Privacy policy

Last updated: 15 September 2026

This policy explains what the SajiloShare mobile app for Android and iOS ("the App") and this website collect, where that information lives, and what you can do about it.

In short: your MeroShare credentials are stored only on your phone, with the password and PIN encrypted. We do not run accounts, we cannot see your password, PIN, CRN or portfolio, and we never sell data.

1. What stays on your device

Everything you enter to add a MeroShare account is kept in the App's private storage on your phone:

  • Depository participant (DP), username and password.
  • CRN, transaction PIN and the BOID returned by MeroShare.
  • The labels you give accounts, such as “Mummy” or “Personal”.
  • Transactions you add by hand to the portfolio, and your app settings.

When you apply for an issue, refresh your portfolio or check an account's renewal date, the App sends these credentials directly from your phone to CDSC's MeroShare servers. They are never sent to a SajiloShare server. Portfolio and transaction data comes back to your phone and is analysed there.

2. What reaches our server

  • Push notification token. If notifications are enabled, your device's Firebase Cloud Messaging (FCM) token is registered so we can tell you when an IPO opens or is about to close.
  • IPO result checks. To read the captcha on CDSC's result site automatically, the App sends the captcha image to our server. For some older issues, the BOIDs you selected and the company are relayed through our server to CDSC's official result site. These are used only to fetch that result and are not stored.
  • Standard request logs (IP address, time, path) kept by our hosting for security and debugging.

IPO calendar data shown in the App and on this website comes from CDSC's public issue list and involves no personal data.

3. Third-party services

  • CDS and Clearing Ltd. (CDSC) / MeroShare: receives your credentials directly from your phone when you use a feature that needs them.
  • Google Firebase: Cloud Messaging for notifications, Analytics for anonymous usage statistics, and Crashlytics for crash reports. None of these include your credentials.
  • Google AdMob: serves the ads that keep the App free. AdMob may use device identifiers according to Google's policies.
  • Public market data sources: share prices are fetched without any personal information attached.

We do not sell, rent or trade your personal data.

4. Security

  • Your MeroShare password and transaction PIN are encrypted with AES-256-GCM before they are stored. The key is generated on your phone and kept in the Android Keystore or iOS Keychain, and never leaves the device.
  • Other account details are kept in the App's private storage, which other apps cannot read.
  • You can lock the App behind a 4-digit PIN and fingerprint or Face ID. Revealing a saved credential asks for that lock again.
  • Moving accounts to a new phone uses an encrypted transfer file or a nearby Wi-Fi transfer, protected by a password or one-time code that is never stored in the file.
  • All network traffic uses HTTPS.

5. Retention and deletion

  • Deleting an account in the App removes its credentials from your phone immediately. Uninstalling the App removes everything it stored.
  • Turning notifications off, or uninstalling, stops your FCM token from being used. Tokens that Firebase reports as invalid are deactivated automatically.
  • Because we never receive your credentials or portfolio, there is nothing of that kind for us to delete on our side.

6. Your choices

  • Disable push notifications from More → Settings, or from your phone's settings.
  • Reset your device's advertising ID, or opt out of personalised ads, in your phone's settings.
  • Email us to ask what, if anything, we hold about your device, or to have it removed.

7. Children

The App is intended for adults who hold their own demat accounts. We do not knowingly collect personal information from children.

8. Changes

If this policy changes, the date at the top of this page will change with it. Material changes will also be noted in the App's release notes.

9. Contact

Privacy questions or requests: [email protected].