Draft

Draft — pending legal review. Do not rely on this document. 12 items marked TO CONFIRM are still open for counsel; until they are settled, nothing here binds you or WealthX.

Legal

Privacy Policy

What CryptX actually stores about you, why each item exists, who else ever sees it, and what you can ask us to do with it. This page describes the real database behind the service — not a generic template. If something is not listed here, we do not collect it.

Last updated 12 August 2026

1Scope, and who we are

CryptX is a product of WealthX Technologies Pvt. Ltd. (“WealthX”, “we”, “us”). This policy covers the CryptX website, the client portal at /app, and the automated execution service behind them. It forms part of the Terms of Service.

It does not cover Delta Exchange India, Razorpay, or any other company you deal with directly. Your exchange account is governed by Delta’s own privacy policy; a card or UPI payment is governed by Razorpay’s.

Data fiduciaryWealthX Technologies Pvt. Ltd.
Registered officeTO CONFIRM: registered office address
Grievance OfficerTO CONFIRM: name, designation and email of the Grievance Officer / Data Protection Officer, and whether one is required

2What we actually hold

Everything below is a real field in the CryptX database. Nothing else about you is stored.

Because you signed up

ItemDetail
First and last nameAs you typed them. Used to address you and on invoices.
Email addressYour login identity, and where verification codes, invoices and service notices go.
Mobile numberAn Indian mobile, stored in +91XXXXXXXXXX form. Used to deliver the verification code over WhatsApp, and for support.
PasswordStored only as a salted one-way hash. The plain password is never written to disk and cannot be recovered by us — only reset.
Verification codesStored as a hash, never in the clear, with an attempt counter, an expiry and two flags recording whether the email and WhatsApp sends succeeded.
Password-reset requestsYour user id, the email, and whether the request is open or done.

Because you connected an exchange account

ItemDetail
Delta API key and secretEncrypted at rest with Fernet (AES) before they touch the database. Decrypted in memory only to place, manage and close orders on your account. See section 6.
Connection settingsThe exchange endpoint, a label for the connection, your size multiplier and minimum size, whether auto-adjust is on, and whether the connection is active or disconnected.
Last wallet balance readA single USD figure, refreshed from Delta, used to size positions in proportion to your balance and to show your dashboard.

Because the algorithm traded

ItemDetail
Execution ledgerOne row per order we send for you: the option symbol, buy or sell, size in contracts, the status (placed, dry-run, skipped or failed), the exchange order id, the fill price, any error the exchange returned, and the timestamp.
Billing windowsStart and end of each window, the gross realised P&L inside it, any deficit carried in or out, the fee percentage, and the fee in USD and INR.
InvoicesAmount in INR, the gross profit the fee was computed on, open or paid, the Razorpay order and payment references, and the created and paid timestamps.

Technical

  • A signed session cookie holding your user id, so you stay logged in. Nothing else is kept in it.
  • Your light/dark preference, stored in your own browser as cx-theme. It never reaches our server.
  • Web-server logs. TO CONFIRM: what our web server and hosting provider log (IP address, user agent, request line), how long those logs are kept, and whether that retention should be published here

3What we do not collect, and cannot do

  • No card, UPI or bank details. Payment instruments are collected by Razorpay on their own page. We receive a payment reference and a success signature — never the instrument.
  • No KYC documents. We do not ask for or store PAN, Aadhaar, passport, address proof or bank statements. Your identity verification happens with Delta Exchange, not with us. TO CONFIRM: whether PAN or GSTIN must be collected for tax invoices, and if so what changes here
  • No advertising or analytics trackers on these pages. There is no Google Analytics, no Meta pixel, no advertising network, no third-party cookie and no cross-site tracking on the public CryptX site.
  • No location, contacts, camera, microphone or device fingerprinting.
  • No sale of your data. We do not sell, rent or trade personal data, and we do not share it for anyone else’s marketing.
  • No access to your exchange account beyond the key. We cannot read your Delta login, your KYC file or your bank details, and the key you issue cannot withdraw funds.

4Why each item exists

  • To run the service you asked for. Name, email, phone, password hash and API credentials exist so an account can be created, verified, logged into and traded.
  • To show you what happened. The execution ledger is what produces your positions, your P&L and your notifications. It is also the audit trail if a fill is ever disputed.
  • To bill you correctly. Billing windows and invoices exist so a fee can be calculated, evidenced and reconciled — see the fee terms.
  • To keep the account secure. Verification codes and reset records exist to stop someone else claiming your email or phone.
  • To answer you. Support correspondence is kept so a query has a history.

TO CONFIRM: the lawful basis to state for each purpose under the Digital Personal Data Protection Act, 2023 — consent versus legitimate uses — and the exact form of notice and consent the Act requires at signup

5Cookies and browser storage

There are exactly two things stored in your browser by CryptX, and neither of them tracks you.

Session cookieSigned, holds your user id, keeps you logged in. Strictly necessary.
cx-themeLight or dark. Local to your browser, never transmitted.

Because we set no analytics or advertising cookies, there is no consent banner to click through. Clearing your browser storage logs you out and resets the theme; nothing else is affected.

6Your exchange API keys

This is the most sensitive thing you give us, so it gets its own section.

  • Encrypted at rest. The key and secret are encrypted with Fernet before being written, using a master key held in the server environment and never stored in the database alongside the data it protects.
  • Trade permissions only. We ask you to issue a key with withdrawals disabled. Delta enforces that on their side, so a compromise of our systems could not by itself move your money, provided the key you issued has withdrawals disabled as we ask.
  • IP whitelisting. We publish the single execution IP in your portal so you can bind the key to it.
  • Used for one thing. The credentials are decrypted only to read your balance and to place, manage and close positions on your own account.
  • Destroyed on disconnect. When you disconnect a connection, the stored key and secret are overwritten in the database and the real credentials are gone. The connection row itself is kept, because your execution ledger and your invoices refer to it — see section 10.

7Who else your data reaches

We use a small number of processors, each for one job. No one else receives your data, and none of them receive more than the job needs.

WhoWhat they getWhy
Delta Exchange IndiaYour API credentials and the orders we placeIt is your account; they execute and custody
RazorpayYour email, the invoice amount and referenceTo collect a performance-fee payment
AiSensy (WhatsApp)Your mobile number, your first name and the one-time codeTo deliver the signup verification code
Our email providerYour email address and the message bodyVerification codes, invoices, service notices
Our hosting providerHolds the server the database runs onTo run the service at all

We may also disclose data where the law compels it, or to establish or defend a legal claim. If that ever happens we will tell you unless we are prohibited from doing so. TO CONFIRM: the list of named processors counsel wants published, and whether written processing agreements are in place with each

8Where the data is stored

Your data sits in a single database on a server we control, reachable only over an encrypted connection.

TO CONFIRM: the hosting provider and the data-centre region to disclose, and the cross-border transfer statement required if that region is outside India

9How long we keep it

  • Account details for as long as you have an account with us.
  • API credentials only while a connection is live — they are destroyed the moment you disconnect.
  • Execution ledger, billing windows and invoices are financial records. They are kept after you leave, so that a past invoice can be evidenced and reconciled.
  • Verification codes expire in minutes and are stored hashed.

TO CONFIRM: the exact retention period for each category, and the statutory minimum that applies to invoices and financial records in India

10Disconnecting, and asking us to delete

Disconnecting is instant and self-serve. Remove the connection in the portal, or delete the key inside your Delta account, and execution on your account stops. The stored credentials are destroyed. Read section 9 of the Terms first if you have open positions — once the key is gone we can no longer close them for you.

Deleting your data is a written request. There is no self-serve delete button today. Email support@cryptxindia.com from your registered address and we will erase your personal details. We will keep the execution and invoice records we are required to keep, unlinked from your profile where we can. We would rather say this plainly than promise an erasure we cannot perform.

TO CONFIRM: the response time to commit to for an erasure request, and which records must be retained by law despite it

11Security, stated honestly

  • Credentials are encrypted at rest; passwords and one-time codes are stored only as hashes.
  • The site is served over HTTPS, and the session cookie is signed.
  • The trading key cannot withdraw, and we ask you to whitelist a single IP for it.
  • Payment instruments never reach our servers.

No system is perfectly secure, and we will not claim otherwise. The strongest protection in this design is not ours — it is that your money never leaves your own exchange account and the key we hold cannot move it. Use a unique password here, and revoke the key on Delta if you are ever concerned.

TO CONFIRM: the breach-notification commitment to publish — who we notify, within what period, and what the Digital Personal Data Protection Act, 2023 requires

12Your rights, and how to use them

  • See what we hold. Ask, and we will send you your record.
  • Correct it. Name, email and phone can be corrected on request; the execution ledger cannot be edited, because it is a record of what actually happened.
  • Erase it. See section 10.
  • Withdraw consent. Disconnect, and stop using the service.
  • Complain. Write to us first; escalation details are on the Contact page.

All of these start at support@cryptxindia.com from your registered email address.

TO CONFIRM: the statutory list of data-principal rights and the grievance-redressal wording required by the Digital Personal Data Protection Act, 2023, including the right to nominate

13Age

CryptX is not for anyone under 18. We do not knowingly hold data about a minor; if we learn that we have, we will delete it and close the account.

14Changes, and how to reach us

If this policy changes materially we will email the address on your account and update the date at the top of this page. TO CONFIRM: notice period for a material change to this policy

WealthX Technologies Pvt. Ltd. — cryptx.wealthx.tech, support@cryptxindia.com, WhatsApp +91 91879 46508.