RightBonds Fixed Income, Simplified
The short version

RightBonds does not collect, transmit, or store any personal or financial data on its servers. Your portfolio holdings never leave your browser. All data you upload is processed locally and saved only in your device's localStorage. You can delete it instantly at any time.

1. Who we are

RightBonds (rightbonds.com) is an independent bond yield aggregator for the Indian fixed-income market. We aggregate publicly available bond listings from multiple investment platforms - GoldenPi, Jiraaf, GripInvest, BondScanner, WintWealth, NSE, and BSE - and present them in a single, filterable interface to help investors compare options.

RightBonds is not a registered investment adviser, broker, or financial institution. Nothing on this site constitutes investment advice.

2. Data we collect - and what we do not

2.1 Bond listings (server-side scraper)

Our automated scraper runs once daily. It fetches publicly available bond data from partner platforms (prices, yields, maturity dates, ISIN numbers) and writes the result to a static JSON file. This scraper processes only public market data and never interacts with any user account or personal information.

2.2 Portfolio analysis (entirely in-browser)

The Portfolio feature lets you upload a holdings statement (CDSL or NSDL depository export) to analyse your bond portfolio. This feature is built with a privacy-first architecture:

2.3 What we do NOT collect

Category Status Detail
User accounts / registration Not collected No sign-up, no login, no email required
Portfolio or holdings data Not collected Stays in your browser's localStorage only
Personal or financial data Not collected No name, email, portfolio value, holdings or ISIN codes are ever sent to us or to our analytics provider. Your full IP address is not either - see the row below
Cookies Not used No cookies set. localStorage holds only the portfolio data you explicitly upload; our analytics keeps nothing on your device (in-memory session only)
IP addresses Truncated, never stored in full Our edge cuts your IP down before anything is forwarded: an IPv4 address loses its final number (203.0.113.9 becomes 203.0.113.0), an IPv6 address keeps only its network prefix. That is enough to tell which country a visit came from and not enough to point back to you or your household. Our analytics provider (PostHog) receives and stores only the truncated form. Cloudflare CDN may transiently log full IPs for DDoS protection per their policy; we never access or retain those logs
Device / browser fingerprinting Not collected No fingerprinting scripts; no persistent device or user identifier

2.4 Anonymous product analytics (PostHog)

We use PostHog to understand which features people use, so we can improve RightBonds. It is configured to be anonymous and privacy-first. The PostHog library is self-hosted from our own server - no third-party script is loaded into your browser.

What is recorded - anonymous, non-identifying usage events only: which page was viewed, that a search or filter was used (and the bond-related terms typed), that a bond detail or platform link was opened, aggregate portfolio counts (whether the statement was CDSL or NSDL, and how many bonds and issuers it contained), and the country a visit came from, worked out from the truncated IP described in the table above.

Heatmaps - we also collect anonymous heatmap data: where on a page people click, where the mouse pointer moves (sampled, not a continuous trail), clicks that produced no visible response, and how far down the page people scroll. All of it is stored as plain coordinates on the page. It tells us which parts of a page get used and which get ignored. It is not tied to any identifier, it records only the position of a click or pointer and never what was clicked, typed or shown, and it is not a recording of your screen or your session.

What is never recorded - your full IP address (our edge truncates it before the data is forwarded, so neither we nor PostHog ever hold the complete address), any cookie or persistent identifier (the session id lives in memory and is gone when you close the tab), your name or email, your portfolio value, and your individual holdings, units or ISIN codes. Autocapture and session replay are switched off, so beyond the anonymous click, pointer and scroll positions described above we never record keystrokes, form contents or your screen.

In short: we can see that a feature was used and roughly where in the world it was used, never who used it or what they hold.

3. Third-party libraries and vendor dependencies

To protect user privacy, all JavaScript libraries used in the Portfolio feature are self-hosted on our servers. We do not load any scripts from external CDNs during the portfolio session, eliminating the possibility of a CDN operator logging your IP address while you analyse your holdings.

Library Version Purpose Hosted
Chart.js 4.5.1 Portfolio charts and graphs Self-hosted
SheetJS (xlsx) 0.18.5 Parse NSDL .xls and CDSL .xlsx / .csv files Self-hosted

Both libraries have been reviewed: neither version contains telemetry, outbound network calls, or data collection of any kind. SheetJS 0.18.5 is the final open-source release and performs all spreadsheet parsing synchronously in memory without any network activity.

What "self-hosted" means for you: When you open the portfolio page, your browser downloads Chart.js and SheetJS from rightbonds.com/vendor/ - our own domain. No request is made to cdn.jsdelivr.net, cdnjs.cloudflare.com, Google Fonts, or any other external service.

4. How your portfolio data is stored

When you upload a holdings statement, the following data is parsed from the file and stored in your browser's localStorage:

localStorage is a browser-native storage mechanism. It is:

Deleting your data

To remove all portfolio data:

5. Cookies & local storage

RightBonds sets no cookies. Our analytics runs in-memory only (persistence: 'memory') - no cookie, no device identifier, nothing written to your device. There is no advertising or third-party tracking cookie anywhere on the site, which is why you see no cookie banner.

The site uses your browser's localStorage for functional preferences you set yourself - theme choice, wishlist, saved filters, and the portfolio data described in section 4. This data stays on your device, is never transmitted, and can be cleared at any time via Clear All or your browser's "Clear site data".

Our host, Cloudflare, may set a strictly-necessary security cookie (such as __cf_bm for bot protection) as part of serving the site. It is essential-only, not used for tracking by RightBonds, and is covered by Cloudflare's Privacy Policy.

6. Hosting and infrastructure

RightBonds is hosted on Cloudflare Workers. Cloudflare operates as a CDN and DDoS protection layer. When you visit RightBonds, your request is handled by Cloudflare's edge network. Cloudflare may process your IP address and basic HTTP headers as part of their infrastructure service. This processing is governed by Cloudflare's Privacy Policy.

RightBonds does not have access to, and does not retain, any logs from Cloudflare's infrastructure. We run no session recording and no A/B testing. The anonymous heatmaps described in section 2.4 are the only behavioural analytics we collect.

Analytics events are sent to our own domain at /ph/ and forwarded from there to PostHog. This is a transport detail, not extra collection: the data is exactly what section 2.4 describes, and our edge truncates your IP address before forwarding, so PostHog receives a country-level prefix and never the full address.

The daily scraper runs on an automated CI/CD pipeline. It accesses only public bond platform APIs and writes a static JSON file to the repository. No user data is processed in this pipeline.

7. Referral links

Some bond listings on RightBonds include referral links to investment platforms (GoldenPi, Jiraaf, GripInvest, WintWealth, BondScanner). These links contain referral codes appended as URL parameters (e.g., ?ref=RIGHTBONDS). If you click a referral link and subsequently register on a partner platform, RightBonds may receive a referral commission from that platform.

Referral links are only used when you do not have portfolio data loaded. When portfolio data is present, bond links navigate directly to the specific bond's detail page on the respective platform - without any referral code - so you can quickly verify your holdings.

Clicking any external link will share your IP address and browser information with the destination platform, governed by that platform's own privacy policy.

8. Children's privacy

RightBonds is intended for adult investors. We do not knowingly collect personal information from individuals under 18 years of age. If you wish to delete any locally stored data, use the Clear All button on the Portfolio page or clear site data from your browser settings.

9. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For material changes, we will post a notice on the RightBonds homepage.

10. Contact

If you have questions about this Privacy Policy or how RightBonds handles data: