Privacy Policy
How Mostly Right handles data across the hosted service, this website, and the browser extension: what we collect, why, who processes it, and the choices you have.
Last updated September 3, 2026 · Mostly Right Inc., Delaware
1. What we collect: the hosted service (app.mostlyright.md)
Account data. When you sign in with Google or GitHub we receive your name and email address from that provider. We do not receive your password. An organisation record is created for you automatically; you do not choose or see it.
Subscription data. Payment is processed byStripe. We do not receive or store your full card number. We hold the Stripe customer and subscription identifiers and your subscription status.
API key data. We store a peppered SHA-256 hash of your key, plus its prefix and last four characters for display. We cannot recover the key itself; this is why it is shown only once.
Usage events. Each Manifest fetch writes one row containing:
- a hashed key identifier
- a timestamp
- the catalog version served
- the SDK version that asked
We deliberately do not log IP addresses, user agents, or which individual data sources you query. The Manifest is served whole, so these records cannot reveal which sources interest you: a meaningful property if you trade on this data. We state this as a commitment: if it ever changes, we will update this policy and notify you before the change takes effect.
Server logs. §2 describes an export of our server request logs to PostHog. It covers every host we serve — mostlyright.md, app.mostlyright.md and api.mostlyright.md — so it reaches this application too. A requestauthenticated with an API key is exported as the route template, method, status and timing only: no address, no user agent, and no identifier of the table you asked for. Anonymous requests to the application are exported on the terms in §2.
Analytics and session recording. The signed-in application uses the same PostHog analytics and session recording described in §2, on the same terms: pages viewed, clicks, and a recording of how you move through the application. Text you type into form fields is replaced with masking characters before the recording leaves your browser. API keys, credentials, and sharing links shown on screen areblocked from recordings entirely — they are replaced with a placeholder, and their values never leave your browser. You can object to analytics and session recording at any time (§7).
Identification. Once you sign in we associate these analytics records with your email address, your account, and your workspace, including pages you viewed and recordings made on earlier visits from the same browser — including visits to the website before you had an account.
2. What we collect: the landing site (mostlyright.md)
Analytics. We use PostHog to understand how the site is used: pages viewed, button and link clicks, and form funnel steps. PostHog processes this data in the United States and derives an approximate location from your IP address. PostHog stores a random visitor identifier in cookies and localStorage on your device, so repeat visits from the same browser are linked to one visitor record.
Server logs. Our servers record each request's address, user agent, path and timing, and we export apseudonymised copy with the query string removed to PostHog (United States) to measure automated and AI-assistant traffic. A request that comes from a browser is exported withonly the network prefix of the address, never the address itself. A request from an automated client — anything not identifying itself as a browser — is exported with thefull address, because that is what lets us check a crawler's claim to be Google or OpenAI against the address ranges those operators publish. We export no cookies, no headers and no request or response bodies. It is kept for the analytics retention period in §6.
Session recording. We use PostHog session recording to watch how visitors move through the site. A recording captures the pages you view and how you interact with them: clicks, scrolling, and cursor movement. Text you type into form fields isreplaced with masking characters before the recording leaves your browser; the text itself never reaches us. You can object to analytics and session recording at any time (§7).
Forms you choose to submit. If you submit the early-access form we store your email address, the audience you selected, and, if you provide them, an organisation name and type, in Supabase.
Identification. If you submit the early-access form, we associate your email address with the analytics record of your visits from that browser, including pages you viewed and recordings made on earlier visits that share the same stored visitor identifier.
3. Why we process it
| Purpose | Data | Lawful basis (GDPR, if applicable) |
|---|---|---|
| Provide the Service | account, API key, subscription | Contract |
| Take payment | subscription, Stripe identifiers | Contract |
| Detect abuse, enforce quotas | usage events | Legitimate interests |
| Understand product usage | analytics, session recordings | Legitimate interests (see §2; object any time, §7) |
| Respond to enquiries | Legitimate interests |
4. Who we share it with
We use a small number of service providers (sub-processors) to operate the products. We do not sell personal data, and we do not share it with advertisers.
| Processor | What it gets | Where |
|---|---|---|
| PostHog | analytics events and session recordings; your email once identified (§1, §2) | US cloud (us.posthog.com) |
| Supabase | early-access submissions | US |
| Google Cloud | account data, usage events (Cloud Run, Cloud SQL, Secret Manager) | US |
| Stripe | payment and billing data | US |
| Google / GitHub | OAuth identity | US |
Each of these providers processes personal data on our behalf under its data processing agreement. We may also disclose information if required by law, or to protect our rights, users, or the public.
5. International transfers
Our infrastructure and sub-processors are in theUnited States. If you are in the EU, UK, or Switzerland, your data is transferred there. For those transfers we rely on the safeguards in our providers' data processing agreements, such as Standard Contractual Clauses (with the UK addendum where applicable) or the provider's EU-US Data Privacy Framework certification.
6. Retention
- account data: for the life of the account, then deleted within30 days of account deletion
- usage events: 24 months, then deleted or reduced to aggregate statistics
- billing records: as required by tax law (typically7 years)
- analytics events: 24 months
- session recordings: up to 90 days inside PostHog, then deleted automatically
- early-access emails: until you ask us to delete them, or the early-access program ends
7. Your rights
Depending on where you live you may have rights to access, correct, delete, port, or object, to withdraw consent, and to complain to a supervisory authority. To exercise them contactteam@mostlyright.md.
If you are a California resident, you may exercise your CCPA/CPRA rights (access, deletion, correction) at the same address. We do not sell personal data and do not share it for cross-context behavioral advertising.
8. Security
Data is encrypted in transit. API keys are stored only as peppered hashes. Database access is over private IP with no public interface. Secrets are held in Google Secret Manager, not in code.
9. Children
The hosted service and this website are not directed at anyone under 16, and we do not knowingly collect their data.
10. Changes and contact
We will post changes here with a revised effective date; material changes will be notified.
1111B South Governors Avenue, Suite 56114
Dover, DE 19904, US
team@mostlyright.md
The browser extension
Effective June 16, 2026
This part explains what the Mostly Right browser extension ("the extension", "we", "us") collects, why, and the choices you have. It is published byMostly Right Inc.
The extension has a single purpose: to show live and forecast weather data next to weather-related prediction markets on Kalshi and Polymarket. This part covers the extension only.
Summary
- The extension works without an account, and most of what it does happens locally in your browser.
- We collect pseudonymous usage analytics by default, including an approximate location derived from your IP address. This is not anonymous, it is never sold, and you can turn it off at any time in the extension's Settings.
- We collect your email address — and optionally a Telegram handle or phone number — only if you choose to submit a data-coverage request or sign up for notifications.
- We do not collect your trades, balances, payment details, passwords, browsing history, or the contents of the pages you visit.
E1. What we collect, and when
a) Usage analytics (on by default; opt-out available)
To understand how the extension is used and to improve it, we collect pseudonymous product-analytics events through our analytics provider,PostHog. These events record actions taken in the extension, for example: the extension was installed; the weather panel was shown; a covered or uncovered market was viewed; a forecast model was changed; the forecast detail view was opened; a coverage request or notification sign-up was made; or an error occurred.
Each event is tied to a pseudonymous identifiergenerated by our backend — not your name, and not credentials you provide. As part of receiving these events over the internet, PostHog derives an approximate location (such as country, region, and city) from your IP address, and the IP address isretained for this location analytics. Because IP-derived location is personal data, this analytics ispseudonymous with location — it is not anonymous.
Analytics events never include your email address, any free text you type into our forms, your Telegram handle or phone number, or the contents of any market page.
This is on by default and you can turn it off at any time: open the extension's panel, go to Settings, and switch off "Share usage data." When off, no further analytics events are sent.
b) Information you choose to give us (optional)
The extension never requires an account. If — and only if — you choose to use one of these features, we collect:
- Coverage requests ("Request data"): youremail address and the free-text description of the market or data you want, along with the market you were viewing.
- Notification sign-ups (waitlist): youremail address, and/or a Telegram handle, and/or a phone number, depending on how you ask to be notified, along with the market you were viewing.
This information is stored in our backend (Supabase) so we can respond to your request or notify you. We use it for that purpose only.
c) Information stored only on your device
Your preferences (temperature unit, selected forecast model, the forecast trend-line toggle, and your analytics opt-out choice) and short-lived caches of weather data already fetched for the open market are stored locally in your browser. This information stays on your device and is not transmitted to us. Your analytics opt-out is stored locally on a per-device basis and does not sync across your devices.
E2. What we do NOT collect
- No financial or trading data. Although the extension runs on Kalshi and Polymarket, it does not read or collect your trades, positions, balances, order history, or any payment information. It only identifies which weather market is on screen so it can show the matching weather data.
- No passwords or credentials.
- No browsing history. The extension detects in-page navigation only on Kalshi and Polymarket so it can refresh the panel for the market you're viewing; it does not record or transmit the pages you browse elsewhere.
- No page content. The current market page is read locally to identify the market and its weather station; that page content is not transmitted off your device.
- No health data, and no personal communications.
E3. Third-party weather data sources
To populate the panel, the extension's background service worker retrieves weather data from public sources: NOAA / National Weather Service aviation weather (aviationweather.gov), theIowa Environmental Mesonet(mesonet.agron.iastate.edu), Open-Meteo(open-meteo.com), and, for Polymarket, Polymarket's public market metadata API (gamma-api.polymarket.com) to map a market to its weather station.
These are outbound requests for weather and market-metadata only — we do not send your email, your form text, or your analytics identity to them. As with any web request, the receiving service necessarily sees the connecting IP address, and each provider's handling of that request is governed by its own privacy policy.
E4. Who we share data with
We do not sell your data, and we do not share it for advertising. We use a small number of service providers (data processors) strictly to operate the extension:
- PostHog — product analytics (the usage events and IP-derived location described in §E1a).
- Supabase — our backend, which stores the coverage requests and notification sign-ups you choose to submit (§E1b).
We may disclose information if required by law, or to protect our rights, users, or the public.
Limited use commitments
- We do not use your data for personalized advertising.
- We transfer data only for providing or improving the service, for legal or security reasons, or as part of a merger or acquisition.
- We do not sell your data.
- Human access to your data is restricted to what is necessary to operate, secure, and support the service.
E5. Your choices and controls
- Turn off analytics: Extension panel → Settings → switch off "Share usage data."
- Delete your saved contact: The extension's Settings include a control that clears the email/Telegram/phone contact saved for notifications, both locally and from our backend on a best-effort basis.
- Access, correction, or deletion: To request access to, correction of, or deletion of information associated with you (including coverage requests or notification sign-ups), contact us at team@mostlyright.md. Depending on where you live, you may have rights under laws such as the EU/UK GDPR or the CCPA/CPRA; we honor applicable requests.
- Uninstalling the extension stops all collection and removes locally stored preferences and caches.
E6. Data retention
We keep analytics data only as long as needed for product analysis, and contact information (email/Telegram/phone) for as long as needed to respond to your request or to send the notifications you asked for, after which it is deleted on request or when no longer needed. Locally stored preferences and caches remain on your device until you clear them or uninstall the extension.
E7. Children
The extension is intended for adults using prediction-market sites and is not directed to children. We do not knowingly collect personal information from children.
E8. International users
We operate from the United States, and information may be processed in the United States and other countries where our service providers operate. By using the extension you understand that your information may be processed in these locations.
E9. Changes to this policy
We may update this policy as the extension evolves. We will revise the "Last updated" date above and, for material changes, take reasonable steps to make the update noticeable. The Chrome Web Store listing's privacy disclosures will be kept consistent with this policy.
E10. Contact
Questions or requests about this policy or your data:
1111B South Governors Avenue, Suite 56114
Dover, DE 19904, US
team@mostlyright.md