Legal
Privacy Policy
Statara Analytics Inc. · Last Updated: July 18, 2026 · Effective: July 18, 2026
Contact: support@statara.co
1. Who We Are and Scope
Statara Analytics Inc. ("Statara", "we", "us", "our") operates the Statara mobile applications (iOS and Android), the statara.co website, and related services (together, the "Service"). We provide performance analytics, behavioral insights, and tax-reporting tools for people who trade on prediction-market and event-contract venues. We are not an exchange, broker, futures commission merchant, investment adviser, or gambling operator: we never execute trades, hold funds or positions, custody assets, or take the other side of any market. This Privacy Policy describes what we collect, why, who we share it with, how long we keep it, and the rights and controls you have. It applies to all users of the Service worldwide.
2. Information You Provide to Us
●
Account information: email address, display name, optional username, and a password (stored only as a salted cryptographic hash; we cannot read it).
●
Venue API credentials: if you connect an exchange account (e.g. Kalshi), you provide an API key identifier and private key. The private key is encrypted immediately with AES-256-GCM, verified with the venue before storage, used solely to cryptographically sign read-only requests for your own data, and destroyed the moment you disconnect. It is never logged, never displayed back to you, and never used to place orders or move funds. See Section 3 for exactly what we read with it.
●
Wallet addresses: if you track a self-custodial venue (e.g. Polymarket), you provide a public wallet address. An address is a public identifier, not a credential: it grants no control over the wallet, and the activity we read from it is the same publicly visible on-chain data any block explorer shows.
●
Statement files: if you import history from a brokerage (e.g. Robinhood or Wealthsimple statement imports), the statement files you upload are parsed to extract your trade history. Extracted data is saved to your account; the files themselves are retained only as long as needed for processing and quality review.
●
Positions and trades you enter manually, with any notes or tags you attach.
●
Goals and preferences: performance goals, display preferences (currency, timezone), notification settings, and dashboard configuration.
●
Profile content: if you enable a public profile or share cards, the display name, username, and statistics you choose to expose.
●
Communications: support conversations, feedback, and survey responses.
●
Questions you ask: if you use natural-language analysis features (e.g. asking questions about your trading history), we process the question text against your own data to produce the answer.
3. Information Collected From Connected Venues
When you connect a venue, we sync the records needed to compute your analytics. Depending on the venue, this includes:
●
Fills: each trade's market, side, contract count, price, fees, maker/taker flag, and timestamp.
●
Settlements: market outcomes, amounts credited, and settlement times.
●
Positions and balances: your open positions, their venue-reported values, and your account balance at each sync.
●
Market metadata: titles, categories, close times, and structural details of the markets you have traded, cached for display.
●
We aim for your Statara figures to reconcile to the cent against the venue's own records, and the Service tells you when they do not. Where a venue reports figures we cannot independently recompute (e.g. certain on-chain venues), numbers are labeled venue-reported.
●
Your trading relationship remains with the venue. Kalshi's and Polymarket's own privacy policies govern their handling of your data: kalshi.com and polymarket.com.
4. Information Collected Automatically
●
Device and app data: device type, operating system, app version, language, and timezone.
●
Push notification tokens: if you enable notifications, we store the device push token needed to deliver them. Tokens are removed when invalid or when you log out.
●
Device identifiers for fraud prevention: we generate a device/browser identifier and receive a payment-method fingerprint from Stripe, used solely to prevent free-trial and promotion abuse and payment fraud.
●
Session and security data: login timestamps, session tokens, IP-derived security signals, failed-login counts, and a security audit trail of sensitive account events (e.g. password changes, credential connections and disconnections).
●
Sync audit records: every venue sync run is logged (venue, trigger, counts, success or failure) so that no sync can fail silently and you can always see when your data was last updated.
●
Error and diagnostics data: crash reports and error events (via Sentry) that may include device and session context. We configure error reporting to exclude venue credentials and private keys categorically.
●
Usage data: features used, screens viewed, and interactions, used to operate and improve the Service.
●
Anti-bot verification: our website uses Cloudflare Turnstile to distinguish humans from bots during signup and login.
5. Payment Information
●
Web subscriptions are processed by Stripe. We never receive or store full card numbers. We store your Stripe customer ID, subscription status, plan, billing period dates, and a card fingerprint/brand/last-4 supplied by Stripe (used for receipts and fraud prevention).
●
Mobile subscriptions are processed by Apple (App Store) or Google (Google Play). We receive and verify purchase receipts/tokens to activate your plan; Apple/Google handle all payment details under their own policies.
●
Billing history, invoices, and refunds are managed by the platform you purchased through.
6. How We Use Your Information
●
Provide the Service: store and display your positions, compute profit and loss, hit rates, exposure, closing-line value, and related statistics, reconciled against venue records.
●
Generate analytics and insights: we analyze your trading history to produce behavioral signals, trader archetypes, performance reports, and pattern detection (e.g. sizing up after losses, concentration, early-exit quality). This is automated profiling of your trading behavior; it produces informational outputs only and has no legal or similarly significant effect on you.
●
Build your tax export: organize your realized results per market into tax-ready reports you can download and hand to a preparer. We do not file anything on your behalf and do not share your tax data with any tax authority.
●
Responsible-trading features: certain signals (e.g. loss-chasing, drawdown alerts) exist to help you see your own patterns and pace your activity.
●
Send notifications: push notifications and emails about your syncs, settlements, milestones, goals, reports, and account events. Every non-critical category can be turned off in the app's notification settings; account-critical messages (billing failures, subscription and security notices) are always sent.
●
Process payments, manage subscriptions, trials, promotions, and referral rewards.
●
Prevent fraud and abuse: trial-abuse detection, duplicate-account detection, payment-fraud screening, rate limiting, and account-security enforcement.
●
Support: respond to your requests and troubleshoot problems.
●
Improve the Service: aggregate, de-identified statistics (e.g. platform-wide averages) that do not identify you.
●
Comply with law: respond to lawful requests and enforce our Terms.
7. Legal Bases (EEA/UK) and Canadian Compliance
Where the GDPR/UK GDPR applies, we rely on: performance of a contract (operating your account and subscriptions), legitimate interests (security, fraud prevention, service improvement, non-intrusive product messages), consent (marketing communications, optional integrations like venue connections, withdrawable at any time), and legal obligation (tax, accounting, lawful requests). In Canada, we comply with PIPEDA and, for Quebec residents, the Act respecting the protection of personal information in the private sector (Law 25), including its requirements for consent, de-indexing, and privacy-incident reporting.
8. Who We Share Data With
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. Your venue API credentials are never shared with anyone, in any form. We share other data only with:
●
Processors who operate the Service under contract: Stripe (payments), Railway (cloud hosting), Expo (push notification delivery), Cloudflare (security/anti-bot), Sentry (error monitoring), and email delivery providers. Each receives only what it needs.
●
The venues you connect: connecting a venue necessarily means our servers communicate with that venue's API using your credentials or address, to read your data. We send them nothing about you beyond the authenticated requests themselves.
●
Apple and Google: to validate in-app purchases you make through their stores.
●
Other users / the public: only the profile statistics you explicitly choose to make public or share via share cards and leaderboards. This is off by default.
●
Authorities: when required by law, subpoena, or court order, or where necessary to protect the rights, safety, or property of Statara, our users, or the public.
●
A successor entity: in a merger, acquisition, financing, or asset sale. We will notify you before your data becomes subject to a different privacy policy.
9. Your Rights and Controls
Depending on where you live (GDPR, UK GDPR, PIPEDA, Quebec Law 25, CCPA/CPRA and other US state laws), you may have the right to access, correct, delete, port, restrict, or object to processing of your personal information, and to withdraw consent. We honor these rights for all users regardless of location. You can exercise most of them directly in the app:
●
Export your data: request a complete machine-readable export from the app's account settings; tax exports are downloadable whenever you need them.
●
Delete your account: deletion is available in-app and removes your account and associated personal data within 30 days (see Retention for limited exceptions).
●
Disconnect venues at any time: disconnecting destroys the stored credential immediately. You can additionally revoke the API key at the venue itself for certainty that no system can use it.
●
Edit or delete individual records, and change notification, privacy, and public-profile settings at any time in the app.
●
Unsubscribe from marketing emails via the link in every email; transactional emails (receipts, security) continue while you have an account.
●
Anything else: email support@statara.co. We respond within 30 days and will not discriminate against you for exercising your rights. You may also lodge a complaint with your supervisory authority (e.g. the Office of the Privacy Commissioner of Canada, the Commission d'accès à l'information du Québec, or your EU/UK data protection authority).
10. Data Retention
●
Venue API credentials: destroyed immediately when you disconnect the venue or delete your account. There is no retention period; the ciphertext is deleted, not archived.
●
Account and trading data: retained while your account is active. Deleted within 30 days of account deletion.
●
Uploaded statement files: retained only as long as needed for parsing and quality review, then deleted; the extracted trade data lives in your account under the rules above.
●
Backups: deleted data may persist in encrypted backups for up to 35 additional days before being overwritten.
●
Payment and tax records: retained as required by tax and accounting law (typically 7 years), held by our payment processors and in our billing records.
●
Security, sync-audit, and error logs: retained up to 24 months for fraud and incident investigation.
●
Fraud-prevention fingerprints: device and payment-method fingerprints linked to trial/promotion abuse may be retained after account deletion to prevent repeat abuse, in de-identified or minimized form where feasible.
●
Support conversations: retained up to 24 months after closure.
11. Security
Venue credentials get custodial-grade treatment: private keys are encrypted at rest with AES-256-GCM using keys held in our infrastructure's secret management (never in code or logs), bound per-user so one account's credential can never decrypt for another, verified against the venue before storage, and used exclusively to sign read requests. More broadly we use TLS encryption in transit, encryption at rest, salted password hashing, optional two-factor authentication, session and refresh-token rotation, role-based access controls, audit logging of sensitive actions, and least-privilege access for our personnel. No system is perfectly secure; if we learn of a breach creating a risk of serious harm, we will notify affected users and regulators as required by law (including Quebec Law 25 and GDPR timelines). If you suspect your account is compromised, contact support@statara.co immediately and revoke your API keys at the venue.
12. Cookies and Similar Technologies
Our website uses strictly necessary cookies for authentication and security (session management, CSRF protection, Cloudflare Turnstile). We do not use third-party advertising cookies or cross-site trackers. Because we don't engage in cross-context tracking, there is nothing to opt out of via Do Not Track or Global Privacy Control signals, but we treat such signals as a marketing opt-out where applicable.
13. Children and Age Limits
The Service is strictly for adults: you must be at least 18 years old, and meet any higher eligibility requirements of the venues whose data you connect. We do not knowingly collect data from anyone under 18. If you believe a minor has an account, contact us and we will delete it promptly.
14. International Data Transfers
We are a Canadian company and our infrastructure providers operate in the United States and other countries. When your data is transferred outside your jurisdiction, we rely on appropriate safeguards such as standard contractual clauses with our processors and processor commitments to equivalent protection. By using the Service you acknowledge your data may be processed in countries with different data-protection laws than your own, subject to the safeguards described here.
15. Third-Party Services
The Service links to or integrates third parties (Kalshi, Polymarket, brokerages whose statements you import, Stripe, Apple, Google). Their privacy practices are governed by their own policies, and we encourage you to read them. Statara is an independent product: we are not affiliated with, endorsed by, or sponsored by any venue, and we are not responsible for the privacy practices of services we do not control.
16. Changes to This Policy
We may update this policy as the Service evolves. For material changes we will notify you by email or in-app notice before the changes take effect, and where required by law we will ask for renewed consent. The 'Last Updated' date at the top always reflects the current version. Continued use after the effective date constitutes acceptance where permitted by law.
17. Contact Us
Privacy questions, rights requests, or complaints: support@statara.co (attention: Privacy Officer). Quebec residents: our designated person in charge of the protection of personal information can be reached at the same address. We aim to acknowledge requests within 7 days and resolve them within 30 days.