Privacy Policy
Last updated: September 26, 2026
1. About This Policy
This policy explains what information Polywhaler ("we", "us") collects, how we use it, and the choices you have. It covers polywhaler.com, Orca at orca.polywhaler.com, the Orca iOS app, and the Polywhaler API (together, the "Service").
2. Information You Give Us
- Account details: your email address and password, or the name, email, and profile picture shared by Google or Apple when you sign in with them. If you use Apple's "Hide My Email", we only receive the relay address. Passwords are hashed with bcrypt and never stored in plain text.
- Profile: an optional display name and avatar.
- Payments: when you subscribe, your payment is handled by Stripe, PayPal, or Apple. We receive your subscription status and billing records, not your full card number. If you pay with crypto, we record the transaction hash and sending wallet address to verify the payment on the blockchain.
- Watchlists and settings: the wallets, markets, and events you follow, your alert rules, and your notification preferences.
- Notification channels: if you connect them, your Telegram chat ID, a Discord or webhook URL you provide, or a push notification token for your device.
- Orca portfolios: your paper portfolios, deposits, copied wallets, and trade history. For live trading, your public wallet address and the trading API credentials you connect for Polymarket or Kalshi. These credentials are encrypted at rest and used only to place and manage the orders your Orca settings call for. We never have access to your wallet's private keys.
- API access: API keys you create and a log of your API usage.
- Messages to us: anything you send when you contact support.
3. Information We Collect Automatically
- Usage analytics: we use Vercel Web Analytics, which counts page views without cookies and without storing your IP address, and Vercel Speed Insights, which measures page performance. We also record a few product events, such as a completed signup or checkout, along with the campaign tags (UTM parameters) of the link that brought you to the site.
- Advertising measurement: see section 6.
- Security data: when someone creates an account, we record the email address and IP address of the attempt to prevent automated abuse.
- Activity in the Service: for example, when you last viewed a trader's profile, so we can show what is new since your last visit.
4. Public Market Data About Traders
Polywhaler analyzes public trading activity. Polymarket trades are recorded on a public blockchain, and Polymarket and Kalshi publish the usernames and avatars that traders choose to display. We collect this public data, including wallet addresses and trading history, and show it with our own analysis, such as whale rankings and insider risk scores. These scores are algorithmic estimates based on trading patterns, not findings about any person. If you have a question about data shown for a wallet or profile, contact us at info@polywhaler.com.
5. How We Use Information
- To provide the Service, including your account, alerts, portfolios, and API access
- To process subscriptions and payments
- To send email about your account, such as verification, password resets, billing notices, and the alerts you set up
- To send product emails, such as whale digests and announcements. Each one has an unsubscribe link
- To measure which ads and campaigns bring people to Polywhaler
- To keep the Service secure, prevent fraud and abuse, and fix problems
- To understand how the Service is used and improve it
- To comply with legal obligations
Some features use AI models from Google and OpenAI to analyze public market and trade data. We do not include your account information in these requests.
If you are in the European Economic Area or the UK, we rely on these legal bases: to perform our contract with you (running your account and subscription), our legitimate interests (security, analytics, and improving the Service), your consent where the law requires it, and legal obligations (such as keeping payment records).
6. Advertising Measurement
We advertise in ChatGPT and use OpenAI's measurement pixel on our website to learn whether those ads lead to signups. When you visit, the pixel can send OpenAI the page you are viewing, information about your browser and device, your IP address, and events such as a completed registration. It may also detect contact details on the page, such as an email address, and send them in hashed form, so OpenAI can match the visit to a ChatGPT ad you saw or clicked. The pixel sets the cookies listed in section 7.
OpenAI handles this data under its own privacy policy. We do not sell your personal information. Some US state laws call sharing data for ad measurement "sharing" for targeted advertising. You can limit it by blocking or clearing cookies in your browser or by using a tracker blocker.
7. Cookies and Browser Storage
- Sign-in and security cookies (set by us): keep you signed in for up to 30 days and protect sign-in forms. These are required for the Service to work.
- Signup marker (set by us,
pw_new_signup): lasts 10 minutes after you create an account with Google, so the signup can be counted for ad measurement. - OpenAI pixel cookies:
__opprefnotes that you arrived from a ChatGPT ad and lasts 30 days.__obrefis a browser identifier that lasts 1 year. OpenAI's servers may also set short-lived security cookies on their own domains. - Browser storage: we keep some preferences, such as your theme, in your browser's local storage, and the campaign tags of your visit in session storage. If you connect a crypto wallet, the wallet connection libraries store its connection state in your browser.
Vercel Web Analytics does not use cookies. You can block or delete cookies in your browser settings. Blocking the sign-in cookies will sign you out.
8. Who We Share Information With
We share information with service providers only as needed to run the Service:
- Vercel: hosting, cookieless analytics, performance monitoring, and avatar storage
- Supabase: our database, hosted in the United States
- Stripe, PayPal, and Apple (via RevenueCat): payments and subscriptions
- Google and Apple: sign-in, if you choose them
- Resend: sending email
- OpenAI: advertising measurement (section 6)
- Telegram, Discord, and Expo: delivering alerts and push notifications to the channels you connect
- WalletConnect and Coinbase Wallet: connecting your wallet, if you choose them
- Polymarket and Kalshi: placing orders for Orca live trading, when you connect an account
Each provider handles data under its own privacy policy. We may also disclose information if required by law, to protect the rights and safety of our users or the Service, or as part of a merger or sale of the business.
9. How Long We Keep Information
We keep your account information for as long as you have an account. When you delete your account, we delete your profile, watchlists, alerts, portfolios, API keys, connected credentials, and notification settings. We keep a small amount of information where we have a reason to:
- Payment records, with your email removed, for accounting and legal purposes
- Records of signup attempts, to prevent abuse
Deleted data may remain in encrypted backups for a short time before it is overwritten.
10. Security
We use HTTPS for all traffic, hash passwords with bcrypt, and encrypt trading credentials at rest. No system is perfectly secure, so please use a strong, unique password and tell us right away if you suspect unauthorized access to your account.
11. Your Rights and Choices
- Delete your account: in the Orca iOS app under Settings, Delete account, or by emailing us.
- Update your profile: in your account settings.
- Stop product emails: use the unsubscribe link in any of them. We will still send essential account and billing email.
- Turn off alerts and push notifications: in your alert settings or your device settings.
Depending on where you live, you may also have the right to access, correct, delete, or receive a copy of your information, to object to or restrict how we use it, and to withdraw consent. To make a request, email info@polywhaler.com from the address on your account. We will respond within 30 days and will not treat you differently for using these rights. If you are in the EEA or the UK, you can also complain to your local data protection authority.
12. International Transfers
We store and process information in the United States. If you use the Service from another country, your information will be transferred to the United States, where data protection laws may differ from those where you live.
13. Children
The Service is not intended for anyone under 18, and we do not knowingly collect information from children. If you believe a child has given us information, contact us and we will delete it.
14. Changes to This Policy
We may update this policy from time to time. We will post changes on this page with a new date, and if a change is significant, we will also let you know by email or in the Service.
15. Contact
If you have any questions about this policy or your information, contact us at info@polywhaler.com.