Privacy Policy

Effective date: July 20, 2026

This Privacy Policy explains what information Kalshi MCP collects when you use our hosted Model Context Protocol service — our website, your dashboard, and the connection that lets your AI assistant act against your own Kalshi account — and how we use, share, secure, and retain that information, along with the choices and rights you have. Kalshi MCP is a paid, hosted software-access service; it is non-custodial and is not a broker-dealer, futures commission merchant, or investment, financial, legal, or tax adviser.

1. Introduction, Scope, and Our Role as Controller

This Policy applies to information Kalshi MCP collects when you visit our website, sign in to the dashboard, or use the connection between your AI assistant and your own Kalshi account. By using the service you agree to the practices described here.

For the account, identity, billing, and usage data we collect to run the service, Kalshi MCP acts as the data controller — we decide why and how that information is processed. We are not, however, the controller of the information that lives inside your Kalshi account or of your trading and settlement records on the exchange. Kalshi (KalshiEX LLC) is a separate, independent controller of that data, and its own privacy practices govern it.

This Policy does not cover how Kalshi handles data on the exchange, how your chosen AI client or model provider (for example, Anthropic, OpenAI, or the maker of your IDE or chat app) handles your prompts and conversations, or how any third-party website we link to handles your data. Each of those parties operates under its own privacy policy, and we encourage you to read them.

2. Information We Collect

Account and identity data. When you sign up and sign in, our authentication provider (Clerk) collects and processes your name, email address, and the authentication identifiers tied to your login (including any OAuth identity you use to connect an MCP client).

Trading credentials you provide. To connect your AI assistant to your own Kalshi account, you voluntarily supply your Kalshi API key ID and the corresponding RSA private key. These are sensitive credentials, and we treat them as a distinct, specially protected category of information. How we secure them is described in Section 4.

Usage and metering data. As you use the service we record operational events in our application database (Convex): which tools and prompts you invoke, when, how long each call takes, whether it errored, which usage meter it consumed, and whether a call was allowed or blocked by your plan limits. We also record the MCP clients you connect (an entry per connected OAuth client, including a best-effort client name, scopes, and first/last-seen timestamps) and per-period quota counts. Order proposals you run through the service are captured as part of this tool-call activity.

Billing data. When you subscribe, our payment processor (Stripe) handles your payment. We keep a local mirror of your billing state — your plan tier, subscription status, billing period, and the Stripe customer and subscription identifiers — so we can apply your plan at request time. We do not receive or store your full card number; card data is handled entirely by Stripe.

Technical data. Like most online services, we and our providers automatically receive technical information such as your IP address, basic device and browser details, and server log data, used for security, debugging, and reliability.

3. How We Use Your Information

We use the information we collect to operate the service for you and for no unrelated purpose. Specifically: we use your account and identity data to authenticate you and maintain your session; we use your Kalshi credentials solely to connect your AI assistant to your Kalshi account and to relay the order proposals you approve (see below); we use usage and metering data to enforce your plan limits, meter consumption, and bill you; we use billing data to process payments and manage your subscription; and we use technical and usage data to provide support, secure the service, detect and prevent fraud and abuse, comply with our legal obligations, and improve the reliability of the product.

Your trading credentials are used exclusively server-side, and only to sign and send to Kalshi the order proposals that you have expressly approved. They are not used for any other purpose, not used to profile you, and never used to act on your account except as you direct.

We tie each category of data to the narrow purpose above so that we hold and use only what we need to run the service (the principle of purpose limitation). We do not sell your personal information.

4. How We Protect Your Kalshi Credentials

Your Kalshi credentials receive the strongest protection in the service, and we describe their handling precisely rather than in generalities.

When you provide your Kalshi API key ID and RSA private key, they are encrypted at rest before storage using the Iron sealing library: AES-256-CBC encryption, HMAC-SHA-256 integrity verification, and PBKDF2-based key derivation. The encrypted blob is stored in your authentication provider's private metadata (Clerk private metadata), which is accessible only to our backend and is never returned to any browser or client.

Your credentials are decrypted only in-request, on our server, and used exclusively to sign the API requests we make to Kalshi on your behalf for the orders you approve. They are never transmitted to, exposed to, or readable by your AI assistant or its model provider, and they are never shared with any party other than Kalshi for the purpose of carrying out the orders you approve.

You can delete your stored credentials at any time from the dashboard. Deleting them removes the encrypted credential blob from your stored metadata and severs the connection between Kalshi MCP and your Kalshi account; no further orders can be placed until you reconnect. We may also suspend or revoke a stored credential for security reasons, for example if we detect suspected compromise or misuse.

5. Non-Custodial, No-Advice, and Trading-Liability Notice

We restate here, for clarity, the core nature of the service described more fully and bindingly in our Terms of Service. Kalshi MCP provides software access only. It is not a broker-dealer, futures commission merchant, introducing broker, exchange, or investment, financial, legal, or tax adviser, and nothing it or your connected AI outputs — including data, summaries, drafted orders, or computed settlement, profit-and-loss, or tax-style figures — is financial, investment, legal, regulatory, or tax advice, an offer or solicitation, or a recommendation to transact.

The service is non-custodial. We never hold, receive, control, or have the ability to withdraw your funds or positions. Every trade executes inside your own Kalshi account under your own credentials. Your AI assistant only proposes orders; no order reaches Kalshi unless and until you expressly approve it, subject to any order-size safety limits you configure. Those limits are a convenience feature, not a guarantee against loss.

You are solely responsible for your trading decisions and their outcomes. We are not liable for trading losses, market behavior, missed, delayed, or executed orders, or any other trading result. Your eligibility, the suitability of any contract, and your conduct on the exchange are governed by Kalshi's own terms and by applicable CFTC regulation of Kalshi — none of which extends to or regulates Kalshi MCP.

This notice appears here for transparency; the enforceable allocation of trading risk and liability lives in the Terms of Service, which control.

6. Legal Bases for Processing (GDPR)

Where the EU or UK General Data Protection Regulation applies, we rely on the following legal bases. Performance of a contract — to provide and bill the service and to use the credentials you supply so your approved orders can reach Kalshi. Our legitimate interests — to keep the service secure, prevent fraud and abuse, and improve reliability, balanced against your rights. Consent — for any non-essential processing such as optional analytics, which you may withdraw at any time without affecting processing that already took place. Compliance with legal obligations — for example, retaining billing records as tax and accounting law requires.

7. Subprocessors and Parties We Share Data With

We share data only with the service providers needed to operate Kalshi MCP, and only the data each one needs. Clerk provides authentication and identity management and stores your encrypted Kalshi credentials in private metadata. Convex is our application database and records usage and metering data, connected-client records, and your local billing-state mirror. Stripe processes your payments and holds your payment-method data. Vercel hosts the application and processes the technical and log data inherent in serving requests.

Kalshi is the exchange that receives and executes the orders you approve; the API requests we sign with your credentials are sent to Kalshi for that purpose.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. Our subprocessors operate under data-protection contracts that limit their use of your data to providing services to us. The current list of subprocessors above is kept up to date; an updated list is available on request.

8. Data Security

We use administrative, technical, and organizational safeguards designed to protect your information. These include encryption in transit (TLS) for data moving between you, us, and our providers; encryption at rest for your stored Kalshi credentials as described in Section 4; access controls that limit credential access to our backend; per-user isolation of stored data; and operational practices such as keeping user identifiers out of application logs.

You also play a part in security. You are responsible for safeguarding the login to your AI client and to your Kalshi MCP account, for the scope of API permissions you grant on Kalshi, and for promptly notifying us at support@kalshi-mcp.com (or through our contact form at https://kalshi-mcp.com/contact) if you suspect any unauthorized access or compromise.

No method of transmission over the internet or of electronic storage is completely secure. While we work to protect your information, we cannot guarantee absolute security.

9. Data Retention

We retain your information only as long as we need it. Your account and identity data is kept while your account is active and for up to 18 months after you close it (to handle disputes, security, and reactivation), after which we delete or anonymize it. Usage and metering data is retained for up to 24 months. Billing and transaction records are retained for at least seven (7) years to meet our tax, accounting, and other legal obligations.

Your stored Kalshi credentials are retained only until you delete them from the dashboard or close your account, at which point the encrypted credential blob is removed from active systems immediately and purged from backups within 90 days, severing the connection to your Kalshi account.

Self-service deletion of your stored credentials is available today; broader self-service deletion of an entire account and its associated usage history is in progress, and in the meantime you can request account deletion as described in Section 10.

10. Your Privacy Rights

Depending on where you live, you have rights over your personal information. Under the GDPR (and similar UK and EEA law) you may request access to your data, correct inaccurate data, request erasure, restrict or object to certain processing, request portability of data you provided, withdraw consent where we relied on it, and lodge a complaint with your data protection supervisory authority.

Under the CCPA and other US state privacy laws, you may request to know what we collect about you, request deletion or correction, and opt out of any sale or sharing of your personal information. We do not sell your personal information or share it for cross-context behavioral advertising, and we will not discriminate against you for exercising your rights. Where required, we honor the Global Privacy Control browser signal as an opt-out request.

To exercise any of these rights, contact us at support@kalshi-mcp.com or through our contact form at https://kalshi-mcp.com/contact. You can also delete your stored Kalshi credentials yourself at any time from the dashboard; until full self-service account deletion is available, we will process account- and data-deletion requests you send to that address. We will respond within the timeframes the applicable law requires, and we may need to verify your identity before acting on a request.

11. Cookies, Sessions, and Analytics

We use strictly necessary cookies and similar technologies to authenticate you and maintain your signed-in session; without these the dashboard cannot function. We may use limited, privacy-respecting analytics to understand how the dashboard is used so we can operate and improve it.

When you arrive through a campaign link containing UTM parameters, we keep those campaign labels in session storage until that browser tab closes and attach a compact source/campaign label to limited setup and conversion events. We do not join that campaign label to your account identity, and campaign links must not contain names, email addresses, account IDs, or other personal information.

We do not use third-party advertising cookies or build advertising profiles from your activity. You can control or block cookies through your browser settings, though disabling strictly necessary cookies may break sign-in. Where required, we honor Global Privacy Control and similar opt-out signals.

12. Age Requirement (18+)

Kalshi MCP is intended only for adults aged 18 or older who meet Kalshi's eligibility requirements and are located in a jurisdiction where Kalshi trading is permitted. This is a hard requirement tied to Kalshi's eligibility rules, not merely the minimum age for general web services.

The service is not directed to children. We do not knowingly collect personal information from anyone under 18, and if we learn that we have done so, we will delete that information.

13. International Data Transfers

Kalshi MCP and the subprocessors that run the service are based in the United States. If you use the service from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your country.

For transfers of personal data from the EEA, the United Kingdom, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum and the Swiss equivalent where applicable. Where a subprocessor is certified under the EU-U.S. Data Privacy Framework (and its UK Extension and the Swiss-U.S. DPF), we may additionally rely on that certification. We confirm each provider's current certification before relying on it.

14. Changes to This Policy

We may update this Policy from time to time. When we do, we will revise the "last updated" date shown on the page and, where the change is material or the law requires, notify you by email or through the dashboard.

Your continued use of the service after an update takes effect means you accept the revised Policy.

15. Contact Us

If you have questions about this Policy, want to exercise your privacy rights, or wish to report a concern, contact us at support@kalshi-mcp.com or through our contact form at https://kalshi-mcp.com/contact. Matters relating to this Policy are governed by the laws of the State of Delaware, consistent with our Terms of Service.