PolyPilot

Legal

Privacy policy

How PolyPilot collects, stores and uses your personal data — and what you can ask us to do with it.

Last updated 14 August 2026

Who we are

PolyPilot is operated by PolyPilot Technologies Ltd. For anything in this policy, write to support@polypilot.online.

Operator note: add your ICO registration reference to lib/site-config.ts before launch. UK organisations processing personal data generally need to register with the Information Commissioner’s Office.

What we collect

  • Account data. Your email address, a bcrypt hash of your password (never the password itself), your referral code, and the code of whoever referred you.
  • Trading credentials. If you choose to connect a wallet, the private key you supply and your Polymarket account address. The key is encrypted with AES-256-GCM before it touches storage. See “Trading credentials” below.
  • Usage and execution data. Which signals you copied, passed on or had blocked, the amounts, and the outcome reported by the exchange.
  • Billing records. Plan, term, price in USD, the cryptocurrency used, and the payment reference. We never see or hold your wallet balance or card details.
  • Technical data. IP address and request metadata, used for rate limiting and abuse prevention.

Trading credentials

This deserves its own section because it is the most sensitive thing we hold.

  • Your signing key is encrypted with AES-256-GCM using a master key that exists only in our deployment environment, never in the database.
  • It is decrypted in memory at the moment an order is signed and is not retained afterwards. It is never written to a log and never returned to your browser.
  • Our staff cannot read it through any interface we operate. The admin console shows only whether a wallet is connected.
  • Deleting the connection from your dashboard erases the stored value immediately.

Why we process it

  • To perform our contract with you — running your account, showing signals, placing the orders you ask for, and taking payment.
  • Legitimate interests — preventing abuse, debugging failures, and keeping the service secure.
  • Legal obligation — retaining billing records for the period required by UK tax law.

Who we share it with

We do not sell personal data and we do not share it for advertising. We use a small number of processors to run the service:

  • Vercel — application hosting.
  • Turso / libSQL — database hosting.
  • A third-party cryptocurrency payment processor — handles checkout and settlement. It receives your email address and the invoice amount. We can name the provider on request.
  • hCaptcha — bot protection on sign-up and sign-in.
  • Vercel Analytics — counts page views and referrers so we know which pages are useful. It sets no cookies, does not fingerprint your device and does not follow you to other sites.
  • Polymarket — orders you instruct us to place are submitted to their exchange, under your own account.

Cookies

We set one cookie: __pp_session, which keeps you signed in. It is httpOnly, same-site, and secure in production.

There are no advertising or tracking cookies on this site. We do measure page views using Vercel Analytics, but it is cookieless — it stores nothing on your device and builds no cross-site profile of you. That is why you are not being asked to dismiss a consent banner: under PECR, consent is required for storing or accessing information on your device, and this does neither.

How long we keep it

  • Account and execution history: while your account is open.
  • Billing records: six years, as required for UK tax purposes.
  • Trading credentials: until you disconnect them, or your account is closed.
  • Rate-limiting data: minutes, in memory only.

Your rights

Under UK GDPR you can ask us for a copy of your data, ask us to correct it, ask us to delete it, object to processing, or ask for it in a portable format. Email support@polypilot.online and we will respond within one month.

If you are unhappy with how we have handled your data you can complain to the Information Commissioner’s Office at ico.org.uk.

Changes

If we change this policy materially we will email account holders before the change takes effect. The date at the top always reflects the current version.