Privacy Policy

Effective Date: August 6, 2026

This Privacy Policy explains how WhaleScope ("WhaleScope," "we," "us," or "our") collects, uses, discloses, and protects information when you use the WhaleScope mobile application (the "App") and the whalescope.io website (together, the "Service").

1. Information We Collect

We collect the following categories of information, based on how you actually use the Service:

1.1 Account information

When you create an account, we collect your email address and password (email/password sign-up), or, if you use Sign in with Apple, your Apple-provided identity token and, if you choose to share it, your name. We do not receive or store your Apple ID password.

1.2 Profile and subscription information

We store your subscription plan, monthly analysis usage count and limit, billing-cycle dates, trial start/end dates, and — depending on how you subscribed — either your Stripe customer/subscription identifiers or your Apple original transaction ID and App Store subscription status. We do not receive or store your full payment card number; payment is handled directly by Apple (App Store) or Stripe.

1.3 Content you submit

1.4 Device and push notification information

If you enable push notifications, we collect your device's push token (an Apple Push Notification service ("APNs") token for the App, or a Web Push subscription endpoint and keys for the website) and store it together with your account and the token's environment (sandbox/production), so we can deliver whale-alert notifications to your device. We remove this token when you disable notifications or sign out.

1.5 Device integrity information

The App uses Apple's App Attest service to help prevent abuse (e.g., automated or fraudulent use of the analysis feature). This involves a device-generated attestation key ID, public key, and related cryptographic assertions. This mechanism is designed to verify your device's integrity and does not identify you personally beyond linking to your account.

1.6 Camera and photo library access

The App requests access to your camera and photo library solely so you can capture or select a screenshot of a Polymarket market to submit for analysis. We do not access your camera or photos for any other purpose, and we do not browse your photo library beyond the image you actively choose to share.

1.7 Information from website visitors and leads

If you interact with our marketing website (for example, by starting a checkout flow or completing an onboarding quiz before creating an account), we may collect your email address, first name, and information about your interaction (such as which plan you were interested in and how you found us).

1.8 Automatically collected / advertising information

Our website uses Google Tag Manager and the Meta (Facebook) Pixel, which automatically collect standard web analytics and advertising information (such as page views) when you visit whalescope.io. Separately, when you complete a purchase or key funnel step, we send certain hashed information (a one-way cryptographic hash of your email address and, where available, your name) together with purchase value and event information to Meta's Conversions API, to help measure and improve the effectiveness of our advertising. Meta receives a hashed, not plain-text, version of this information. See Section 6 for your choices regarding this use.

1.9 Data we do not collect

We do not ask for or knowingly collect your date of birth, government ID, precise location, contacts, or any cryptocurrency wallet private keys or seed phrases. The "whale wallet" data shown in the Service concerns third-party public Polymarket traders' on-chain activity, not your own wallet.

2. How We Use Information

We use the information described above to:

We do not use your data to train third-party general-purpose AI models beyond the ordinary processing described in Section 3 (i.e., sending your submitted market/screenshot content to AI providers to generate your requested analysis).

3. How We Share Information

We do not sell your personal information for money. We share information only as follows:

Service providers who process data on our behalf, each limited to what they need to perform their function:

ProviderPurposeData received
SupabaseAuthentication, database hosting, real-time data syncAccount, profile, subscription, tracking, and alert data
StripeWeb subscription payment processingEmail, name, plan, payment metadata (no full card number to us)
Apple (App Store Server API / APNs)iOS subscription verification, push notification deliveryPurchase transaction data; device push token
Google (Gemini API)OCR and text extraction from submitted screenshotsThe screenshot image; extracted market text
Anthropic (Claude API)Generating the AI market verdictMarket question and publicly derived whale/sentiment data used as analysis context (not your account identity)
DuckDuckGo SearchRetrieving public sentiment sources for a marketSearch queries derived from the market question (no personal information)
ResendSending transactional emails (password reset, receipts, trial notices)Your email address and name
Meta (Facebook)Advertising measurement (Pixel and Conversions API)Hashed email/name, purchase value, page-view events
Google Tag ManagerWebsite analytics/tag managementStandard web analytics data

Polymarket / public blockchain data: the Service reads publicly available Polymarket and blockchain data to generate whale analyses; we do not send your personal account information to Polymarket.

Legal and safety: we may disclose information if required by law, subpoena, or legal process, or if we believe disclosure is necessary to protect the rights, property, or safety of WhaleScope, our users, or the public.

Business transfers: if we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to standard confidentiality protections.

4. Cookies and Similar Technologies

Our website uses cookies to keep you signed in (via Supabase's session-cookie mechanism) and, if loaded, cookies set by Google Tag Manager and the Meta Pixel for analytics and advertising purposes. You can control cookies through your browser settings; blocking essential session cookies may prevent you from staying signed in.

5. Data Retention

We retain your account, profile, analysis history, tracked-market, and alert data for as long as your account is active, and for a reasonable period afterward to comply with legal, tax, accounting, or fraud-prevention obligations, or to resolve disputes. Device push tokens are removed when you disable notifications, sign out, or when Apple/browser push services report the token as no longer valid. You may request earlier deletion as described in Section 7.

6. Your Choices

7. Accessing, Correcting, or Deleting Your Data

You may request access to, correction of, or deletion of your personal information, or export of your data, by emailing us at the address in Section 10 with the subject line "Privacy Request." We will verify your request using your account email and respond within the time required by applicable law. Note that as of the effective date of this Policy, account deletion is handled manually by our team upon request rather than through an automated in-app control; if you request deletion, we will delete or anonymize your account and associated data (subject to any retention we are legally required to keep, such as tax records related to completed payments).

8. Your California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, "CCPA"), gives you the right to know what personal information we have collected about you and how it has been used and disclosed; delete personal information we have collected from you, subject to certain exceptions; correct inaccurate personal information; and opt out of the "sale" or "sharing" of your personal information.

We do not sell personal information in exchange for money. However, our use of the Meta Pixel and Meta Conversions API to support advertising measurement (Section 1.8) may be considered "sharing" for cross-context behavioral advertising purposes under the CPRA's broad definition. You can opt out of this sharing at any time using the methods described in Section 6 (Global Privacy Control or emailing us), and we will honor Global Privacy Control signals sent by your browser on whalescope.io. We do not knowingly sell or share the personal information of consumers we know to be under 16 years of age. To exercise any of these rights, contact us using the details in Section 10. We will not discriminate against you for exercising your CCPA rights.

9. Children's Privacy (COPPA)

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Account creation requires only an email address and password (or Apple Sign-In) and does not request age or date of birth, but the Service is intended for users 18 and older per our Terms of Use. If you believe a child under 13 has provided us with personal information, contact us at the address in Section 10 and we will delete it.

10. Contact Us

If you have questions about this Privacy Policy or wish to exercise any of the rights described above, contact us at:

Email: whalescopeapp@gmail.com

11. International Users

The Service is operated from the United States, and our service providers (including Railway, Vercel, and Supabase) may process and store data on servers located in the United States or other countries where they operate. By using the Service, you understand that your information may be transferred to and processed in countries other than your country of residence, which may have data protection laws different from those of your country.

12. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by posting the updated Policy in the App and/or on whalescope.io and updating the "Effective Date" above, and, where required by law, through additional notice (such as email or an in-app notice). Your continued use of the Service after the updated Policy takes effect constitutes acceptance of the changes.

See also our Terms of Use.