← Measurement Finance

Privacy Notice

Version 1.1 · Last updated 5 September 2026 · Effective 5 September 2026

This notice explains what personal data we collect when you use Measurement Finance, why we collect it, who receives it, how long we keep it, and the rights you have over it.

Sections 1 to 13 apply to everyone. If you are in the EEA or the United Kingdom, they are our notice under Articles 13 and 14 of the UK and EU General Data Protection Regulation. If you are in the United States, read them together with the US state privacy rights annex in section 14.

At a glance

  1. Who we are
  2. Data we collect
  3. How and why we use it
  4. Who we share it with
  5. Blockchain data
  6. International transfers
  7. Automated decision-making
  8. How long we keep it
  9. How we protect it
  10. Your rights
  11. Cookies
  12. Children
  13. Changes
  14. US state rights

1. Who we are and how to contact us

This notice is issued by Measurement Finance ("we", "us", "our"). We are the controller of the personal data described in this notice.

You can reach us about anything in this notice, and exercise any of the rights described in section 10, at privacy@measurement.finance.

Providing the data requested when you sign in, and when you fund or instruct a Position, is necessary for us to enter into and perform our agreement with you. If you do not provide it, we cannot open an account for you or act on your instructions.

2. Personal data we collect about you

2.1 Data you provide to us

2.2 Data generated by your use of the product

2.3 Data we receive from third parties

We do not seek, and do not knowingly collect, special category data within the meaning of Article 9 of the GDPR.

3. How and why we use your personal data

We process personal data only for the purposes set out below. Each row states the lawful basis on which we rely for that purpose. Where we rely on legitimate interests, the interest is identified.

Purposes of processing, the data used, and the lawful basis for each
PurposeData usedLawful basis
Creating and administering your account and providing the product to you Sign-in data, account identifier, wallet addresses Performance of a contract (Art. 6(1)(b))
Placing, adjusting and closing the orders that constitute your Position, and crediting and returning funds Wallet and custody data, transaction and Position data Performance of a contract (Art. 6(1)(b))
Maintaining accurate balances, Positions and records, and reconciling them against the execution venue and the blockchain Transaction and Position data, wallet addresses Performance of a contract (Art. 6(1)(b))
Detecting and preventing fraud, abuse and unauthorised access, and protecting funds held on the platform Technical data, transaction and Position data, account identifier Legitimate interests (Art. 6(1)(f)) — protecting our users, their funds and our platform from financial crime and abuse
Measuring how the product is used, diagnosing faults and improving the product Usage data, technical data, account identifier Consent for the storing of and access to information on your device (see section 11), and legitimate interests (Art. 6(1)(f)) for the subsequent analysis — understanding and improving how our product is used
Responding to your enquiries and providing support The content of your message, account identifier, and (for in-product Feedback) the selected scenario, allowlisted technical context, and the sign-in wallet address recorded on a sent report Performance of a contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)) — responding to people who contact us
Operating the Trend Requests board Content you submit, display name, account identifier Performance of a contract (Art. 6(1)(b))
Recording your request to be notified when a Basket becomes available Account identifier, the Basket and Direction requested Consent (Art. 6(1)(a)), given by activating the notify control
Complying with our legal, tax, accounting and record-keeping obligations, and responding to lawful requests from competent authorities Account, transaction and Position data Legal obligation (Art. 6(1)(c))
Establishing, exercising or defending legal claims Any of the above, so far as relevant to the claim Legitimate interests (Art. 6(1)(f)) — protecting our legal position

Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that our interests are not overridden by your interests, rights and freedoms. You may request a summary of that assessment at any time.

4. Who we share your personal data with

We disclose personal data to the recipients identified below, each of which processes it for the purposes described. We do not sell personal data and we do not share it for cross-context behavioural advertising.

Recipients of personal data, their role, and the categories disclosed to each
RecipientRoleData disclosed
Privy Authentication, wallet creation and key management, and orchestration of card funding Email address or wallet address, account identifier, wallet addresses, funding amounts
Polymarket The execution venue on which your orders are placed, and the bridge that converts incoming funds. Market data is also requested directly by your browser, which discloses your IP address to Polymarket. Wallet addresses, orders and fills, deposit and settlement transactions, IP address
Card and on-ramp providers engaged through Privy, including MoonPay, Meld and Coinbase depending on the route offered to you Converting card or bank payments into the asset used to fund your Position, and performing their own identity and anti-money-laundering checks as independent controllers The data you provide to them directly, and the destination address
DeepSeek Generating the Feedback support conversation and categorising feedback A bounded model context made from a rolling summary, recent saved Feedback turns and the current message; no allowlisted technical context, account, wallet, financial, authentication or secret data
GitHub Keeping the private issue created from a submitted Feedback report A bounded summary or excerpt, deterministic classification, scenario, allowlisted technical context and a conversation reference; not the full transcript, Privy DID, bearer token, wallet or financial data
Google (Google Analytics) Product usage measurement Usage and technical data and a pseudonymous account identifier, subject to the exclusions in section 11
Cloudflare Delivery of images and static assets IP address and request metadata
Railway Hosting of our application and database, as our processor All data we hold

We do not carry out identity verification or "know your customer" checks ourselves, and we do not collect identity documents. Where such checks are performed, they are performed by the card and on-ramp providers named above, acting as independent controllers under their own privacy notices and using data you provide directly to them.

We also disclose personal data where we are required to do so by law or by a competent authority, and to our professional advisers where necessary for the purposes in section 3. If our business is reorganised, sold or merged, personal data may be transferred to the acquiring entity, and this notice will continue to apply to it until replaced.

5. Blockchain data

Funding a Position, placing an order, and withdrawing each result in transactions being recorded on a public blockchain. Those records are public, permanent and outside our control. We cannot amend, delete or restrict them, and neither can you.

Wallet addresses and transaction records may be capable of being linked to you, by us or by third parties who analyse blockchain data. If you exercise your right to erasure, we can erase the personal data held in our own systems; we cannot erase data written to a public blockchain, and the right does not extend to it.

6. International transfers

We and our service providers operate in several countries, including the United States. Your personal data may therefore be transferred to, stored in and processed outside the EEA and the United Kingdom.

Where we transfer personal data outside the EEA or the United Kingdom, we rely on one of the following safeguards: an adequacy decision of the European Commission or UK adequacy regulations covering the destination; the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the transfer originates in the United Kingdom; or another mechanism permitted under Chapter V of the GDPR. Where we rely on the Standard Contractual Clauses we also assess whether supplementary measures are required for the destination. You may request a copy of the safeguards we have put in place.

7. Automated decision-making and profiling

We use automated processing in two places. Only one of them involves a decision about you.

The AI that maintains a Basket operates on markets, not on people. It selects and reweights prediction markets using market data. It does not use your personal data, does not profile you, and produces no decision concerning you. Every user holding that Direction is affected identically.

Automated controls may restrict activity on an account. We operate automated rules to detect fraud, abuse and anomalous movement of funds, which may delay a transaction or restrict an account. Where such a decision is based solely on automated processing and produces legal effects concerning you or similarly significantly affects you, you have the right to obtain human intervention, to express your point of view and to contest the decision. Write to privacy@measurement.finance.

8. How long we keep your personal data

We retain personal data only for as long as necessary for the purposes set out in section 3. Where a retention period is prescribed by law, we apply that period. Otherwise we determine the period by reference to the volume, nature and sensitivity of the data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it, and whether those purposes can be achieved by other means.

Retention period by category of data
CategoryRetention period
Account and sign-in recordsFor the duration of your account, and for a further period after closure for as long as a claim may still arise or the records must be kept by law
Transaction, order and Position recordsFor the period required by applicable tax, accounting and financial record-keeping law — generally not less than five years from the date of the transaction
Support correspondenceThree years from the last communication
In-product Feedback reportsAccepted Feedback turns, completed assistant replies, model memory, hashed rate records, and the account identifier and sign-in wallet address recorded on a sent report are retained indefinitely in the dedicated private database unless an authorised operator completes a verified owner-erasure request or a legal requirement applies. There is no automatic deletion. DeepSeek receives bounded context only to provide the requested response and classification, subject to its current API retention terms. A separate private GitHub issue retains only the bounded summary/reference, is not automatically deleted, and is redacted for a verified erasure request.
Analytics data14 months, after which it is deleted by our analytics provider
Trend Requests board contentFor as long as the board carries it, or until you ask us to remove your contribution
Blockchain recordsPermanent and outside our control — see section 5

For Feedback, verified erasure is operator-assisted rather than self-service: we verify the requester, delete that owner's dedicated-database conversations, model memory and associated rate records, and redact matching GitHub summaries before the database deletion. The current staging Feedback database uses its attached service volume only. It has no scheduled backup or verified volume-loss restore coverage, so staging records must not be treated as recoverable. Production Feedback is not enabled. At the end of another applicable period we delete the data or irreversibly anonymise it, in which case we may continue to use the anonymised data indefinitely.

9. How we protect your personal data

We maintain technical and organisational measures appropriate to the risk. Access to production systems and to the data they hold is limited to personnel who require it. Signing authority over the wallets holding user funds is separated so that no single compromised component can move funds unilaterally, and the movement of value is restricted to destinations you control. You may export the private key of your wallet, or revoke our signing permission over it, at any time from the account menu.

No system can be guaranteed secure. Where a personal data breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay.

10. Your rights

Subject to the conditions and exemptions in applicable law, you have the right to:

To exercise any of these rights, write to privacy@measurement.finance. We may ask you to verify your identity before we act, in order to ensure we do not disclose personal data to the wrong person. We respond within one month of receipt, and will tell you if we need to extend that period. Exercising your rights is free of charge, and we will not treat you detrimentally for doing so. Where a request is manifestly unfounded or excessive we may charge a reasonable fee or decline to act, and we will explain why.

You also have the right to lodge a complaint with a supervisory authority. In the United Kingdom this is the Information Commissioner's Office (ico.org.uk). In the EEA it is the authority in the Member State of your habitual residence, place of work, or the place of the alleged infringement. We would welcome the opportunity to address your concerns first.

11. Cookies and similar technologies

We use cookies and similar technologies, including browser local storage, for two purposes.

Strictly necessary. Keeping you signed in, recording your privacy choice, and protecting against abuse. These are set without your consent because the service you have requested cannot be provided without them.

Analytics. We use Google Analytics 4, provided by Google, to measure how the product is used: which surfaces are reached, which controls are used, and where a flow fails. It sets cookies in your browser to recognise a returning visit. We do not operate advertising or remarketing, and the advertising consent signals remain switched off irrespective of your choice.

Analytics is on by default and you may switch it off here. Switching it off prevents the analytics tag loading on your next page view and deletes the analytics cookies already present in this browser.

Your choice is stored in this browser only. It does not follow you to another device, and clearing site data resets it. You may also block or delete cookies through your browser settings, in which case parts of the product may cease to function.

11.1 What is never sent to our analytics provider

The following never leave the product for an analytics service. This is enforced by an automated check that fails our build if any of it is introduced:

12. Children

The product is not directed at children and is not available to anyone under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

13. Changes to this notice

We update this notice when our practices or the applicable law change. Where a change is material, we will notify you by email or in the product at least 30 days before it takes effect, unless we are required to act sooner. The version number and dates at the head of this page always identify the current version.

14. US state privacy rights

This section applies if you are a resident of a US state with a comprehensive consumer privacy law, including California, Colorado, Connecticut, Virginia and Texas. It supplements, and does not replace, the sections above.

14.1 Categories of personal information

Statutory categories of personal information collected, the purpose, and the recipients
Statutory categoryExamplesPurposeDisclosed to
IdentifiersAccount identifier, email address, wallet addresses, IP address Account administration, security, measurement Privy, Polymarket, Google, Cloudflare, Railway
Commercial informationDeposits, orders, Positions, withdrawals Executing your instructions, record-keeping Polymarket, on-ramp providers, Railway
Internet or other electronic network activity Surfaces opened, controls used, errors encountered Measuring and improving the productGoogle, Railway
Sensitive personal information Account log-in credentials, handled by our authentication provider Authenticating youPrivy

We collect these categories from the sources, and for the business purposes, described in sections 2 and 3, and retain them for the periods described in section 8.

14.2 Your rights

You have the right to know what personal information we collect and how we use and disclose it, to access and obtain a copy of it, to correct it, to delete it, and not to be discriminated against for exercising these rights. Submit a request to privacy@measurement.finance. You may use an authorised agent, and we may ask for proof of that authorisation. If we decline a request, you may appeal by replying to our response; we will inform you of the outcome within the period required by your state's law.

We do not sell personal information and we do not share it for cross-context behavioural advertising, and have not done so in the preceding 12 months. We do not use or disclose sensitive personal information for purposes that give rise to a right to limit. We honour the Global Privacy Control signal where your browser transmits one.

Contact

Questions about this notice, and requests to exercise your rights, should be sent to privacy@measurement.finance. We also read @MeasurementFi01 and our Telegram group, though we ask that you do not send personal data through those channels.