The full legal text is published at calibri.io/hub/privacy-policy. This article covers the same ground in plain language; where the two differ, the published policy governs.
What we collect
Account details
Given by you when you sign up:- Email address — the account identifier and how we contact you.
- Password — stored hashed, never in readable form. We cannot see it. Accounts created with Google or a wallet get a random one they never use.
- Google account identifier, if you continue with Google. Google sends us a signed token containing your email address, whether Google has verified it, and an account identifier; we store the identifier so the same Google account signs you back in. We do not receive your Google password, and we do not gain access to anything else in your Google account.
- Wallet address, if you sign in with a wallet, or the public half of your passkey credential if you enrol one. The private half of a passkey never leaves your device and is never sent to us.
- Referral code, where you arrived through one.
Identity verification (KYC)
Collected only where verification is required for your account or jurisdiction:- Legal name, date of birth, nationality and country of residence
- Residential address
- Government-issued photo ID and any supporting documents
- Phone number
- Source of funds and occupation, where asked
- Politically-exposed-person screening results
Trading and platform activity
- Orders, fills, contracts, positions, and settlement outcomes
- Rewards and referral earnings
- Market suggestions you submit
- Your Safe address and the on-chain transactions relayed on your behalf
Technical data
- Session cookies — HTTP-only, used to keep you signed in. Not used for advertising.
- Device and browser information, IP address, and request logs — kept for security, fraud prevention, and debugging.
- Analytics — we use Google Analytics 4 (linked to Firebase) to understand how the app is used. Where you are signed in, events are associated with your account identifier.
- Bot protection — Cloudflare Turnstile runs on sign-up and sign-in.
- Push notification tokens, if you enable notifications.
- Browser security reports — content-security-policy violation reports, which we log to catch misconfigurations. They are logged and discarded, never stored against your account.
What is public by design
Some things are public because the system is on-chain, not because we published them: The leaderboard shows a privacy-masked display name — an opted-in name, or a masked form derived from your account. You can opt out in your account preferences.What we do with it
We do not sell your personal data, and we do not share it with advertisers.
Who else sees it
Only the providers needed to run the service:- Identity verification providers — for document and identity checks
- Google Analytics / Firebase — usage analytics and push notifications
- Google Sign-In, if you use it — Google learns that you signed in to Calibri, as it does for any site you use it on. We send Google nothing about your trading
- Cloudflare — bot protection and network delivery
- Our support helpdesk — for tickets you raise
- Market resolution sources (Coinbase, sports data providers) — these receive no personal data; we read prices and results from them, and nothing about you goes the other way
- Regulators, law enforcement, and auditors — where we are legally required to disclose
How long we keep it
- Account and KYC records — for as long as your account is open, and afterwards for as long as financial-services record-keeping rules require. These retention periods are set by regulation, not by us, and they mean closing your account does not immediately erase your verification records.
- Trading activity — retained as part of the same record-keeping obligation.
- Technical logs — a limited period, for security and debugging.
- On-chain data — permanent and outside anyone’s control, including ours.
Your rights
Depending on where you live, you can ask us to:- Access the personal data we hold about you
- Correct anything inaccurate
- Delete your data, subject to the retention obligations above
- Object to or restrict certain processing
- Port your data to another provider
- Withdraw consent for anything you opted into, such as marketing
Security
Passwords are hashed. Sessions are HTTP-only cookies with CSRF protection and a sliding expiry. API requests are signed so a captured signature cannot be replayed against a different request. Passkeys and wallet keys stay on your device — we never hold a key that can move your funds. No system is perfectly secure. Keep your credentials, passkeys, API keys, and session keys to yourself, and revoke anything you think has been exposed.Cookies
We use cookies to keep you signed in, to protect against cross-site request forgery, and — where analytics is enabled — to measure usage. We do not use advertising cookies. Blocking the session cookie will stop you from signing in.Children
Calibri is not for anyone under the legal age in their jurisdiction. We do not knowingly collect data from minors, and will delete it if we find we have.Changes
We may update this policy. Material changes will be announced, and the published policy carries the authoritative version and date.Contact
Privacy questions and data requests: support.calibri.io/contact.Related
Terms of use
The rules you accept by trading.
Getting started
Creating an account and setting up your wallet.
How self-custody works
Why we hold no funds and no keys.