Privacy Policy
Last updated: [DATE]
Draft, not yet reviewed by counsel. The content below describes how Mobytape actually works, but it has not been checked by a qualified lawyer for your jurisdiction. Have it reviewed, replace every bracketed placeholder, then delete this notice before running ads or accepting payment.
What we collect
| Data | Why |
|---|---|
| Email address and display name | To create your account, sign you in, and send alerts and account email. |
| Password hash | Sign-in. Passwords are hashed with bcrypt and never stored in readable form. |
| Google or X account identifier | Social sign-in, if you use it. We store the provider's subject identifier and basic profile fields. We never store provider access or refresh tokens. |
| Telegram chat identifier | Only if you connect Telegram, so alerts can be delivered there. |
| Your alert rules, tracked wallets and notification history | To run the product. |
| API keys | Stored only as a SHA-256 hash, alongside a short prefix so you can tell keys apart. |
| Session records: browser user agent, IP address, timestamps | So you can review and revoke your signed-in devices, and to detect stolen session tokens. |
| IP address | Rate limiting and abuse prevention. |
| Stripe customer and subscription identifiers | To manage your subscription. We never see or store your card details. |
What we do not collect
We do not collect wallet private keys, we do not connect to your wallet, and we cannot transact on your behalf. Public blockchain and venue data shown in the product is not personal data you have given us; it is public activity we read from Polymarket and Kalshi.
Who we share it with
- Stripe, for payment processing and subscription state.
- Telegram, only if you connect it, to deliver your alerts.
- [EMAIL PROVIDER], to deliver account and alert email.
- Google and X, only if you use social sign-in.
- [HOSTING AND CDN PROVIDER], which processes requests on our behalf.
We do not sell personal data, and we do not share it with advertisers.
How long we keep it
Account data is kept while your account exists. Password reset and email confirmation tokens expire within 30 minutes and 24 hours respectively. Expired session records are cleared on a schedule. Market price and flow snapshots are pruned after [30] days. On account deletion we remove your personal data, subject to records we must keep for tax or legal reasons.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your data, and to object to certain processing. Contact us and we will respond within the period the applicable law requires.
Cookies
The application sets one essential cookie: an HttpOnly refresh-token cookie
that keeps you signed in. It is not used for advertising or cross-site
tracking. This marketing site sets no cookies. Campaign parameters in a link
you followed, such as utm_source, are passed through to the
signup link and are not stored on this site.
Security
Passwords are hashed with bcrypt. Refresh tokens and API keys are stored only as hashes. Sessions are grouped into families so a replayed token revokes the whole family. Traffic is served over HTTPS. No system is perfectly secure; tell us immediately if you suspect a problem with your account.
Contact
Data controller: [LEGAL ENTITY NAME], [REGISTERED ADDRESS]. Reach us through the contact page.