Skip to privacy policy

Bravado / Privacy

Your data. Your connections.

Privacy Policy — how information moves through Bravado, why we process it, and how you can manage access.

Effective September 18, 2026

1. Scope & contact

Bravado Trade (“Bravado,” “we,” “us”) is the company responsible for the services and information processing described in this policy. We provide prediction-market infrastructure, a trading terminal, developer APIs, analytics and AI integrations. This policy describes our handling of information across our website, the terminal, the developer Console, our account authorization services and our MCP server.

Contact support@bravadotrade.com for privacy questions or requests. If an organization provides your access, it may also control information associated with your membership and use of its account.

This policy describes Bravado's processing. Connected AI platforms, identity providers, payment providers, prediction-market venues and public blockchains have their own practices.

2. Information we process

  • Account and organization information. Email address, name or username if supplied, identity-provider identifiers, verification status, organization membership, role and product permissions. The terminal uses wallet and identity services; the developer Console uses a separate account system.
  • Wallet and market information. Public addresses, wallet associations, transaction hashes, orders, fills, positions, transfers and derived analytics such as profit and loss. Public wallet data can identify a person when combined with other information; public availability does not make it anonymous.
  • API and tool requests. Requested wallet or market identifiers, venue, time window, filters, SQL statements where that tool is used, and the results needed to answer the request.
  • Authentication and authorization records. Sessions, registered client information, consent, scopes, token-related records and connection revocation history. Authentication secrets are handled through the relevant sign-in or credential-management flow.
  • Usage, billing and security records. Request times, routes or tool names, response status, errors, request counts, data scanned, account or connection identifiers, subscription and invoice references. Hosting, security and diagnostics systems may process IP addresses, browser information and request or query logs.
  • Information you send us. Support messages and contact-form details, including name, email, company, Telegram handle and project information when supplied. An emailed tax report uses the recipient address, wallet, reporting year and generated report; the website's report-email flow also adds the email to a contact audience.

Our website uses Vercel Analytics, and account surfaces use cookies or similar session storage for authentication. The terminal also has error and performance monitoring integrations that operate when configured. Browser and network providers receive technical information needed to deliver pages, fonts and other assets.

3. How we use information

We process information to provide the service you use: maintain accounts, verify access, execute authorized trading actions in trading products, retrieve market data, calculate analytics, run permitted queries and deliver requested reports. We use usage records to enforce limits and calculate billing, and diagnostic information to investigate failures and protect accounts and infrastructure.

We also use information to answer support or sales inquiries, send requested or service-related communications, manage disputes, and meet applicable legal obligations. The purpose depends on the product and action; using the MCP integration does not authorize the trading terminal to act on your behalf.

4. AI & MCP connections

The Bravado MCP server at mcp.bravadotrade.com provides read-only analytics to clients such as ChatGPT and Claude. It cannot place or cancel orders, transfer funds or sign blockchain transactions.

Connecting an account uses OAuth through Bravado's authorization service. The client receives scoped access; mcp.read covers curated analytics and mcp.query covers guarded SQL. Bravado processes the inputs the client sends and returns results to that client. It does not request or retrieve your complete conversation history through these tools.

Anything included in a tool argument, including text inside SQL, reaches the service. Do not include passwords, API secrets, private keys, recovery phrases or unrelated personal information. The connected AI provider processes the results under its own policy and account settings; disconnecting Bravado does not remove copies already stored in your conversations.

5. Sharing & service providers

We share information with the recipients needed to deliver the requested service:

  • Your chosen integrations. AI clients receive requested tool results. Trading venues, wallet infrastructure and blockchain networks receive the data needed for actions you authorize in trading products.
  • Service providers. Hosting, databases, identity, security, analytics, email and payment providers process information for their functions. Our integrations include Vercel, DigitalOcean, AWS, ClickHouse, WorkOS, Privy, Stripe, Resend and Sentry, depending on the service. Website sales forms can use Google services. Not every provider receives every category of data.
  • Your organization. Authorized administrators can manage membership, permissions, connections and available usage or billing records.
  • Support and legal recipients. Authorized personnel and advisers can access information needed for support, security investigations, disputes or legal obligations. We may disclose information in response to a valid legal requirement.

Payments are handled through the payment provider's interface. Do not send payment-card details in MCP tool calls or support messages. Public community messages can be read by other members; use the support email for private account matters.

6. Retention

Retention depends on the record and purpose. Revoking a credential stops access; it does not automatically erase the account, usage history, billing records or public market data associated with it.

Retention periods and criteria by record category
RecordPeriod or retention criterion
OAuth accessAuthorization codes are valid for 60 seconds, access tokens for five minutes, and refresh tokens for 30 days with rotation on use. Expiration limits access, not the storage of related records.
Accounts and connectionsKept while needed to provide the account and manage access. Closure or deletion requests are reviewed separately; revoked connection records may remain for security and audit purposes.
Usage, invoices and audit historyKept for billing reconciliation, security, disputes and applicable recordkeeping obligations, including after disconnection where those purposes continue. These records are not subject to the token-expiration periods above.
Support and contact recordsKept to handle the inquiry and its follow-up. Contact-list removal and deletion requests can be sent to support; records needed to resolve an ongoing issue or meet a legal obligation may be retained.
Technical logs and backupsRetention follows the relevant system's operational and recovery cycle. There is no single published deletion period across these systems. Deletion from an active system does not imply immediate removal from every backup.
Public blockchain historyOn-chain records are persistent and cannot be erased by Bravado. Our historical analytics can continue to include public transactions independently of a Bravado account.

For categories without a fixed period above, we assess retention against the continuing service, security, accounting or legal purpose. Contact us to request deletion or ask about the period applicable to a particular record. We will explain any reason a request cannot be fully fulfilled.

7. Your controls & rights

  • Revoke access. Use the MCP connection controls in the Bravado Console and disconnect the integration in your AI client. Existing access tokens may remain usable for up to five minutes after revocation.
  • Manage credentials and membership. Revoke API keys and manage organization access through the Console where your role permits. Removing a local cookie signs you out locally; it is not an account-deletion request.
  • Request access, correction or deletion. Email support@bravadotrade.com. Depending on applicable law, you may also request a copy, restriction or objection to processing, or contact a data-protection authority.
  • Manage communications. Use an unsubscribe control where provided or ask support to remove you from contact lists. Necessary account and security messages are separate from promotional communications.

We may verify account ownership before acting on a request. We do not need your password or wallet recovery phrase for that verification. Legal obligations, unresolved disputes and records held independently by others may limit deletion; we explain relevant limitations when responding.

8. Security & processing locations

We use HTTPS, scoped authentication and access controls, with protected handling of credentials, to reduce unauthorized access. No system can guarantee absolute security. If you suspect unauthorized access, revoke affected credentials or connections and contact support.

Bravado and its providers may process information outside your country. The applicable processing locations and protections depend on the service and provider. You can contact us for information relevant to your account.

9. Policy updates

We update the effective date when this policy changes and provide additional notice where required for material changes. Product-specific notices may provide further information at the point of collection.

For questions about this policy, contact support@bravadotrade.com.