Trust surface
Privacy
Effective 31 July 2026
What is processed
For an OPEN market lookup or bounds preview, Conviction processes the market reference, selected outcome, total risk budget, and maximum price. A final OPEN card also processes the public Polygon deposit-wallet address and an optional note. For Position Manager, Conviction processes the selected CLOSE or TAKE_PROFIT action, market, outcome, an exact V2-aligned CLOSE quantity or whole-share TAKE_PROFIT quantity, minimum or target price, any TAKE_PROFIT venue expiry, seller address, optional note, and prior OPEN source. It independently re-fetches that source settlement and reads public balance, approval, order, trade, and Polygon receipt data needed for the selected action and proof.
What the application does not request
Never submit a seed phrase, private key, bearer token, CLOB credential, reusable trade signature, or raw trade transaction to a hosted Conviction endpoint. In the browser OPEN and CLOSE flows, the connected buyer wallet signs setup, x402 payment, and trade messages locally and broadcasts only the buyer-approved transactions; the bounded x402 payment authorization is sent to Conviction only for payment settlement or reconciliation. Transient Polymarket credentials and executable signed orders remain in browser memory and are not sent to Conviction. Immediately before a browser OPEN submission, the hosted attempt endpoint receives only the unsigned public order fields and a short-lived Owner-EOA authorization binding their hashes to the settled payment and issuer-signed card. It never receives the order signature or CLOB credentials. The public agent/CLI likewise keeps the buyer's separate trade confirmation, credentials, and official-plugin execution on the buyer's machine.
Storage and infrastructure
Conviction has no user accounts, cookies, advertising tracker, or third-party analytics SDK. It may use an isolated first-party operational activation store to count coarse pre-payment refusals and buyer-terminal reports, and to deduplicate issuer-verified signed-card response deliveries and successful proof verifications. A paid-card delivery event proves only that the server returned a trusted issuer-signed response after settlement; it does not prove that a buyer browser received, persisted, or executed that card. Verified event identifiers are HMAC-pseudonymized with domain separation; browser terminal reports are explicitly untrusted diagnostics and are retained only as identifier-free daily counters. These short-lived activation records expire after 31 days. The activation store never receives or persists raw wallet addresses, transaction, proof, or order hashes, market references, selected market outcomes, budgets, rationale, IP addresses, user-agent strings, request bodies, or CLOB data. It is credential- and database-isolated from wallet setup, payment-entitlement, and execution-control safety state.
The public previews and verifiers temporarily retain an IP-shaped client identifier and request count in a warm server instance to limit abuse; those buckets are bounded and are not written to the activation store. Buyer-side reconciliation journals and authenticated CLOB credentials stay on the buyer's machine and are never submitted to a hosted Conviction endpoint. When a buyer moves from preview to Wallet Center, the selected market, outcome, budget, and cap may be kept in that tab's session storage for up to 60 minutes so setup can continue with the same trade; an active tab removes it at expiry, a browser-suspended tab removes it on resume, and a successful OPEN removes it immediately. If the buyer signs an exact pUSD transfer in Wallet Center, the browser stores that one-call signed request, its short-lived consent capability, exact source, destination, and amount in local storage until the exact Polygon transfer is confirmed. Session-bound relayer poll capabilities are not persisted; after re-authentication, the same nonce-bound request recovers a fresh status capability without another signature or transfer. This recovery record cannot approve a venue, change the destination or amount, pay Conviction, or place a trade; it exists so a reload cannot prompt a second transfer. That local record is a browser recovery cache, not proof that no transfer exists: after submission, the relayer's bound transaction record and Polygon are authoritative. Clearing site data or changing browser profiles removes local discovery only, so the buyer must not infer that an interrupted transfer failed or sign a replacement until the original status is resolved. During a browser CLOSE, Conviction stores the exact bounded request, signed manager card, X Layer payment transaction, bounded EIP-3009 payment authorization, deterministic signed-order ID, exchange address, Polygon scan-start block, and any Polygon settlement reference in local storage and a same-tab session-storage fallback. It does not store the order signature or CLOB credential. That recovery record is isolated by owner, Deposit Wallet, and source proof; a completed or explicit zero-fill action leaves only a terminal replay tombstone through the four-hour manager recovery window, while an unresolved payment or submission remains fail-closed. Before durable browser OPEN activation, a settled legacy OPEN payment can refresh the same request for no more than 60 minutes. After activation, the payment-entitlement safety store keeps the exact paid card only through its five-minute issuer window and permanently retains a narrow anti-replay record once the browser binds that payment to an order attempt. That record contains the public payment transaction, payer/Owner and Deposit Wallet addresses, request, card, intent, issuance, order, and binding hashes, plus consent and authorization timestamps. It contains no rationale, executable order signature, CLOB credential, payment authorization, IP address, or user-agent string. The permanent record is necessary to stop a later browser or rolled-back local checkpoint from using the same payment for another order. A settled Position Manager payment can refresh its exact source-and-bounds request for no more than four hours. Every refreshed card still expires after five minutes and still requires separate trade confirmation. After a completed browser OPEN, Conviction stores up to 20 public position dossiers per owner EOA and Deposit Wallet in that browser's local storage. A dossier can include both public wallet addresses, market and outcome, optional rationale, payment/fill/order hashes, the issuer-signed OPEN intent, and public proof data. Use “Clear saved positions” in Portfolio to remove that wallet pair's saved dossiers, or clear Conviction site data in the browser; exported files must be deleted separately. Hosting, x402 facilitation, Polymarket APIs, and Polygon RPC infrastructure may retain ordinary request, operational, or payment logs under their own policies. A successful paid OPEN or Position Manager notification contains only fixed settlement metadata—service name, amount, network, transaction hash, and time—not the wallet, note, source proof, or request body.
Contact
For a privacy or deletion inquiry, contact @Emini_qdee on X and identify the approximate request time. Conviction cannot delete records controlled solely by third-party infrastructure providers.