Software Engineer and Student
This site and the self-hosted applications behind it are operated by one person for personal use. This page states plainly what is collected and what is not.
Effective August 10, 2026. Review cadence: annually, and on any material change.
This policy covers www.kanishksachdev.com and the self-hosted applications running on subdomains of kanishksachdev.com, including the personal finance application through which bank connections are made. These applications are not offered as a service to the public. Registration is closed and the only user account is my own.
I am the only user of these applications and the only person whose data they hold. Nothing is sold. Nothing is shared with advertisers or data brokers. There is no analytics product tracking visitors across sites, and there is no third party recipient of personal data beyond the infrastructure and financial data providers listed in section 4, each of which is necessary to make the thing work.
The public portfolio can be read without signing in and without creating an account. Requests to it are served through a content delivery network and a reverse proxy, both of which write standard access logs containing the requesting IP address, timestamp, requested path, and user agent. Those logs exist to operate and secure the site, in particular to detect and block abusive traffic. They are retained on a rolling 30 day window and are not used to build a profile of any visitor.
The personal finance application connects to my own bank and brokerage accounts through third party aggregation providers. When I link an institution, the provider returns account details, balances, transactions, and holdings for the accounts I select. That data is stored in a database on infrastructure I operate.
No personal data is sold, rented, or shared for advertising. Data reaches third parties only where the provider is part of delivering the service:
Each provider is accessed through an account protected by multi-factor authentication, and each receives only what it needs to perform its function.
Traffic is encrypted in transit with TLS 1.2 or better. Financial data is encrypted at rest. Databases are not exposed to the public internet. Administrative access requires an enrolled device on a private network plus key based authentication, and applications holding financial data require multi-factor authentication before any authenticated page can be reached. The full set of controls is described in the Information Security Policy and the Access Control Policy.
Financial data is kept while the corresponding account connection is active and is removed when the institution is disconnected. Logs roll off after 30 days. Encrypted backups expire on a fixed rotation, so deleted data stops being recoverable from any copy after roughly six months. The full schedule is in the Data Retention and Deletion Policy.
Public pages set a preference cookie to remember light or dark theme. Signed in areas set a session cookie so that authentication persists between pages. Both are first party and functional. There are no advertising or cross-site tracking cookies.
Since the only data subject is the operator, requests for access, correction, or deletion are exercised directly rather than through a request process. If you nonetheless believe these systems hold data about you, for example because you contacted me by email, write to security@kanishksachdev.com and I will locate it, tell you what it is, and delete it on request.
Material changes are reflected by advancing the effective date at the top of this page. This policy is reviewed annually and whenever the set of connected providers changes.
Questions about this policy can go to security@kanishksachdev.com.