Privacy Policy — Mispria Chrome Extension
Last updated: August 13, 2026 · applies to extension version 4.x
This policy covers the Mispria browser extension only. The website is covered by our site privacy policy.
1. What the extension is
A side panel that displays analytics for cryptocurrency Up/Down prediction markets: our model's probability next to the market's price, implied versus realized volatility, and a multi-exchange spot composite. It is a read-only analytics tool. It cannot trade, place orders, hold funds, or access any wallet.
2. What stays on your device
- Display settings — which cards are collapsed, your chosen venue and asset, toggles. Stored locally, never sent anywhere.
- Your Mispria session — when you are signed in on mispria.com, the extension reads the session cookie that page already set and keeps a copy in the browser's local extension storage, so you do not have to sign in twice. It includes your session token and the e-mail address of your account.
- Market data being displayed — prices, the page title of the market you have open, and the numbers currently on screen. Held in memory to draw the panel and discarded.
3. What leaves your device
- Your session token → mispria.com servers. To show Pro metrics we open an authenticated connection to
wss://edge.mispria.comand send the session token so the server can confirm the account and that the subscription is active. The same token is used to read your plan from our database. We do not store the token server-side; it is verified and discarded. This is the only personal data the extension transmits. - Market queries → third-party market APIs. Price and volatility requests go directly from your browser to Polymarket, Kalshi, Binance and Coinbase public read-only endpoints. We are not an intermediary and receive nothing from them. Those services see the request as they would any visit to their site, including your IP address; their own privacy policies apply.
If you are signed out, or using the free tier, the extension transmits no personal data at all — it computes the model locally in your browser.
4. What we never do
- No advertising, no advertising identifiers, no third-party analytics or tracking SDK.
- We never sell or transfer your data to anyone, and never use it for any purpose unrelated to the single purpose of the extension.
- No browsing history collection. Content scripts run on exactly two sites — polymarket.com (to read the open market) and mispria.com (to read your session). Every other tab is invisible to the extension.
- No keystroke, form, password, or payment data is read. Card details never touch the extension or our servers — payments happen on the website, through Stripe.
- Nothing is used to assess creditworthiness or for lending purposes.
5. Permissions, and why each one exists
sidePanel— draw the panel itself.tabs— read the URL of the active tab to detect which market you are looking at. Used to match a market address; not logged, not transmitted.scripting— load the two content scripts into tabs that were already open when the extension was installed or updated, so you do not have to reload.storage— keep your display settings and signed-in session locally.polymarket.com— read the market title and on-screen prices as a fallback when the API is unavailable, and read the official opening price.gamma-api.polymarket.com,clob.polymarket.com— market metadata and order-book prices (read-only).api.binance.com,api.exchange.coinbase.com— one-minute candles used to compute realized volatility (read-only, public).api.elections.kalshi.com— Kalshi market prices (read-only, public).mispria.com— read your session cookie so signing in on our site signs you in to the extension.*.supabase.co— our database endpoint, used to read your own subscription status with your own token, protected by row-level security.
6. Retention and deletion
The session copy lives on your device until you sign out, clear browser data, or uninstall the extension — removing the extension removes it. Server-side, the account and subscription records are covered by the site privacy policy, and you can delete your account or write to us at any time.
7. Who we are
The data controller is GuideMyGuest OÜ (registry code 17284496), Sakala tn 7-2, Kesklinna linnaosa, 10141 Tallinn, Estonia — operator of the Mispria product. Questions or data requests: contact@mispria.com.
8. Changes
If a future version changes what the extension collects, this page is updated before that version ships, and the date at the top changes with it.
Mispria is a data-analytics tool — not financial advice, not trading signals, and not a trading venue. For users aged 18 and over.