Privacy Policy
Last updated August 8, 2026. This describes what PolyHawk collects and why. Have counsel review it against GDPR, CCPA, and your other obligations.
What we collect
- Account data — email address, display name, and profile photo if you sign in with Google. Held in Firebase Authentication.
- Usage data — the analyses you run, your paper-trading positions, the wallets you track, and your settings. Held in Firestore, keyed to your account.
- Billing data — handled by Whop. We store your Whop membership ID and subscription status. We never see or store your card number.
- Trading credentials — only if you choose to enable Copy Trading. See below.
Trading credentials
If you connect a wallet for Copy Trading, your private key and API key are encrypted with AES-256-GCM on our server before they are written to storage. They are never returned to the browser, never logged, and are decrypted only inside the process that places your orders. Disconnecting deletes them.
A private key grants full control of the funds in that wallet. Only connect a wallet funded with an amount you are willing to lose entirely, and revoke access when you are done.
What we send to third parties
- OpenAI — market data and your questions to the AI Coach are sent to OpenAI to generate a response. Do not paste secrets into the Coach.
- Whop — your email, to process payments and match your membership to your account.
- Google Firebase — our hosting, authentication, and database provider.
- Polymarket — we read their public APIs. We do not send them your personal data.
We do not sell your personal data.
Cookies
We set one essential cookie, __session, which keeps you signed in. It is httpOnly and cannot be read by JavaScript. We do not use advertising or cross-site tracking cookies.
Retention
Account and usage data is kept while your account is open. Delete your account and we remove your personal data within 30 days, except records we must keep for tax and accounting purposes.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. Email support@polyhawk.io and we will respond within 30 days.
Security
Data is encrypted in transit with TLS and at rest by our providers. Access to production systems is restricted. No system is perfectly secure; if a breach affects you we will notify you as required by law.
Children
The service is not for anyone under 18. We do not knowingly collect data from children.