Oddictor ← Back to Oddictor
Public draft — not legally effective This is a working draft published for transparency and review. It has not been adopted by an identified operator, has not passed legal counsel review, and should not be relied upon as final legal terms. Operator identity, jurisdiction and a contact channel are not yet designated and are marked below. Draft v0.1 · 2026-10-01.

Privacy Policy (Draft)

Applies to: oddictor.com research preview · Status: DRAFT · Version 0.1 · Date: 2026-10-01

1. Who is responsible for this service

OWNER DECISION REQUIRED: The operating legal entity, its jurisdiction and a public privacy contact have not yet been designated. No entity name, address or email is asserted here because none has been confirmed. This section must be completed before this policy can take effect.

Until an operator is designated, this document describes the actual technical behavior of the current research preview, verified against its source code, rather than legal commitments.

2. What the service currently is

Oddictor is an experimental research preview that displays public prediction-market prices (from Polymarket), public market inputs (Binance spot data, MLB standings) and an experimental, uncalibrated model baseline. There are no user accounts, no public signup, no payments and no execution of transactions.

3. Data we collect from visitors

Accounts and identity: none. There is no registration, login, or profile. We do not collect names, email addresses or payment details.

Cookies: the application sets no cookies.

Analytics/tracking: the application includes no analytics, advertising or tracking scripts.

Browser storage: the watchlist feature stores market identifiers in your browser's localStorage. This data stays on your device, is not transmitted to us, and can be cleared via your browser settings. An owner-only test feature may store an access token in sessionStorage for the current browser session only; this feature is not available to the public.

API usage: the public API serves market data only (GET /api/markets, /api/health, /api/methodology). The only write endpoint (POST /api/alerts) is restricted to an owner test token and is intended only for market identifiers and numeric thresholds; public alert signup is not enabled.

4. Infrastructure processing we do not control

The site is served through a Cloudflare Tunnel. Cloudflare processes connection data (such as IP addresses and request metadata) as part of delivering and securing the site, under its own privacy policy. We have not yet completed a review of Cloudflare's data handling as it applies to this deployment; treat this as an open item, not a settled assessment.

OPEN ITEM: Confirm hosting/CDN providers, their log retention, and any subprocessors before the final policy. Do not assume specifics beyond what is stated here.

5. Third-party data shown on the site

Market prices, event information and public trader leaderboards originate from third-party public sources (Polymarket; Binance; MLB). We display this data; we do not control those platforms' own privacy practices. Whale/leaderboard entries are public on-chain or platform identifiers published by the source platform, not data we collect about our visitors.

6. What we do not do

  • No advertising-data sales or sharing features are implemented in the application. Infrastructure connection processing is described above.
  • No profiling, personalization or behavioral advertising.
  • No marketing email (we hold no email addresses).
  • No payments and no storage of payment data.

7. Planned features that would change this policy

User accounts, watchlist sync, personal alerts and a paid "Plus" subscription are under design consideration only and are not available. If introduced, they would involve collecting at least an email address and account preferences, and using a payment processor for the planned Plus tier (planned at $9/month, not purchasable today). This policy will be rewritten and re-published before any such feature launches, and no such data is being collected now.

8. Your rights

Depending on your location, you may have rights under laws such as the EU/UK GDPR (e.g., access, rectification, erasure, portability, objection) or the California CCPA/CPRA (e.g., to know, delete, correct, and opt out of sale/sharing). Because there are no visitor accounts or application-held visitor profiles, there is generally no such account record held by the application to access or delete; infrastructure connection metadata may still exist. Once a privacy contact is designated (Section 1), this section will state how to exercise these rights.

9. Data retention

The application backend does not intentionally store visitor account records or visitor identifiers. The browser retains local watchlist data until you clear it. Cloudflare may retain connection metadata under its own practices; its retention for this deployment is not yet established. Owner-only alert test rules (a market identifier and a numeric threshold, no visitor data) are stored on the service's server. No specific retention period or deletion guarantee for infrastructure logs is asserted pending review.

10. Children

The service is not directed at children. There is no public registration or visitor-submission form; infrastructure connection metadata may still be processed as described above.

11. Changes

This draft will be revised before it becomes effective. The version and date at the top identify the current draft.

12. References

  • Regulation (EU) 2016/679 (GDPR) — official text, EUR-Lex
  • California Consumer Privacy Act — California Attorney General
  • Cloudflare Privacy Policy
  • Cloudflare Tunnel documentation

Oddictor / Research preview · Experimental, non-personalized research. Not investment advice. This product never executes transactions.

Draft Terms of Service · Market overview