Privacy
Thesis is an invite-only learning network for investors, hosted in India. This page says what we store, why, for how long, and how you leave. It is written to comply with India's Digital Personal Data Protection Act (DPDP), 2023.
What we collect, and why
Identity: your email, your real name, and the invite that vouched for you (membership is invitation-only, so the invite chain is part of your identity here). Credentials: a one-way hash of your password — we cannot read it, ever. Your work: what you publish (theses, charts, discussions), which is the point of the platform, and your private material (journal, drafts, simulator history), which stays private to you. Sign-in region: on login we derive your state/region from your network address and store only the region — never the IP address itself. Usage: which sections of the app you visit (path only — no IPs, no device fingerprints, no third-party trackers), and security events on your account (sign-ins, failed attempts, password changes).
What we never do
No advertising, no selling or sharing of data, no third-party analytics, no tracking cookies. The only cookie is your session. Your data is stored in India and does not leave the country in the normal course of operation — with one narrow exception: delivering a password-reset email (see "Email" below).
We email you in exactly one situation: you asked to reset your password. Delivery is handled by a third-party service provider; your email address and the message pass through its servers to reach you. Everything else reaches you inside the app.
Retention
Your account data lives as long as your account does. Usage records are pruned automatically (page visits after 180 days, security events after 365 days). Nightly backups rotate every 14 days — so after you delete your account, copies of your data persist in backups for up to 14 more days, then are gone.
Leaving (the Right To Leave)
You can delete your account yourself, from Settings, at any time — no emails, no approval. Deletion is all-or-nothing: your identity and private data are erased; knowledge you chose to publish remains, anonymized to "Former Member," because a published thesis is an issued report the community may have relied on. This is stated before you ever publish.
Your rights & contact
You may access and correct your data (Profile & Settings) or erase it entirely (account deletion). For any concern — including grievances under the DPDP Act — message the founder directly on Thesis; every member has this channel. A dedicated grievance email address will be published on this page when it goes live. If we ever suffer a breach affecting your data, you will be told plainly and promptly what was and wasn't exposed.
Version 1.1 — 5 September 2026 (added: the password-reset email exception) · Version 1.0 — 22 July 2026. Back to sign in