 055. Ads
  6. 066. How long we keep data
  7. 077. Your rights
  8. 088. Security
  9. 099. Children
  10. 1010. Changes to this policy
  11. 1111. This website (punji.app)
  12. 1212. Contact
Punji

A calmer way to follow NEPSE. Made in Kathmandu, for Nepali investors.

[email protected]

Download on the App StoreGet it on Google Play

Follow us

Live market

  • NEPSE today
  • Heat map
  • Floorsheet
  • Stock pages
  • Listed companies
  • Sectors
  • Brokers
  • Dividends
  • Screener
  • Compare
  • Forex
  • Gold & silver

Your money

  • Portfolio tracker
  • Calculators
  • IPO result check
  • Virtual trading

Punji

  • Features
  • How it works
  • Pricing
  • Learn
  • Changelog
  • Support
  • About

Legal

  • Privacy
  • Terms
  • Delete account

Market data is derived from published NEPSE data and may be delayed. Nothing here is investment advice.

© 2026 Punji. All rights reserved.

Charts by TradingView

Free to use. Supported by ads.