Privacy
Last updated August 5, 2026
The short version
Everything you write in Chad — your reasoning, your notes, your journal — is stored in your own browser, not on our servers, and we never receive it. We do receive a de-identified record of the trades themselves: the market, the price, the size, and how it resolved, with nothing you wrote and nothing identifying you attached. You can turn that off, and delete what has already been sent, in Settings.
What stays on your device
These are written to your browser’s local storage (IndexedDB and localStorage) and never leave it:
- Everything you write: your reasoning on a trade, what has to be true, what would change your mind, your retrospectives, and your journal.
- Your sources and who you attribute a trade to.
- Your Kalshi API key. It is stored locally and used to sign requests in your browser; the private key is never sent to our servers.
Because this data lives in your browser, clearing your browser data or switching devices will lose it unless you have exported a backup or subscribed to cloud backup.
What we store on our servers
Only these, and only in the circumstances described:
- A de-identified record of each trade, unless you turn it off in Settings. Each record contains the market ticker, its category, which side you took, the price you paid, the number of contracts, the fees, when you opened and closed the position, how it settled, and the resulting profit or loss. It also records whetheryou wrote a thesis or attributed a source — as a yes or no, never the text. It carries a random identifier generated by your browser, which has no link to your email, your account, or the identifier used for usage statistics. We use it to study how prediction markets are traded. It is never sold.
We call this de-identified rather than anonymous, and the difference matters: a real market ticker and an exact timestamp are specific enough that someone holding Kalshi’s public trade history could in principle match records back to one trader. Nothing on our side connects them to you, and you can turn this off and delete everything already sent, at any time, from Settings. - Your email address, if you join the waitlist or create an account. Accounts also store a password, which is hashed by our authentication provider and never visible to us.
- Subscription records, if you subscribe: your Stripe customer and subscription identifiers, the subscription status, and the current billing period end. We never receive or store your card number.
- A cloud backup of your Chad data, only if you subscribe and cloud backup runs. This is a copy of the same data described above. It is stored so that it is only readable by your own account. It is not end-to-end encrypted, which means we have the technical ability to read it; we do not do so except where strictly necessary to operate or debug the service.
- A published track record, only if you explicitly enable publishing. This is deliberately public: it contains resolved trades and summary accuracy, and no written reasoning. You can delete it from Settings at any time.
- Anonymous usage statistics, unless you turn them off in Settings. These are tied to a random per-browser identifier, not to your email or account, and contain no trade content.
Who else is involved
We use a small number of processors to run the service. Each receives only what it needs:
- Supabase — accounts, authentication, and the server-side records listed above, including the de-identified trade records.
- Stripe — payments and subscription billing. Stripe handles your card details directly; we never see them.
- Vercel — application hosting.
- Kalshi and ESPN — queried to price markets and resolve outcomes. Requests to Kalshi are signed with your own key.
Your choices
- Export everything, at any time, from Settings — a plain JSON file you keep.
- Turn off de-identified trade records in Settings, and delete every record already sent from this browser with one button.
- Turn off anonymous usage statistics in Settings.
- Delete a published track record from Settings.
- Delete your account and everything stored with it by emailing support@chad-brain.com. Deleting the account also deletes the cloud backup and subscription record tied to it.
Cookies
Chad sets a cookie to keep you signed in, and — while the app is in private beta — a cookie recording that you were let through the pre-launch gate. There are no advertising or cross-site tracking cookies.
Contact
Questions about this policy, or about data we hold: support@chad-brain.com. See also our Terms and Refund Policy. Chad is operated from the United States at chad-brain.com.