Privacy Policy
What we don't collect
We don't ask you to create a TopK account or provide a name or email address. We don't run third-party advertising or analytics trackers, and we don't sell data to advertisers. We never receive your wallet seed phrase or private key. Public wallet addresses, public Polymarket profile information, and the room data described below are exceptions to “no profile information”: they are needed when you connect or use multiplayer.
How the apps and providers work
UP / DOWN, UP / DOWN RACE, Solo, and Race run primarily in your browser. Depending on the market and screen, your browser may contact Polymarket services (Gamma market metadata, CLOB books and orders, the Data API, public profiles, the relayer, Polygon RPC, and the one-time geographic-restriction check), Binance and Hyperliquid market-data services, the National Weather Service, Open-Meteo, Kalshi, and sports or economic-data providers. These providers receive ordinary request data such as your IP address, user agent, requested resource, and timing, and handle it under their own policies.
The trading SDK and its browser dependencies are bundled and served by TopK from content-hashed same-origin files. The exact versions and integrity hashes are locked at build time, and a software bill of materials is included with each web release; the trading pages do not execute packages from a public JavaScript CDN.
Our server also retrieves or relays data from third-party providers' endpoints. In those cases the provider generally sees our server request rather than a direct request from your browser. Sources can change as features evolve.
Wallets and trading
When you choose to trade, you connect your own wallet. Trade authorization and order signing happen in your browser; we never receive your private key. The apps read your public wallet address, Polymarket account wallet, public username/avatar, balance, positions, entry prices, trades, and P&L so they can submit orders and keep the display reconciled with the venue.
To use TopK's Polymarket builder credentials, our server issues a nonce, receives a wallet signature over a narrow authorization statement, and returns a short-lived bearer token. The server then sees the builder-sign request envelope and returns builder authentication headers. It retains the challenge/token state in memory for a short period and does not receive the wallet key that produced the signature. Funds and positions remain on Polymarket / the blockchain, not with us.
Data stored in your browser
Polymarket L2 API credentials default to sessionStorage, so they normally disappear when that tab session ends. They are namespaced by environment, chain, connected EOA, Polymarket trading wallet, and SDK schema version. You may explicitly opt in to remembering them in localStorage on that device, and every trading page includes a control to clear wallet data and disconnect. These credentials can authenticate CLOB API requests; they are not your wallet private key, but they are sensitive and any script executing in the TopK origin could read them. The apps also store a namespaced app trade ledger (token/market, side, size or value, price, time, and order ID) in localStorage for local activity statistics. Race invite links keep a random participant capability in the page URL fragment, while the room creator's separate admin capability stays in sessionStorage. Clearing wallet data or site data removes the applicable browser records.
Multiplayer and chat
UP / DOWN RACE and Race send room data to our shared relay. Depending on the app and whether you connected a wallet, other authorized room participants may receive your Polymarket username or session identifier, position sides and share counts, average entry prices, realized and mark-to-market P&L, and recent trades. This information is therefore not anonymous within the room. Do not join a room if you do not want its participants to see those details.
Chat messages, display names, room settings, proposals, market selections, and race state are also sent to the relay and broadcast to room participants. The relay keeps up to 100 recent chat messages in memory for late joiners and deletes the in-memory room state when its last connection leaves; it does not intentionally write room chat to a database. Anyone holding the room's participant capability can join and receive the current room state, so protect shared links.
Server logs & cookies
Like most websites, our server and hosting stack may keep short-lived operational and security logs such as IP address, timestamp, requested path, response status, rate-limit events, and service errors. We use no advertising or cross-site tracking cookies. Any cookie introduced for a functional feature will be used only for that purpose.
Children
TopK.trade is not directed to children and is intended only for adults who are legally permitted to use prediction markets in their jurisdiction.
Changes
We may update this policy; material changes will be reflected by the "last updated" date above.
Contact
Questions about privacy? Reach us at hello@topk.trade.