What Sahi keeps, and why.

Sahi Capital is a tool for wealth advisors. A firm signs in, brings in its families’ statements, declares each family’s principles and reads what drifted. This page says what that involves, in plain words. Last revised 16 September 2026.

Who this covers

Two kinds of people. Advisors, who sign in and use Sahi. Clients, the families whose money an advisor looks after, whose details an advisor enters or imports. A client never signs in and never sends Sahi anything directly; their firm does, on their behalf.

What is kept

  • About an advisor: an email address, a name, the firm they belong to and their role in it. When they sign in, the device and browser, the network address and the city it resolves to, so that Settings can list where they are signed in and let them end any session. Those records go when the session does.
  • About a client: a name, an email address if the advisor records one, the household they belong to, notes the advisor writes after a meeting, the principles the advisor declares for them, and the dates they were last reviewed and last spoken to. No PAN, no date of birth, no bank account.
  • The book: the holdings and transactions that a statement contains, read out of a CAMS statement, an MFCentral export or a broker file. The rows are kept. The file itself is not: it is read once and discarded, and only its name and how many rows it carried are recorded.
  • Prices and fund holdings from public sources, which belong to nobody.

Why

To do the one thing the product does: value each family’s book against what that family declared, and show the advisor what needs attention. Nothing is kept for any other purpose. There is no advertising, no analytics script, no tracking pixel, and nothing is sold or shared with anyone for their own use.

Who can see it

Each firm’s data is sealed from every other firm by rules in the database itself, not by a filter in the app. Within a firm, a partner sees the firm’s clients and a relationship manager sees their own. Sahi’s operator can reach the database to run and support the service, and does not look at a firm’s data except to fix a problem that firm has raised.

Where it lives

The application runs on Vercel, served from Mumbai. The database and the sign-in service are provided by Supabase. Sign-in codes are sent by email through Resend. The nightly jobs that fetch prices and fund holdings run on GitHub and write them to the same database. These four are the only companies that handle the data, and each handles it to run the service and for nothing else.

Sign-in and cookies

There is no password. An advisor signs in with a code sent to their email. The only cookies are the ones that keep that sign-in: the session itself, and two small clocks that end it after an hour idle or twelve hours in all. Nothing tracks a visitor to the front page.

How long

For as long as the firm uses Sahi. When a firm leaves, its clients, notes, principles and book are deleted with it. A client’s record can be removed by their advisor at any time.

Your rights

Anyone whose details are held, an advisor or a client, can ask what is held about them, have it corrected, or have it erased. Write to hello@sahicapital.com and say who you are; a client should write through, or with, their advisor, since it is the firm that holds their record. This is also the address for any grievance about how data has been handled. If a grievance is not resolved, the Data Protection Board of India can be approached under the Digital Personal Data Protection Act, 2023.

Changes

If what Sahi keeps or does with it changes, this page changes first, and the date at the top with it.