Polyterminus
← Home·Legal

Privacy Policy

Effective July 28, 2026

This Privacy Policy explains how ARCADA LLC ("we", "Polyterminus") collects, uses, and protects personal data when you use polyterminus.com and app.polyterminus.com (together, the "Service").

1. Who we are

Data controller: ARCADA LLC, Delaware, United States. Contact: privacy@polyterminus.com.

2. What we collect

  • Account data: email address, display name, authentication provider (email link, Google, wallet address).
  • Trading configuration: Polymarket signer key (encrypted at rest), preferences, alert rules, watchlists.
  • Usage data: pages viewed, features used, latency and error events (via Sentry).
  • AI conversations: the prompts you send to AI features are transmitted to the upstream provider (self-hosted rotator, or OpenRouter, Anthropic, Google — depending on cascade state). We retain them only for the shortest time needed to serve the request and to compute quotas.
  • Payment data: for paid plans, Stripe collects and stores card details directly — we only see a customer identifier.

3. What we do NOT collect

  • Your Polymarket funds — we never touch them.
  • Third-party accounts you did not explicitly link.
  • Government IDs, tax information, or KYC documents (Polymarket handles KYC on its side).

4. Why we process data (legal bases)

  • Contract performance: to run the Service you signed up for.
  • Legitimate interests: to secure the Service, detect abuse, improve product.
  • Consent: for optional cookies, marketing emails, telemetry-share.
  • Legal obligation: to comply with tax, accounting, and law-enforcement requests where legally binding.

5. Where data lives

All personal data is stored in Google Cloud Platform, project polyterminus-eu, region europe-west6 (Zurich, Switzerland). Firestore holds account records, preferences, and encrypted credentials. Secret Manager holds our encryption keys and provider credentials. Cloud Run runs the API. No user data leaves the EU except when explicitly sent to a third-party AI provider you\'ve chosen (BYO keys) or the shared house AI cascade you\'ve consented to use.

6. Data-processor partners

  • Google Cloud — infrastructure hosting (Firestore, Cloud Run, Secret Manager). EU-region processing.
  • Sentry — error and performance monitoring. US-hosted; EU personal data pseudonymised before send.
  • Stripe — payment processing for paid plans. Their own privacy policy applies.
  • OpenRouter / Anthropic / Google Gemini — AI providers (only when you use AI features and depending on cascade routing).

7. Retention

Account and trading configuration data: for the life of your account plus 90 days after deletion (for backup rotation). Usage / telemetry: 90 days rolling. AI prompt logs: 30 days. Payment records: 7 years (Delaware tax and accounting requirements).

8. Your rights (GDPR, CCPA, and similar)

You have the right to: (a) access personal data we hold about you; (b) correct inaccurate data; (c) request deletion (right to be forgotten); (d) restrict or object to certain processing; (e) receive an export (data portability); (f) withdraw consent for optional processing; (g) lodge a complaint with your data-protection authority. Email privacy@polyterminus.com. We respond within 30 days.

9. Cookies and telemetry

The marketing site uses no third-party analytics tracking cookies by default. The app uses a small number of first-party cookies for authentication, preferences, and CSRF protection. Errors are collected via Sentry when opted in. We do not sell personal data. We do not run advertising retargeting.

10. Security

Credentials at rest are encrypted with AES-256-GCM using keys stored in Secret Manager. All transport uses TLS 1.2+. Access to production systems is limited to the founder and requires 2FA. We follow the principle of least privilege for internal roles.

11. Children

The Service is not for anyone under 18. We do not knowingly collect data from minors. Contact us if you believe a minor has provided us with data.

12. Changes to this policy

Material changes will be announced by email and via in-app notice at least 14 days before taking effect.

13. Contact

Data protection inquiries: privacy@polyterminus.com. General: hello@polyterminus.com.