Privacy Policy

Effective: July 21, 2026 · MarketMaster v7.0

The short version

MarketMaster is a website at marketmaster.live and a Chrome extension, covering Kalshi and Polymarket. Some data stays entirely on your device (see Section 2) — we don't see it. But MarketMaster is no longer just a license-issuance backend: signed-in features like watchlists & email alerts, the trading journal, analytics, the public leaderboard, and the developer API all store data on our servers so they can work. Section 3 lists everything we store, in full. The one thing that's always opt-in is analyzer pick-tracking (Section 8) — it's off unless you turn it on, and you can turn it back off and delete your history at any time.

1. Who we are

MarketMaster is run by an individual developer (referred to as "we," "us," or "the developer"). For privacy questions, contact support@marketmaster.live or use our contact form.

2. What the Chrome extension stores on your device

MarketMaster uses two Chrome storage areas, split by sensitivity and size:

2.1 Device-local only (chrome.storage.local)

2.2 Synced across your Chrome profiles (chrome.storage.sync)

The developer cannot read either of these two Chrome storage areas. chrome.storage.sync is encrypted in transit and at rest by Google as part of your Chrome account. To stop syncing, sign out of Chrome or disable extension sync in chrome://settings/syncSetup. Separately, if you're signed into a MarketMaster account, related data you enter on the website — watchlists and alert thresholds, journal entries, your username, and (only if you opt in) your analyzer picks — is stored on our backend as described in Section 3. That backend data is visible to us as the service operator, the same as any other account data, and is never sold.

3. What our backend stores

If you create a MarketMaster account at marketmaster.live, we store the following so that sign-in, billing, and the signed-in features of the site can work:

We do not store the specific markets you passively browse or analyze unless you've opted into pick-tracking (Section 8). We don't store your third-party exchange API keys (Kalshi, Polymarket, PredictionHunt) — those stay local to your device, see Section 2. We don't store your trade history or account balances from Kalshi or Polymarket, and we don't store your IP address beyond short-lived rate-limit and abuse-prevention records.

4. Subprocessors we rely on

We use a small number of well-known subprocessors. Each only sees the data it needs:

5. What the extension transmits to third parties

The MarketMaster extension makes direct HTTPS requests from your browser to these services so you can see live data. The marketmaster.live website and its backend make equivalent server-side requests to Kalshi's and Polymarket's public APIs to power the scanner, arbitrage detection, smart money feed, and leaderboard when you're using the site instead of (or in addition to) the extension.

6. Cookies and similar technologies

The marketing site at marketmaster.live uses a small number of essential cookies and browser-storage entries only for keeping you signed in (Supabase session tokens) and remembering your filter / sort choices on the dashboard. We do not use advertising cookies, third-party analytics, or cross-site trackers.

7. Chrome permissions, explained

8. Analyzer pick-tracking and the public leaderboard (opt-in)

Pick-tracking is off by default. If you turn it on — via the extension's consent prompt or Settings → Privacy on your dashboard — MarketMaster records each analyzer "pick" you make: the market, the side you picked, the price/probability at the time, and a timestamp. This is tied to your account and stored on our servers.

We use this to calculate your personal pick-accuracy statistics on /analytics and, if you've claimed a username, your rank (MMR) on the public /leaderboard. Opting in makes your username, your rank/tier, and your win-loss pick record publicly visible on /leaderboard and on a public profile page at marketmaster.live/u/<your-username>. Bet amounts, account balances, and wallet contents are never recorded or shown. We do not sell or share this data, and we don't aggregate it across users beyond the accuracy and leaderboard calculations described here.

This is opt-in and reversible. You can turn pick-tracking off and delete your pick history at any time from the extension Settings or your dashboard — doing so removes you from the public leaderboard and stops new picks from being recorded.

9. Your rights and choices

10. California residents (CCPA/CPRA)

We don't sell or share personal information as defined by California law, and we don't use personal information for cross-context behavioral advertising. California residents have the right to know, correct, delete, and limit use of sensitive personal information — all of which can be exercised via the methods in section 9.

11. European / UK residents (GDPR / UK GDPR)

For data we hold (account, subscription, license, watchlists, journal, and — if you opt in — analyzer picks), the developer acts as the data controller. Lawful basis is contractual necessity (to provide the service you signed up for), consent (for opt-in pick-tracking), and, for security and fraud-prevention logs, legitimate interest. You may exercise your rights of access, rectification, erasure, restriction, and portability via the methods in section 9 or by emailing support@marketmaster.live.

12. International data transfers

Our subprocessors (Supabase, Stripe, Cloudflare, Resend, Netlify, Sentry) operate globally. Data may be transferred to and processed in the United States and other countries. Each subprocessor maintains appropriate safeguards (Standard Contractual Clauses, etc.) for such transfers.

13. Children

MarketMaster isn't directed at children under 18 and isn't intended for anyone under the age of majority in their jurisdiction. We don't knowingly collect data from minors.

14. Security

All requests use HTTPS. Passwords are hashed by Supabase Auth using bcrypt — we never see or store plain-text passwords. Card data is handled directly by Stripe; we never see or store full card numbers. License keys are stored hashed where practical. We can't promise the service is unbreakable — no service can — but we take reasonable, standard precautions. If you suspect your account is compromised, change your password immediately and contact support@marketmaster.live.

15. Changes to this policy

We may update this policy. Material changes will be flagged on the dashboard and via email (if your notification preferences allow). The "Effective" date at the top reflects the most recent revision.

16. Contact

Privacy questions, deletion requests, or data-rights requests: email support@marketmaster.live or use our contact form.