Last updated: April 11, 2026
Last updated: April 11, 2026
This Privacy Policy describes how Probalytics ("we", "us", or "our") collects, uses, and processes personal data when you use our website at probalytics.io and our data infrastructure services (collectively, the "Service").
We are subject to the General Data Protection Regulation (GDPR) and applicable Finnish/EU data protection law.
1. Who We Are
Probalytics is a data infrastructure provider offering access to prediction market data — including market metadata, trade history, and orderbook history — for Polymarket and Kalshi. We serve developers, quantitative researchers, and algorithmic trading firms.
For GDPR purposes, Probalytics is the data controller for personal data collected through our website and API.
Contact: arsenii@probalytics.io
2. What Data We Collect
2.1 Account Data
When you sign up for an API key or paid plan, we collect:
- Name
- Email address
- Payment information (processed via Stripe — we do not store card data)
- Company name (optional)
2.2 Usage Data
When you use the API or ClickHouse SQL endpoint, we collect:
- API key used
- Endpoints queried, query volume, and timestamps
- IP address
- HTTP request metadata (user agent, response codes)
This data is used to enforce rate limits, detect abuse, and monitor service health.
2.3 Website Analytics
We use PostHog (EU cloud instance, eu.posthog.com) to collect anonymous usage analytics on the website, including:
- Pages visited and time on page
- Referral source
- Country-level geolocation (not precise location)
- Browser and device type
We do not use Google Analytics. PostHog processes data within the EU.
2.4 Communications
If you join the waitlist or subscribe to updates, we collect your email address and any optional information you provide. We use Brevo for transactional and marketing emails.
2.5 Market Data
The data we provide through the Service (Polymarket trades, orderbook snapshots, Kalshi market data) is public or licensed market data. It does not contain personal data as defined under GDPR.
Polymarket operates on the Polygon blockchain; on-chain data is publicly accessible. Kalshi data is accessed via their public API.
3. Legal Basis for Processing
| Purpose | Legal Basis |
|---|---|
| Providing the Service (API access, billing) | Contract performance (Art. 6(1)(b)) |
| Fraud detection, rate limiting, abuse prevention | Legitimate interests (Art. 6(1)(f)) |
| Sending transactional emails | Contract performance (Art. 6(1)(b)) |
| Sending marketing emails | Consent (Art. 6(1)(a)) |
| Website analytics | Legitimate interests (Art. 6(1)(f)) |
| Legal compliance (invoicing, tax records) | Legal obligation (Art. 6(1)(c)) |
4. Data Retention
- Account data: Retained while your account is active and for 12 months after account closure, unless a longer retention period is required by law.
- API usage logs: Retained while account is active and up to 12 months after account closure for operational purposes.
- Billing records: Retained for 7 years to comply with Finnish accounting law.
- Marketing email list: Retained until you unsubscribe or withdraw consent.
5. Third-Party Processors
We share your data with the following processors under GDPR-compliant data processing agreements:
| Processor | Purpose | Location |
|---|---|---|
| Stripe | Payment processing | US (SCCs / EU data residency option) |
| Brevo (Sendinblue) | Email delivery | EU |
| PostHog | Product analytics | EU (eu.posthog.com) |
| AWS (EU region) | Infrastructure & data storage | EU |
We do not sell personal data to third parties.
6. Your Rights Under GDPR
You have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Erase your data ("right to be forgotten"), subject to legal obligations
- Restrict processing in certain circumstances
- Data portability — receive your data in a machine-readable format
- Object to processing based on legitimate interests
- Withdraw consent at any time for processing based on consent (e.g., marketing emails)
To exercise any of these rights, email arsenii@probalytics.io. We will respond within 30 days.
You also have the right to lodge a complaint with the Finnish Data Protection Ombudsman (tietosuoja.fi).
7. Cookies
We use minimal cookies:
- Session cookie: Required for authenticated access to the dashboard.
- Analytics: PostHog may set a cookie to identify returning sessions. This is anonymized.
We do not use advertising or tracking cookies.
8. Security
We use industry-standard security practices including TLS encryption in transit, access control on ClickHouse endpoints, and API key authentication. API keys should be kept confidential — you are responsible for any access made with your key.
9. OAuth Authentication (Google & GitHub)
You may sign in to Probalytics using your Google or GitHub account. Here is what we access and why.
Google OAuth
We request the following scopes:
openid— confirm you have a valid Google accountemail— create and identify your Probalytics accountprofile(name) — pre-fill your display name
We do not request access to Gmail, Google Drive, Google Calendar, your contacts, or any other Google service. We do not act on your behalf in any Google product.
Probalytics's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we only use Google user data to provide authentication; we do not transfer it to third parties except as necessary to operate the service; we do not use it for advertising; and we do not allow humans to read it except for security or legal reasons.
GitHub OAuth
We request the following scopes:
read:user— confirm your GitHub identity and read your public profileuser:email— retrieve your primary email address to create your account
We do not request access to your repositories, code, issues, organizations, or team membership. We do not act on your behalf on GitHub.
What we do with OAuth data
Data obtained via OAuth is used exclusively to create and authenticate your account, associate it with an email address for billing and communication, and pre-fill your display name. We do not store OAuth tokens beyond the session required to complete authentication.
Revoking access
You can revoke Probalytics's OAuth access at any time:
- Google: myaccount.google.com/permissions
- GitHub: github.com/settings/applications
Revoking OAuth access does not delete your Probalytics account. To close your account, email arsenii@probalytics.io.
10. Cookies
We may update this policy from time to time. Material changes will be communicated by email to registered users. The "Last updated" date at the top reflects the most recent version.
12. Contact
For privacy-related questions or to exercise your rights:
Email: arsenii@probalytics.io
Website: probalytics.io
Probalytics is a service operated by Workki Oy, Kokinniitty 7 B, 02250 Espoo, Finland.