Market PrediktAI market edge
Start for €1
← All legal documents

Privacy policy

What data we hold, why, for how long, and what rights you have.

Last updated: August 10, 2026

⚠️ This document is incomplete: the operating legal entity is not yet registered, and the missing details appear in plain text below. It is not binding on anyone as it stands.

Data controller

⟨TODO : registered company name⟩, ⟨TODO : registered address⟩. Contact: ⟨TODO : data protection contact⟩.

No data protection officer is appointed: our activity does not fall within the cases where appointment is mandatory. That may change and will be stated here.

What we collect

We collect what the service needs in order to work, and nothing that exists to profile you for advertising.

  • Account: email address, name if you provide one, profile picture if you sign in with Google.
  • Preferences: language, display theme, preferred currency, country.
  • Subscription: plan, status, periods, invoices, and your customer id at the payment provider.
  • Usage: per-feature quota counters, alerts you create, notifications, screenshots you request.
  • Polymarket wallet: only if you declare it yourself. The field is optional and exists to attribute a verified result to your account.
  • Security: an audit log of administrative actions, sign-in timestamps, rate-limit counters.

What we do not collect

No card details. Entry happens at the payment provider, inside their own compliance perimeter.

No advertising trackers, no third-party social widgets, no sale of data. We run no audience analytics today.

Legal bases

Each processing activity rests on a distinct basis.

  • Performance of the contract: account, subscription, delivery of analyses, invoicing.
  • Legal obligation: retention of accounting and tax records.
  • Legitimate interest: service security, fraud prevention, rate limiting, audit log.
  • Consent: the optional declaration of your Polymarket wallet, withdrawable at any time.

Recipients and processors

We use the following providers, each for a specific purpose. This list is kept current and describes what the code actually calls.

  • Payment provider — Stripe or Paddle depending on configuration: payment, invoicing, subscription management.
  • Google — only if you choose Google sign-in: authentication.
  • Email delivery service — transactional email: sign-in links, billing notifications.
  • Anthropic — generation of market analyses. The markets analysed are public; we do not pass your identity.
  • S3-compatible object storage — storage of screenshots you generate.
  • Hosting and database — ⟨TODO : hosting provider⟩.

Transfers outside the European Union

Some of these providers are established outside the European Union, notably in the United States and the United Kingdom. Those transfers rely on the European Commission's standard contractual clauses or on an adequacy decision, depending on the provider.

Retention periods

  • Account and preferences: for the life of the account, then deleted within thirty days of closure.
  • Accounting records and invoices: ten years, the statutory retention period, regardless of account closure.
  • Audit log and security data: twelve months.
  • Screenshots: until you delete them, or on account closure.
  • Sessions: no longer than the session's validity, then deleted.

Your rights

You have rights of access, rectification, erasure, restriction, objection and portability, and the right to withdraw consent where consent is the basis.

Exercise them by writing to ⟨TODO : data protection contact⟩. We reply within one month.

You may also lodge a complaint with the supervisory authority of your country of residence.

Automated decisions

Our analyses are generated automatically, but they produce no legal effect concerning you and are not automated decision-making under the GDPR: they decide nothing, they inform you.