Legal
Privacy Policy
A precise account of what we collect and why. The short version: browsing is anonymous, and the only personal data we hold is what you give us to run alerts and your watchlist.
Effective July 29, 2026
1.Browsing without an account
Market data, order books, charts, cross-venue comparison and hedging tools are all available with no account and no sign-in. We do not require you to identify yourself to use them.
2.What we collect
If you create an account
- Email address — the identifier for your account and the destination for alerts.
- Watchlist entries — the market IDs you save, plus the probability at the moment you saved each one so we can show the change since.
- Alert rules — the market, venue, condition and threshold you configured, when each last fired, and an optional webhook URL you supply.
- Session record — a random token and its expiry, so you stay signed in.
If you contact us
The name, email address and message you submit, retained so we can reply and keep a record of the correspondence.
Server logs
Our hosting provider records ordinary request logs (IP address, user agent, timestamp, path) for security and reliability. These are not linked to your account by us.
3.What we do not collect
We do not run third-party advertising, behavioural tracking or analytics pixels. We do not build advertising profiles, and we do not collect payment details — the service does not take payments. We never receive your venue credentials, wallet keys, positions or balances; the terminal only ever reads public market data.
4.Cookies
We use exactly one cookie:
preduck_session— a signed,HttpOnly,SameSite=Laxsession token set after you sign in, expiring after 30 days. It is strictly necessary to keep you authenticated and carries no tracking data.
Your theme preference (system, light or dark) is stored in your browser's localStorage. It never leaves your device and is not sent to us.
5.Why we process it
- To provide the service — authenticating you, storing your watchlist, evaluating and delivering alerts. Legal basis: performance of a contract.
- To keep the service secure and working — abuse prevention, debugging, capacity planning. Legal basis: legitimate interests.
- To answer your messages. Legal basis: legitimate interests.
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
6.Processors we rely on
- Supabase — hosted Postgres storing profiles, sessions, watchlists and alert rules.
- Resend — delivery of sign-in links and alert emails, when email delivery is configured.
- Our hosting provider — runs the application and produces the request logs described above.
Each processes data on our instructions. Where processing involves an international transfer, it is carried out under appropriate safeguards such as Standard Contractual Clauses.
Requests the terminal makes to Polymarket, Kalshi and Hyperliquid are made server-side for market listings, so those venues do not receive your IP address for that traffic. Live order book streams for Polymarket and Hyperliquid connect directly from your browser to those venues, which necessarily exposes your IP address to them under their own privacy policies. Clicking a venue link takes you to their site, governed by their policy.
7.Retention
- Account, watchlist and alert data: until you delete your account.
- Sessions: 30 days, then purged automatically.
- Sign-in links: single use, expiring after 15 minutes.
- Contact correspondence: up to 24 months.
- Server logs: per our hosting provider's retention schedule.
8.Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to our processing of your data, to receive a portable copy, and to complain to your data protection authority. Under U.S. state privacy laws you may have rights to know, delete, correct, and to opt out of sale or sharing — we do neither.
Exercise any of these by writing to contact@preduck.com. We will respond within the period required by applicable law, and we will not discriminate against you for exercising a right.
9.Security
Session cookies are HMAC-signed, HttpOnly, and marked Secure over HTTPS. Database access is restricted to the server; row-level security is enabled and default-deny. No system is perfectly secure, and we cannot guarantee absolute security — but we do not store passwords, payment details or venue credentials, which materially limits what a breach could expose.
10.Children
The service is not directed at anyone under 18, and we do not knowingly collect their data. If you believe a minor has provided us data, contact us and we will delete it.
11.Changes
We may update this policy; material changes will be reflected in the effective date above.
12.Contact
Preduck Labs Ltd.
[Registered address — replace before publishing]
contact@preduck.com
See also our Terms of Service and Risk Disclaimer.