Privacy Policy
Effective date: 25 July 2026
Who is responsible
The data controller for personal data processed through polycat.io is PolyCat, a service established and operated within the European Union ("we"). Contact: support@polycat.io. This policy explains what we collect, why, and your rights under the EU General Data Protection Regulation (GDPR).
What we collect
Account data: email address, username, hashed password (or Google account identifier if you sign in with Google).
Service data: your Polymarket account address, the wallet addresses you choose to copy, your configuration (bet amounts, limits, categories), and records of trades placed by the Service for you.
Wallet credentials: the private key you provide is encrypted with AWS Key Management Service before storage and is used solely to sign Polymarket orders. It is never displayed, exported, or used for any other purpose.
Payment data: payments are processed by Stripe. We never see or store your card number; we store your subscription status and Stripe customer reference.
Technical data: IP address and basic request logs for security and rate limiting.
Why we process it (legal bases)
To provide the Service you signed up for, including placing trades you configured (performance of contract, Art. 6(1)(b) GDPR); to secure the Service and prevent abuse (legitimate interest, Art. 6(1)(f)); to comply with bookkeeping and tax obligations (legal obligation, Art. 6(1)(c)); and, where you opt in, to send product emails (consent, Art. 6(1)(a), withdrawable anytime in Settings → Notifications).
Who processes it for us
We use established processors to run the Service: Supabase (database and authentication), Amazon Web Services (key management, EU region), Stripe (payments), Hostinger (website hosting), Railway (trade engine hosting), and Google (optional sign-in). Each processes data on our instructions under data-processing agreements. Some providers may process data outside the EU/EEA under appropriate safeguards (EU standard contractual clauses / adequacy decisions).
How long we keep it
Account and service data: for as long as your account exists. Wallet credentials: until you disconnect them or delete your account, at which point they are deleted. Trade and payment records: up to 7 years where required by applicable EU bookkeeping and tax law. Security logs: up to 12 months.
Your rights
You have the right to access, rectify, and erase your personal data; to restrict or object to processing; and to data portability. You can exercise most of these directly (Settings, Connect page) or by emailing support@polycat.io. Account deletion removes your personal data except records we must retain by law. You also have the right to lodge a complaint with your national data protection authority.
Cookies
The Service uses only strictly necessary storage (login session in your browser's local storage). We do not use advertising cookies or third-party trackers.
Changes
We will update this policy as the Service evolves and announce material changes in the Service. Questions: info@polycat.io.