Privacy policy
Last updated 31 August 2026
This explains what we collect, why, and what we never do. Short version: we collect the minimum needed to run your account, we don’t sell anything about you, and your exchange keys are encrypted and never shown again.
What we collect
- Your email address — to identify your account, verify it, reset your password, and send the alerts you asked for.
- Your password, hashed — stored one-way (PBKDF2). We cannot read it, and neither can anyone who steals the file.
- Your plan and billing status — what you subscribed to and whether it is active.
- Your settings — the markets and limits you choose.
- Basic technical logs — request times and errors, used to keep the service running and to investigate abuse.
Exchange API keys
If you connect a Kalshi account, your key ID and private key are encrypted at rest before being stored, and are never returned to your browser, never written to logs, and never shown again — the app displays only the last few characters so you can recognise which key is connected. They are used solely to check your balance and, once automated trading launches, to place the orders you have authorised. You can disconnect at any time from the Auto-Trade page, which deletes the stored keys.
Payments
When paid plans launch, card payments will be handled by a third-party payment processor. We never see or store your full card number. We keep only the plan, the status, and the processor’s reference.
Cookies
We use one cookie: a sign-in session token. It is HttpOnly (JavaScript cannot read it) and exists only to keep you signed in. If you tick “keep me signed in” it lasts 30 days; otherwise it clears when you close your browser. We do not use advertising or cross-site tracking cookies.
What we never do
- We do not sell or rent your personal information.
- We do not share your trading activity with anyone.
- We do not send marketing email you did not ask for.
- We do not use your data to train anything.
Who we share with
Only the services needed to operate: our hosting provider, our email delivery provider, and our payment processor. Each receives only what its job requires. We may also disclose information if the law requires it.
How long we keep it
Account data is kept while your account is open. If you close your account we delete your account record and any stored exchange keys. We may keep minimal billing records where the law requires, and anonymous, non-identifying performance statistics.
Your choices
You can change your email settings or password from your Account page, disconnect exchange keys at any time, and ask us to delete your account and data. Ask through the in-app helper and it reaches us by email.
Security, honestly stated
We hash passwords, encrypt exchange keys, restrict file permissions, and serve the site over HTTPS. No system is perfectly secure. If we ever discover a breach affecting your data, we will tell you promptly and plainly.
Children
Chamiko is not for anyone under 18, and we do not knowingly collect their data.
Changes
If we change this policy in a way that matters, we will email you or show a notice in the app before it takes effect.