1. Information We Collect
An account is optional. Everything Virgil does works without one; creating one keeps your subscription on every device and opens the web terminal with the same login. We handle only the following:
- Account details — if you create an account: your email address, or the identifier Apple provides when you use Sign in with Apple (which may be a private relay address). Stored by Supabase, which hosts our authentication, together with the date the account was created. Used to sign you in, to keep your subscription and connected wallet in sync between the app and the web terminal, and to email you about your account and occasional Virgil updates. You can unsubscribe from updates at any time; account and billing notices still arrive.
- Polymarket wallet address — the public address you choose to enter. It is stored on your device, and sent to our servers so we can look up your public on-chain activity and apply the daily limits on AI features.
- Kalshi API credentials — the key ID and RSA private key Kalshi issues to you. These are stored only on your device and are never sent to our servers. Your device signs each request itself and talks to Kalshi directly. Records of your settled Kalshi trades are sent for the Trading Analysis feature described in section 4; your credentials are not.
- Subscription status — handled by RevenueCat. Without an account it is held under an anonymous identifier; with one, under your account id, so a subscription bought in the app or on the web is recognised in both. Apple or Stripe processes the payment; we never see your card details.
2. What We Do Not Collect
- Your name or postal address — and no email address unless you choose to create an account
- Payment details of any kind
- Usage analytics — the app contains no analytics or tracking SDK
- Push notification tokens — the app does not send push notifications
- Advertising identifiers, device model, or OS version
- Precise location, contacts, photos, or anything else on your device
3. How We Use Your Information
We use the above only to fetch and display your positions from Polymarket and Kalshi, calculate P&L and edge metrics, generate the AI insights described below, and apply the daily limits on AI features. We will never sell your data, use it for advertising, share your credentials with anyone, or trade against you.
4. AI Analysis
Three features call a third-party AI provider. Every one of those calls is made by our servers, never by your device, and never with your credentials.
- Market Brief — written twice a day from public market data. It is identical for every user and contains nothing about you.
- Trading Analysis — the one feature that is about you. It covers both exchanges.
- Polymarket: we send your wallet address, and our servers read your public on-chain activity from it.
- Kalshi: your portfolio there is not public, so our servers cannot read it. Instead your device sends the settled trades it has already worked out — market title, what you paid, what you received, the resulting profit or loss, your average entry price, and the date. Nothing about your open positions is sent.
- Market Deep Dive — we send public information about the market you tapped, plus public web search results. It contains nothing about you or your positions.
Our AI provider processes these requests in real time and does not use them to train its models.
5. Data Security
- Kalshi credentials and, if you sign in, your session token are held in the iOS Keychain, not in the app’s ordinary storage. Credentials never leave your device.
- Traffic between the app, Polymarket, Kalshi, our servers, and our AI provider is encrypted in transit over HTTPS.
- The tables holding AI analyses cannot be read by the app at all. Row-level security is enabled with no client policy, so only our server-side functions can read or write them.
- Credentials are never logged or shown in plain text.
No method of transmission or storage is completely secure. We use commercially reasonable measures but cannot guarantee absolute security. You are responsible for the security of your device and your Kalshi API credentials, and we recommend using read-only keys where Kalshi offers them.
6. Third-Party Services
- Polymarket — we read your public on-chain positions and activity. That data is publicly visible on the blockchain whether or not you use Virgil.
- Kalshi — your device requests your portfolio directly, using your own credentials, subject to Kalshi’s privacy policy. Our servers separately read Kalshi’s public market data, without any credentials.
- Supabase — hosts our database and server functions, in the United States.
- Our AI provider — as described in section 4.
- RevenueCat — records subscription status under an anonymous identifier.
- Apple — processes all payments.
Each operates under its own privacy policy. We are not responsible for third-party data practices.
7. Data Retention and Deletion
On your device: your wallet address, your Kalshi credentials, and cached analyses are removed when you disconnect the account in Settings, and when you delete the app. Signing out removes your session.
On our servers: AI analyses are stored against your wallet address — or, if you have connected only Kalshi, a one-way hash of your Kalshi key identifier — and the date they were produced, so the same analysis is never generated twice, alongside a daily count of how many analyses that account has requested. Shared market briefs and market deep dives contain no user data. We keep these records until you ask us to remove them.
Deleting your account: Settings → Account → Delete Account, in the app. This permanently removes your account, your email, your connected wallets, your portfolio snapshots and the analyses generated for your wallet. It does not cancel a subscription — Apple or Stripe manage those, and you should cancel there first if you want billing to stop. If you never created an account, or would rather email, write to virgil@pier94talent.com and we will remove every record associated with your wallet address.
8. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, delete, or port your personal data, to object to its processing, and to withdraw consent. To exercise any of these rights, email virgil@pier94talent.com. We will respond within 30 days. EU and UK residents may also lodge a complaint with their local data protection authority. California residents have the same rights under the CCPA, plus the right to non-discrimination for exercising them; we do not sell personal information.
9. Age Requirement
Virgil is intended for users 18 years of age and older. We do not knowingly collect personal information from anyone under 18. If we become aware that a minor has provided personal information, we will delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be shown in the app, and the “Last updated” date above will change.
11. Contact
Pier94 Talent LLC — virgil@pier94talent.com