PolyYard Decentralized Privacy Policy
Last Updated: August 26, 2026
This Privacy Policy (this "Policy") describes how PolyYard ("PolyYard," "we," "us," or "our") handles information in connection with your access to and use of the PolyYard graphical user interface, decentralized order relayer, mobile interfaces, and web applications located at polyyard.io and any associated subdomains, APIs, or smart contract routers (collectively, the "Interface" or "Platform").
PolyYard is committed to protecting user privacy through a privacy-by-design, non-custodial Web3 architecture. We do not operate a centralized customer account system, do not hold custody of user digital assets, and do not harvest personal identity information for commercial monetization.
1. Fundamental Web3 Architecture & Principles
1.1. Non-Custodial & Accountless Infrastructure:
PolyYard is a decentralized front-end interface and communications relayer interacting with public smart contracts deployed on the Polygon PoS network (Chain ID: 137) and third-party decentralized order-matching systems (specifically, Polymarket's Central Limit Order Book ("CLOB") and Gnosis Conditional Tokens Framework ("CTF")).
1.2. No User Accounts or Customer Databases:
You do not need to register an account, create a username or password, verify an email address, or submit identity documentation (KYC) to browse the Interface. Your interaction with the Interface is established exclusively through your self-custodial Web3 cryptographic wallet.
2. Information We Do NOT Collect
Because of the decentralized nature of PolyYard, we never collect, store, transmit, or process:
- Government Identity Data: Legal names, physical street addresses, passport numbers, national ID numbers, or government-issued identification cards.
- Contact Information: Personal email addresses, telephone numbers, or physical mailing addresses.
- Financial Account Data: Bank account details, credit/debit card numbers, or traditional payment gateway credentials.
- Cryptographic Secrets: Private keys, seed phrases, recovery passwords, or hardware wallet authorization keys. You retain 100% custody and control of your credentials at all times.
3. Information Processed When You Use the Interface
While we do not collect personal identifiers, certain technical and blockchain-level information is processed automatically during your interactions with the Interface:
3.1. Public Blockchain Data
When you connect a Web3 wallet (e.g., MetaMask, Rabby, Coinbase Wallet, Rainbow, TronLink) and initiate transactions or sign cryptographic messages:
- Public Cryptographic Addresses: Your public blockchain wallet address (
0x...or TronT...) is read by the front-end to display your token balances, outcome shares, and transaction status. - On-Chain Transactions: Actions such as approving token allowances, executing smart contract calls, and redeeming winning prediction positions are permanently recorded on public, distributed ledgers (including Polygon PoS).
- EIP-712 Off-Chain Signatures: When placing prediction orders, you generate an EIP-712 structured cryptographic signature. This signature validates your order parameters (outcome token ID, side, price, and relayer markup fee) without revealing private keys.
- Public Ledger Immutability: Blockchain records are public, decentralized, and permanent. We do not operate, own, or control the underlying blockchain networks and have no ability to modify, redact, erase, or restrict on-chain transaction data.
3.2. Network Security, Telemetry & Geofencing Logs
When your web browser or client requests resources from the Interface, our edge routing and security infrastructure (e.g., Cloudflare) processes minimal technical telemetry:
- IP Addresses & Geolocation Filters: Inbound IP addresses are processed in transient server memory solely to enforce compliance with our Terms of Service (specifically, geoblocking access from restricted and OFAC-sanctioned jurisdictions) and to prevent automated Distributed Denial of Service (DDoS) attacks.
- Device & Client Diagnostics: Non-identifiable technical data—such as browser user-agent strings, operating system type, preferred language settings, and request timestamps—may be collected temporarily to optimize layout responsiveness and debug system performance.
3.3. Third-Party Protocol & Bridge Ingestion
- Polymarket CLOB & Gamma APIs: The Interface sends read/write requests to Polymarket's public endpoints (
gamma-api.polymarket.comandws-subscriptions-clob.polymarket.com) to stream real-time order books, price odds, and market outcomes. - Cross-Chain Bridge SDKs (Li.Fi & Symbiosis): When you use embedded cross-chain deposit widgets (e.g., bridging BEP-20 USDT from BNB Chain or TRC-20 USDT from Tron), transaction parameters (originating chain, source token, destination address, and swap amounts) are communicated directly to the respective bridge APIs and intent solvers.
4. Cookies, Local Storage & Tracking Technologies
- No Commercial Ad Tracking: PolyYard does not use third-party tracking pixels, advertising cookies, fingerprinting scripts, or data broker analytics (such as Google Analytics or Meta Pixel).
- Browser Local Storage (
localStorage): The Interface uses standard client-side browser storage solely to remember your user interface preferences between sessions. This includes:- Theme preferences (Dark / Light mode);
- Pinned or favorited prediction markets;
- Acknowledgment flags for the Terms of Service and Risk Disclosures.
You can clear local storage at any time through your browser's privacy settings.
5. How Processed Information Is Used
Any technical data processed by the Interface is used strictly for the following operational purposes:
- Facilitating Non-Custodial Interactions: Enabling your self-custodial wallet to construct and relay orders to the Polymarket CLOB and Gnosis CTF contracts.
- Regulatory & Sanctions Compliance: Automated enforcement of IP-based geofencing rules to restrict access from prohibited jurisdictions and sanctioned territories.
- Interface Reliability & Performance: Mitigating bot attacks, malicious API abuse, and optimizing server response latency.
- Platform Maintenance: Debugging UI layout issues across desktop and mobile devices.
6. Sharing & Disclosure of Information
We do not sell, rent, monetize, or trade any user telemetry or wallet information. Information is only disclosed under the following limited circumstances:
- Public Blockchains: Your wallet address and smart contract transactions are broadcast directly to public nodes and are visible to anyone inspecting the blockchain.
- Infrastructure Service Providers: Reputable third-party hosting, edge routing, and node providers (e.g., Cloudflare, Alchemy, QuickNode) process network traffic solely to deliver the web application securely.
- Legal & Regulatory Obligations: If required by a valid, binding legal process or court order issued by a court of competent jurisdiction, we may disclose available technical logs. However, because we do not maintain user identity databases, we cannot provide information that we do not possess.
7. Data Security & Retention
- Retention Period: Transient network logs and IP connection records processed by our edge security infrastructure are retained on standard rotating schedules (typically purged within 30 to 90 days).
- Cryptographic Security: The Interface relies on industry-standard Web3 communication protocols (HTTPS/TLS 1.3, WSS, and EIP-712 cryptographic signatures) to prevent man-in-the-middle tampering during order transmission.
8. Your Rights & Blockchain Realities (GDPR / CCPA / International Standards)
Under data protection frameworks such as the General Data Protection Regulation (GDPR) or California Consumer Privacy Act (CCPA), individuals have specific rights regarding personal data (including rights of access, rectification, objection, and erasure / "right to be forgotten").
- Application to Blockchain Data: Due to the decentralized, immutable, and cryptographic nature of blockchain technology, neither PolyYard nor any single entity can alter, update, or delete transaction data recorded on the Polygon PoS network or any public blockchain.
- Exercising Rights: Because PolyYard does not store personal identification records, email lists, or identity databases, we have no mechanism to link an anonymous public wallet address to any real-world individual.
9. Third-Party Links & Services
The Interface links to or incorporates third-party protocols, software widgets, and documentation (such as Polymarket, Gnosis CTF, UMA Oracle, Li.Fi, Symbiosis, and Web3 wallet providers).
This Policy applies solely to the PolyYard front-end Interface. We do not control and are not responsible for the privacy practices, code integrity, or data policies of external third-party protocols or websites. We encourage you to review the privacy documentation of any third-party services you interact with.
10. Children's Privacy
The Interface is strictly directed to and designed for individuals who are at least eighteen (18) years of age (or the legal age of majority in their jurisdiction). We do not knowingly facilitate access for or process data from minors. If you are under 18 years of age, you are strictly prohibited from using the Interface.
11. Modifications to this Privacy Policy
We reserve the right to revise or update this Policy at our sole discretion. Any changes will be published directly on this page with an updated "Last Updated" and "Effective Date" header. Your continued interaction with the Interface following the posting of an updated Policy constitutes your acknowledgment and acceptance of the revised practices.
12. Contact & Open-Source Verification
If you have questions, feedback, or require technical clarification regarding our privacy and data practices, you may:
- Inspect the open-source repository and smart contract code at our official GitHub organization;
- Engage with the developer community through the official PolyYard community communication channels.