Privacy Notice
This notice explains what personal data we collect when you use Measurement Finance, why we collect it, who receives it, how long we keep it, and the rights you have over it.
Sections 1 to 13 apply to everyone. If you are in the EEA or the United Kingdom, they are our notice under Articles 13 and 14 of the UK and EU General Data Protection Regulation. If you are in the United States, read them together with the US state privacy rights annex in section 14.
At a glance
- We collect what we need to operate your account, place the orders you instruct, and keep the product working. We do not sell personal data.
- Your sign-in and your wallet are operated by Privy. Your orders are placed on Polymarket. Both receive personal data.
- Transactions are recorded on a public blockchain. Those records are permanent, and neither we nor you can delete them.
- We measure how the product is used with Google Analytics. It is on by default and you can switch it off in section 11.
- Wallet addresses, private keys, balances, position values and exact monetary amounts are never sent to our analytics provider.
- Accepted Feedback messages and completed assistant replies are retained in a dedicated private database. DeepSeek receives bounded support context; a private GitHub issue receives only a bounded summary and conversation reference, not the full transcript.
1. Who we are and how to contact us
This notice is issued by Measurement Finance ("we", "us", "our"). We are the controller of the personal data described in this notice.
You can reach us about anything in this notice, and exercise any of the rights described in section 10, at privacy@measurement.finance.
Providing the data requested when you sign in, and when you fund or instruct a Position, is necessary for us to enter into and perform our agreement with you. If you do not provide it, we cannot open an account for you or act on your instructions.
2. Personal data we collect about you
2.1 Data you provide to us
- Sign-in data. Where you sign in with Google, we receive your email address and an account identifier from our authentication provider. Where you sign in with an existing wallet, we receive that wallet address.
- Withdrawal instructions. The destination blockchain address you specify and the amount you instruct.
- Content you submit. Where you post to or vote on the Trend Requests board, we collect the content you write, the category you select, any market links you include, and the display name associated with your account.
- Feedback. If you use the in-product Feedback chat, we retain each message that the service accepts and a completed assistant reply in a dedicated private database, together with the selected problem scenario where applicable and allowlisted technical context: a coarse product surface, public Trend identifier and Direction, browser family and major version, viewport, locale, time zone and client time. When you send a report, the private issue it creates also records your account identifier and your sign-in wallet address, read from our identity provider using your verified sign-in, so that we can trace the account behind a report we are investigating. Text left unsent remains in your browser. We do not collect attachments, cookies, browser storage, balances, order or fill data, payment details, secrets such as passwords, recovery phrases and private keys, or raw URLs as technical context.
2.2 Data generated by your use of the product
- Wallet and custody data. The address of the wallet created for you, the addresses of the wallets holding each Position, and the status of the platform's signing permission over them.
- Transaction and Position data. Deposits, purchases, top-ups, rebalances, exits and withdrawals; order and fill records; balances; and the composition and value of each Position you hold.
- Usage data. The surfaces you open, the controls you use, whether a step succeeded or failed, and rounded bands for a committed budget. Section 11 sets out both what this contains and what it excludes.
- Technical data. IP address, browser and device characteristics, and the page you arrived from.
2.3 Data we receive from third parties
- From our authentication and wallet provider: your account identifier, your verified email address where applicable, and your wallet addresses.
- From payment and on-ramp providers: confirmation that a funding attempt succeeded or failed, and the amount. We do not receive your card or bank details.
- From the execution venue: the status and fills of orders placed for your Position.
- From public blockchains: transactions involving your wallet addresses.
We do not seek, and do not knowingly collect, special category data within the meaning of Article 9 of the GDPR.
3. How and why we use your personal data
We process personal data only for the purposes set out below. Each row states the lawful basis on which we rely for that purpose. Where we rely on legitimate interests, the interest is identified.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Creating and administering your account and providing the product to you | Sign-in data, account identifier, wallet addresses | Performance of a contract (Art. 6(1)(b)) |
| Placing, adjusting and closing the orders that constitute your Position, and crediting and returning funds | Wallet and custody data, transaction and Position data | Performance of a contract (Art. 6(1)(b)) |
| Maintaining accurate balances, Positions and records, and reconciling them against the execution venue and the blockchain | Transaction and Position data, wallet addresses | Performance of a contract (Art. 6(1)(b)) |
| Detecting and preventing fraud, abuse and unauthorised access, and protecting funds held on the platform | Technical data, transaction and Position data, account identifier | Legitimate interests (Art. 6(1)(f)) — protecting our users, their funds and our platform from financial crime and abuse |
| Measuring how the product is used, diagnosing faults and improving the product | Usage data, technical data, account identifier | Consent for the storing of and access to information on your device (see section 11), and legitimate interests (Art. 6(1)(f)) for the subsequent analysis — understanding and improving how our product is used |
| Responding to your enquiries and providing support | The content of your message, account identifier, and (for in-product Feedback) the selected scenario, allowlisted technical context, and the sign-in wallet address recorded on a sent report | Performance of a contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)) — responding to people who contact us |
| Operating the Trend Requests board | Content you submit, display name, account identifier | Performance of a contract (Art. 6(1)(b)) |
| Recording your request to be notified when a Basket becomes available | Account identifier, the Basket and Direction requested | Consent (Art. 6(1)(a)), given by activating the notify control |
| Complying with our legal, tax, accounting and record-keeping obligations, and responding to lawful requests from competent authorities | Account, transaction and Position data | Legal obligation (Art. 6(1)(c)) |
| Establishing, exercising or defending legal claims | Any of the above, so far as relevant to the claim | Legitimate interests (Art. 6(1)(f)) — protecting our legal position |
Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that our interests are not overridden by your interests, rights and freedoms. You may request a summary of that assessment at any time.
4. Who we share your personal data with
We disclose personal data to the recipients identified below, each of which processes it for the purposes described. We do not sell personal data and we do not share it for cross-context behavioural advertising.
| Recipient | Role | Data disclosed |
|---|---|---|
| Privy | Authentication, wallet creation and key management, and orchestration of card funding | Email address or wallet address, account identifier, wallet addresses, funding amounts |
| Polymarket | The execution venue on which your orders are placed, and the bridge that converts incoming funds. Market data is also requested directly by your browser, which discloses your IP address to Polymarket. | Wallet addresses, orders and fills, deposit and settlement transactions, IP address |
| Card and on-ramp providers engaged through Privy, including MoonPay, Meld and Coinbase depending on the route offered to you | Converting card or bank payments into the asset used to fund your Position, and performing their own identity and anti-money-laundering checks as independent controllers | The data you provide to them directly, and the destination address |
| DeepSeek | Generating the Feedback support conversation and categorising feedback | A bounded model context made from a rolling summary, recent saved Feedback turns and the current message; no allowlisted technical context, account, wallet, financial, authentication or secret data |
| GitHub | Keeping the private issue created from a submitted Feedback report | A bounded summary or excerpt, deterministic classification, scenario, allowlisted technical context and a conversation reference; not the full transcript, Privy DID, bearer token, wallet or financial data |
| Google (Google Analytics) | Product usage measurement | Usage and technical data and a pseudonymous account identifier, subject to the exclusions in section 11 |
| Cloudflare | Delivery of images and static assets | IP address and request metadata |
| Railway | Hosting of our application and database, as our processor | All data we hold |
We do not carry out identity verification or "know your customer" checks ourselves, and we do not collect identity documents. Where such checks are performed, they are performed by the card and on-ramp providers named above, acting as independent controllers under their own privacy notices and using data you provide directly to them.
We also disclose personal data where we are required to do so by law or by a competent authority, and to our professional advisers where necessary for the purposes in section 3. If our business is reorganised, sold or merged, personal data may be transferred to the acquiring entity, and this notice will continue to apply to it until replaced.
5. Blockchain data
Funding a Position, placing an order, and withdrawing each result in transactions being recorded on a public blockchain. Those records are public, permanent and outside our control. We cannot amend, delete or restrict them, and neither can you.
Wallet addresses and transaction records may be capable of being linked to you, by us or by third parties who analyse blockchain data. If you exercise your right to erasure, we can erase the personal data held in our own systems; we cannot erase data written to a public blockchain, and the right does not extend to it.
6. International transfers
We and our service providers operate in several countries, including the United States. Your personal data may therefore be transferred to, stored in and processed outside the EEA and the United Kingdom.
Where we transfer personal data outside the EEA or the United Kingdom, we rely on one of the following safeguards: an adequacy decision of the European Commission or UK adequacy regulations covering the destination; the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the transfer originates in the United Kingdom; or another mechanism permitted under Chapter V of the GDPR. Where we rely on the Standard Contractual Clauses we also assess whether supplementary measures are required for the destination. You may request a copy of the safeguards we have put in place.
7. Automated decision-making and profiling
We use automated processing in two places. Only one of them involves a decision about you.
The AI that maintains a Basket operates on markets, not on people. It selects and reweights prediction markets using market data. It does not use your personal data, does not profile you, and produces no decision concerning you. Every user holding that Direction is affected identically.
Automated controls may restrict activity on an account. We operate automated rules to detect fraud, abuse and anomalous movement of funds, which may delay a transaction or restrict an account. Where such a decision is based solely on automated processing and produces legal effects concerning you or similarly significantly affects you, you have the right to obtain human intervention, to express your point of view and to contest the decision. Write to privacy@measurement.finance.
8. How long we keep your personal data
We retain personal data only for as long as necessary for the purposes set out in section 3. Where a retention period is prescribed by law, we apply that period. Otherwise we determine the period by reference to the volume, nature and sensitivity of the data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it, and whether those purposes can be achieved by other means.
| Category | Retention period |
|---|---|
| Account and sign-in records | For the duration of your account, and for a further period after closure for as long as a claim may still arise or the records must be kept by law |
| Transaction, order and Position records | For the period required by applicable tax, accounting and financial record-keeping law — generally not less than five years from the date of the transaction |
| Support correspondence | Three years from the last communication |
| In-product Feedback reports | Accepted Feedback turns, completed assistant replies, model memory, hashed rate records, and the account identifier and sign-in wallet address recorded on a sent report are retained indefinitely in the dedicated private database unless an authorised operator completes a verified owner-erasure request or a legal requirement applies. There is no automatic deletion. DeepSeek receives bounded context only to provide the requested response and classification, subject to its current API retention terms. A separate private GitHub issue retains only the bounded summary/reference, is not automatically deleted, and is redacted for a verified erasure request. |
| Analytics data | 14 months, after which it is deleted by our analytics provider |
| Trend Requests board content | For as long as the board carries it, or until you ask us to remove your contribution |
| Blockchain records | Permanent and outside our control — see section 5 |
For Feedback, verified erasure is operator-assisted rather than self-service: we verify the requester, delete that owner's dedicated-database conversations, model memory and associated rate records, and redact matching GitHub summaries before the database deletion. The current staging Feedback database uses its attached service volume only. It has no scheduled backup or verified volume-loss restore coverage, so staging records must not be treated as recoverable. Production Feedback is not enabled. At the end of another applicable period we delete the data or irreversibly anonymise it, in which case we may continue to use the anonymised data indefinitely.
9. How we protect your personal data
We maintain technical and organisational measures appropriate to the risk. Access to production systems and to the data they hold is limited to personnel who require it. Signing authority over the wallets holding user funds is separated so that no single compromised component can move funds unilaterally, and the movement of value is restricted to destinations you control. You may export the private key of your wallet, or revoke our signing permission over it, at any time from the account menu.
No system can be guaranteed secure. Where a personal data breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay.
10. Your rights
Subject to the conditions and exemptions in applicable law, you have the right to:
- Access — obtain confirmation of whether we process your personal data and a copy of it, together with the information in this notice.
- Rectification — have inaccurate personal data corrected and incomplete data completed.
- Erasure — have your personal data deleted where we no longer have grounds to retain it. This does not extend to blockchain records (section 5) or to records we are required to retain by law.
- Restriction — require us to suspend processing in defined circumstances.
- Portability — receive the personal data you provided to us in a structured, commonly used, machine-readable format, or have it transmitted to another controller.
- Objection — object to processing carried out on the basis of our legitimate interests, on grounds relating to your particular situation.
- Withdrawal of consent — withdraw consent at any time where we rely on it. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
- Human review — not be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you.
To exercise any of these rights, write to privacy@measurement.finance. We may ask you to verify your identity before we act, in order to ensure we do not disclose personal data to the wrong person. We respond within one month of receipt, and will tell you if we need to extend that period. Exercising your rights is free of charge, and we will not treat you detrimentally for doing so. Where a request is manifestly unfounded or excessive we may charge a reasonable fee or decline to act, and we will explain why.
You also have the right to lodge a complaint with a supervisory authority. In the United Kingdom this is the Information Commissioner's Office (ico.org.uk). In the EEA it is the authority in the Member State of your habitual residence, place of work, or the place of the alleged infringement. We would welcome the opportunity to address your concerns first.
11. Cookies and similar technologies
We use cookies and similar technologies, including browser local storage, for two purposes.
Strictly necessary. Keeping you signed in, recording your privacy choice, and protecting against abuse. These are set without your consent because the service you have requested cannot be provided without them.
Analytics. We use Google Analytics 4, provided by Google, to measure how the product is used: which surfaces are reached, which controls are used, and where a flow fails. It sets cookies in your browser to recognise a returning visit. We do not operate advertising or remarketing, and the advertising consent signals remain switched off irrespective of your choice.
Analytics is on by default and you may switch it off here. Switching it off prevents the analytics tag loading on your next page view and deletes the analytics cookies already present in this browser.
Analytics is on.
Your choice is stored in this browser only. It does not follow you to another device, and clearing site data resets it. You may also block or delete cookies through your browser settings, in which case parts of the product may cease to function.
11.1 What is never sent to our analytics provider
The following never leave the product for an analytics service. This is enforced by an automated check that fails our build if any of it is introduced:
- Wallet addresses, private keys and transaction hashes.
- Your email address or name.
- Balances, Position values, profit and loss, and exact monetary amounts. A committed budget is transmitted only as a rounded band.
- Position, order and withdrawal identifiers.
- Anything you type.
12. Children
The product is not directed at children and is not available to anyone under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
13. Changes to this notice
We update this notice when our practices or the applicable law change. Where a change is material, we will notify you by email or in the product at least 30 days before it takes effect, unless we are required to act sooner. The version number and dates at the head of this page always identify the current version.
14. US state privacy rights
This section applies if you are a resident of a US state with a comprehensive consumer privacy law, including California, Colorado, Connecticut, Virginia and Texas. It supplements, and does not replace, the sections above.
14.1 Categories of personal information
| Statutory category | Examples | Purpose | Disclosed to |
|---|---|---|---|
| Identifiers | Account identifier, email address, wallet addresses, IP address | Account administration, security, measurement | Privy, Polymarket, Google, Cloudflare, Railway |
| Commercial information | Deposits, orders, Positions, withdrawals | Executing your instructions, record-keeping | Polymarket, on-ramp providers, Railway |
| Internet or other electronic network activity | Surfaces opened, controls used, errors encountered | Measuring and improving the product | Google, Railway |
| Sensitive personal information | Account log-in credentials, handled by our authentication provider | Authenticating you | Privy |
We collect these categories from the sources, and for the business purposes, described in sections 2 and 3, and retain them for the periods described in section 8.
14.2 Your rights
You have the right to know what personal information we collect and how we use and disclose it, to access and obtain a copy of it, to correct it, to delete it, and not to be discriminated against for exercising these rights. Submit a request to privacy@measurement.finance. You may use an authorised agent, and we may ask for proof of that authorisation. If we decline a request, you may appeal by replying to our response; we will inform you of the outcome within the period required by your state's law.
We do not sell personal information and we do not share it for cross-context behavioural advertising, and have not done so in the preceding 12 months. We do not use or disclose sensitive personal information for purposes that give rise to a right to limit. We honour the Global Privacy Control signal where your browser transmits one.
Contact
Questions about this notice, and requests to exercise your rights, should be sent to privacy@measurement.finance. We also read @MeasurementFi01 and our Telegram group, though we ask that you do not send personal data through those channels.