Overview
At Nyotam, privacy is part of trust. We are transparent about the data we handle and we keep collection to what is necessary to operate the Services — running prediction markets, securing accounts, and improving the product. This policy applies to everyone who uses Nyotam.
How your data is protected
Your data is encrypted in transit, stored on managed, access-controlled infrastructure, and isolated per-user by database-level security rules so members can only ever read their own private records. We never sell your personal data.
Information We Collect
We collect the following categories of information, in each case only as needed to provide and protect the Services:
- Profile information
- Your display name, avatar, and optional details you add to your profile.
- Account information
- The phone number or email associated with your account and your basic account status.
- Authentication data
- Credentials and tokens used to sign you in securely — for example via phone or a provider such as Google. We never see your provider password.
- Prediction activity
- The markets you participate in, the positions you take, and your forecasting history.
- Market participation
- Aggregate signals such as which markets you follow and your standing on leaderboards.
- Comments & user content
- Comments, replies, and other content you post on the platform.
- Analytics events
- Privacy-conscious product events (for example, pages viewed or actions taken) used to understand and improve the experience.
- Device information
- Technical details such as browser type, device, and approximate region, gathered to keep the platform secure and working correctly.
As wallet and payment features roll out, we may also process transaction records and limited payment metadata needed to complete deposits and withdrawals. We will update this policy before those features collect new categories of data.
How We Use Data
We use the information we collect to:
- Create and secure your account and authenticate your sign-ins.
- Operate prediction markets — recording your positions and resolving outcomes fairly.
- Display profiles, comments, leaderboards, and other community features.
- Detect and prevent fraud, manipulation, spam, and other prohibited activity.
- Understand product usage through analytics so we can improve the experience.
- Communicate with you about your account, important changes, and (where you opt in) updates.
- Comply with legal obligations and enforce our Terms of Service.
Data Retention
We keep personal data only for as long as it is needed for the purposes described in this policy, or as required by law.
- Account and profile data is retained while your account is active.
- Prediction and market records may be retained for integrity, leaderboard accuracy, and audit purposes.
- When you delete your account, we remove or anonymise your personal data, except where we must retain limited records to meet legal or fraud-prevention obligations.
Security
Protecting your data is a priority. We apply layered safeguards across our infrastructure and application:
Encryption
Data is encrypted in transit using industry-standard TLS, and stored on managed infrastructure that encrypts data at rest.
Access controls
Database-level row security ensures members can only access their own private records. Internal access to systems is limited to what is necessary and is monitored.
Authentication safeguards
Sign-in is handled by a trusted authentication provider, with sensitive operations protected by server-side checks and rate limiting to defend against abuse and account takeover.
No system is perfectly secure. If we ever become aware of a breach affecting your data, we will act promptly and notify affected members as required by law.
Your Rights
You have meaningful control over your data. You can:
- Access your data. Review the information associated with your account.
- Update your profile. Edit your display name, avatar, and profile details at any time from your settings.
- Request account deletion. Ask us to delete your account and associated personal data.
- Request data removal. Ask us to remove specific content or data, subject to legal and integrity requirements.
- Manage communication preferences. Choose which notifications and updates you receive.
To exercise any of these rights, use the controls in your profile settings or contact us using the details below. We may need to verify your identity before acting on a request.
Third-Party Services
We rely on trusted service providers to run Nyotam. These providers process data only on our instructions and for the purposes below. As the platform grows, this list may expand — we will keep it current.
- Supabase
- Our managed database, authentication, and storage infrastructure — the backbone of accounts, markets, and security rules.
- Google Authentication
- Optional sign-in with a Google account. We receive basic profile information, never your Google password.
- Google Analytics
- Privacy-conscious product analytics used to understand usage and improve the experience.
- Flutterwave
- Planned payment processing for future wallet, deposit, and withdrawal features.
- Email providers
- Used to send account, security, and (where you opt in) product communications.
- Push notifications
- Optional alerts about market activity and account events, delivered through a push service.
Changes to This Policy
We may update this Privacy Policy as the platform evolves or as legal requirements change. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you within the product. Continued use of Nyotam after changes take effect means you accept the updated policy.
Contact
Questions about your privacy or this policy? Reach out and we’ll help.
Our commitment
We collect only what we need, protect it carefully, and give you control over it. Privacy isn’t a setting on Nyotam — it’s part of how the platform is built.