Privacy Policy

Last updated: June 2026

What we collect

When you create a PolyPulse account we collect your email address (used for authentication and account recovery) and, optionally, a phone number (used for account verification and security).

We store your alert and auto-trade preferences so we can deliver the service you signed up for. If you enable automated trading, we also store your exchange API credentials and/or connected wallet — encrypted at rest (see “Auto-trading” below).

How we use your data

Your data is used solely to operate PolyPulse:

  • Authenticate you and manage your account
  • Deliver whale-trade alerts through the channels you enable (Telegram and push notifications)
  • Execute the automated trades you explicitly configure on your connected exchange
  • Process payments via Stripe (we never see or store your card number)

We do not sell, rent, or share your personal information with third parties for marketing purposes. Ever.

Alerts

Whale-trade alerts are delivered via Telegram and browser / mobile push notifications, based on the channels you choose to enable. You control which alerts you receive and can disable them at any time in your account settings.

Auto-trading & exchange credentials

Automated trading is strictly opt-in. If you connect an exchange (e.g. Kalshi) or a wallet, your API credentials are encrypted at rest using AES-256-GCM and are used only to place the trades you have configured.

You can disable auto-trading and remove your stored credentials at any time. We never expose your keys to the browser or any third party.

Account security

Two-factor authentication (via an authenticator app) is available, and is required for any account with connected exchange credentials or a wallet. This protects the parts of your account that can move real money.

Data storage & security

Your data is stored in Supabase (PostgreSQL) with row-level security policies. All connections are encrypted via TLS, and sensitive secrets (exchange keys) are encrypted at rest. We retain whale-trade data for historical display; account data is deleted when you delete your account.

Third-party services

We use the following services to operate PolyPulse:

  • Supabase — authentication and database
  • Stripe — payment processing
  • Vercel — hosting
  • Telegram — alert delivery
  • Resend — transactional email
  • Privy — wallet connection (optional)
  • OpenAI — the in-app “Pulse” assistant

Each operates under their own privacy policies.

Contact

Questions about this policy? Email us at support@polypulse.app.