Privacy Policy
Last updated: January 2026 · Effective: January 2026
This Privacy Policy explains how PolySharks.ai ("PolySharks", "we", "us") collects, uses, discloses, and protects your personal information when you use our website and services.
1. Information We Collect
We collect: (a) account information you provide (email, password hash, optional name) when you sign up; (b) subscription & billing metadata via Stripe (we never store card numbers — Stripe does); (c) technical data automatically (IP address, browser, device, pages viewed, referral source); (d) public on-chain data from Polymarket (wallet addresses, trades) and public Kalshi market data. We do not collect special-category data (health, biometrics).
2. How We Use Information
To operate the PolySharks service (deliver dashboard content, process subscriptions, send transactional emails, prevent abuse), to improve the product (aggregate analytics, A/B tests), and to comply with legal obligations. We use a lawful basis of contract performance for paid features and legitimate interest for product analytics.
3. Cookies & Tracking
We use strictly-necessary cookies for session auth and cart state. We use optional analytics cookies (page views, referral) only after your explicit consent via the cookie banner. You can withdraw consent at any time in the cookie banner at the bottom of every page. See /cookie-policy for a full list.
4. Sharing Your Data
We share data only with: Supabase (database + auth hosting), Stripe (payment processing), GoDaddy / nodemailer (outbound email), Vercel / Emergent (application hosting). We never sell personal data. We disclose data in response to lawful legal process.
5. Data Retention
Account data is retained while your account is active and for 90 days after cancellation, then permanently deleted unless required by tax or fraud-prevention laws (7-year max). Aggregated usage metrics may be retained indefinitely in anonymized form.
6. Your Rights (GDPR / CCPA / UK GDPR)
You may (a) request a copy of your data, (b) correct it, (c) delete it, (d) port it, (e) object to processing, (f) withdraw consent. Email [email protected]. California residents have the right to know what we collect and to opt-out of data sales (we do not sell). We respond within 30 days.
7. International Transfers
Your data is stored in US-based servers (Supabase, Stripe, Vercel). If you access from outside the US we rely on Standard Contractual Clauses for any transfer.
8. Children
PolySharks is not directed to persons under 18. If we learn we have collected data from someone under 18 we will delete it immediately. Contact [email protected] to report.
9. Security
We use HTTPS/TLS, bcrypt-style password hashing via Supabase, Stripe-hosted checkout, row-level-security on the database, and restricted admin access. No system is 100% secure — report suspected incidents to [email protected].
10. Changes to This Policy
We will notify you by email and in-app banner at least 30 days before material changes take effect. The "Last updated" date below always reflects the current version.
11. Contact
PolySharks — [email protected]. Postal contact available on request at [email protected].