Privacy Policy
Last updated: 2026-08-21
Who is responsible
Data controller: Not yet stated — TailMyPicks is not yet registered as a business.
Contact: the contact address, which is not published yet
This policy covers the tailmypicks.com website and everything served from it.
What we deliberately do not collect
This list comes first because it is the part that took work. None of the following is recorded by this application, anywhere, for any visitor:
- No IP address. Not in the checker, not in any usage counter. Abuse is bounded by rate limiting, which does not require keeping one.
- No user agent and no referrer. Which browser you use and which page sent you here are not written down.
- No advertising or analytics third party. No tracking pixel, no fingerprinting, no third-party script of any kind. If that ever changes, this list changes first.
- No wallet connection. TailMyPicks never asks you to connect a wallet or to sign anything, and could do nothing with it if you did.
What we collect today
There are no accounts yet, so this is a short list and it is the whole of it. When you open a wallet’s page, we write down three things:
- The wallet address you looked at, which is a public identifier on a public blockchain, and the date and time.
- Which of our four answers you were shown — a record, a wallet we rebuilt that scores nothing, an address we have never seen, or a mistyped one. We want to know whether the second answer is the one people actually reach, because it is the one this product is for.
- A random number identifying your browser, kept in a cookie on this site for thirteen months. It exists so that ten visits from one person do not read as ten people. It is generated at random, is not derived from anything about you or your device, and cannot be traced back to you by us or by anybody who obtained it. Clear your cookies and you are a new visitor, with nothing connecting you to the old one — we would rather undercount than identify you.
We do not ask your consent for that cookie, and this is why: it is used only to count visits to this site, by us, for us. It is not shared, not combined with anything else, not used to follow you anywhere, and its life is not extended each time you come back. Those are the conditions the CNIL sets for audience measurement that needs no banner, and meeting them was the design rather than the excuse.
Everything on the list above still holds while this happens: no IP address, no user agent, no referrer. And if you mistype an address, what you typed is not kept — we record that a typo happened and nothing about what it said.
The server that serves these pages keeps operational logs, as any web server does, for security and debugging. They are not used to build a profile of anyone and are not combined with anything else.
What we will collect when accounts exist
Stated in advance so it is not a surprise. It is a short list, and the design is already written down:
- Account data — your email address, a cryptographic hash of your password (we cannot read the password itself), your subscription status, and the reference our payment provider uses for you.
- Payment data — handled entirely by the payment provider. Card numbers never reach our servers and we never see them.
The wallet records are not data about you
TailMyPicks publishes the trading record of wallet addresses on prediction markets. Those records are computed from public blockchain activity and public interfaces. They are not data we collected from our users, and being a TailMyPicks user has no bearing on whether your wallet appears — the index was built from the markets, not from the audience.
Why we process it, and for how long
- Counting how many people use the checker, and how many come back — legitimate interest (GDPR art. 6(1)(f)). We cannot judge a feature we cannot measure, and this is the least we could measure and still know. Kept while the measurement is useful, which in practice means while it is being compared against a later period. The cookie itself expires after thirteen months and is never renewed, so after that a returning browser is a new one to us whatever the older rows say.
- Providing the service and your subscription — performance of a contract (GDPR art. 6(1)(b)). Kept while your account exists, deleted within 30 days of its deletion.
- Security, abuse prevention and server logs — legitimate interest (art. 6(1)(f)). Kept for a short operational period and not longer.
- Invoicing and accounting records — legal obligation (art. 6(1)(c)). Kept for the period French commercial law requires, which is ten years.
- Service emails such as a password reset — performance of a contract. No marketing email is sent without separate consent.
Who else touches it
Only the providers needed to run the service, and today that is one: Hetzner Online GmbH, which hosts the server and the database in the European Union.
When payments and transactional email are switched on, the providers doing that work will be named here before they are switched on, together with where they process data and under what transfer mechanism.
Your rights
You may ask for access to your data, its correction, its erasure, its portability, or a restriction of processing, and you may object to processing. We answer within one month. Write to the contact address, which is not published yet.
You may also lodge a complaint with the CNIL (cnil.fr) or with the supervisory authority in your own country.
Security
Passwords will be stored only as a slow cryptographic hash. Traffic is encrypted in transit. Payment details never reach our servers. Access to production data is limited to the operator. No system is perfectly secure; in the event of a breach affecting your data we will notify you and the authority as the law requires.