Privacy policy
Updated
You do not need an account, an email address or a cookie to use SlateProof, and the site has no analytics, advertising or tracking scripts. A few settings stay on your own device. An optional account stores what this page lists, and nothing else.
- Sign-in needed
- No
- Cookies when signed out
- None
- Analytics, ads, trackers
- None
- Other companies loaded
- Google Fonts (typefaces)
- Exchange keys
- Only in your own browser
- Account data
- Never sold or shared
Last checked against the code on October 6, 2026. This is a plain-language description of what the software does, not legal advice.
What happens if I just visit?
Your browser asks the SlateProof server for pages, styles, scripts and data, so the server sees your IP address and what you request, as any web server must. SlateProof's own code does not log page views or build profiles, sets no cookie unless you sign in, and runs no analytics, advertising or tracking script. Servers and proxies can keep ordinary connection logs of their own; SlateProof has no analytics system that would use them. The site's Content-Security-Policy lets your browser load scripts only from SlateProof itself and connect only to SlateProof and the exchange APIs described below.
What does my browser remember?
The dashboard keeps your choices in your browser's own storage so they survive a reload. None of it is sent to SlateProof's server. You can remove all of it by clearing this site's data in your browser.
| Setting and key | What it holds |
|---|---|
Your stateedge.state | The state you picked in "Where you bet", so the page shows only the venues legal there. |
Venues you can useedge.accounts, edge.accountsKnown | Which sportsbooks and exchanges you switched on, and which venues the page knew about when you chose, so a new venue starts on only where it is legal. |
Promo kindsedge.promosOn, edge.promoOff | Whether promotions count for you at all, and which kinds you turned off. |
Promo filteredge.filter | The kind of promotion the promo list is filtered to. |
Sign-up offers doneedge.signedUp | The venues whose sign-up offer you marked as already claimed. |
Hidden movesedge.hidden | Moves you hid until tomorrow, with the time you hid them (ignored after 20 hours). |
Moves marked placededge.placed | Moves you marked as placed, with the time (only where bet tracking is on, which for now is the owner's own computer). |
Tax bracketedge.tax | The federal bracket you entered and whether you itemize, used only in your browser to show after-tax values. |
Arbitrage budgetedge.arbTotal | The total you set for one arbitrage. |
Alertsedge.sound | Whether the page plays a sound or shows a browser notification for a new lock, and the smallest lock that should alert you. The page does this itself while it is open; nothing is sent to a push service. |
Track-record settingsedge.recordStake, edge.recPeriod, edge.recFrom, edge.recTo | The bet size on the slider and the period you chose, including any dates you picked. |
For the length of one tab, the page also keeps this in session storage:
| Setting and key | What it holds |
|---|---|
What is openedge.front, edge.open | Which move is in front and which panels are open, so a refresh does not lose your place. Cleared when you close the tab. |
Which other companies are involved?
Google Fonts. Every page asks fonts.googleapis.com for a stylesheet and fonts.gstatic.com for the typeface files. Google therefore sees your IP address and browser details, as any host would. SlateProof sends a Referrer-Policy of same-origin, so your browser does not tell Google which SlateProof page you are on. Google's privacy policy covers what it does with the request. Serving the fonts from SlateProof's own server would remove this; that has not been done yet.
Exchanges, only if you connect one. When you connect a key, and when you point at or click a one-click button, your browser contacts that exchange's API directly: api.polymarket.us and gateway.polymarket.us for Polymarket US, and api.novig.com or api.paper.novig.com for Novig. They see your IP address and the request. Kalshi does not accept browser requests, so for Kalshi your browser talks to SlateProof's server, which relays the request (see below). Each exchange's own privacy policy applies to what it receives.
PropLine. SlateProof's server, not your browser, fetches odds from PropLine. Nothing about visitors is sent to it.
Hosting. SlateProof runs on a server rented from Hetzner and managed by its owner. Accounts, sessions, logs and the engine's records are files on that server's disk, not in an analytics or advertising service. SlateProof sends no email.
What does an account store?
Accounts are optional and work only over HTTPS. Signing up takes an email and a password, and two-factor sign-in with an authenticator app is required, because accounts can place real orders. Here is every field the account system writes, by record. A test runs the real sign-up, two-factor, connection, order and administrator flows and fails if a field is stored that this table does not list.
Your account
| Item | What it is and why it is kept |
|---|---|
Account IDid | A random identifier (a UUID). It ties your sessions, security-log entries and orders to the account. |
Email addressemail | Your sign-in name, stored in lower case. SlateProof sends no email and does not check that the address is yours. |
PasswordpasswordHash | Never stored as you typed it. Only a scrypt hash is kept (cost factor 32,768, with a random salt for each password), so it cannot be read back. |
DatescreatedAt, updatedAt | When the account was created and when its record last changed. |
Email checkemailVerified | Always true: an address is accepted at sign-up without a check, because no email is sent. |
Rolerole | user, or admin for the owner's own accounts that can open the admin console. |
Statusstatus, disabledReason | active or disabled. When an administrator disables an account, the reason they typed is kept. |
Two-factortotp, recoveryCodes, mustEnrollTotp | Your two-factor set-up and recovery codes (the next rows), and a flag that stays true until two-factor is set up or after an administrator resets it. |
Password change flagmustChangePassword | True after an administrator issues a temporary password; you must choose a new one at your next sign-in. |
Sign-in failuresfailedLogins, lockedUntil | The count of wrong passwords and codes since your last complete sign-in, and when a temporary lock ends. Five failures lock the account for 15 minutes, and each further failure doubles that, up to 24 hours. |
Last sign-inlastLoginAt, lastLoginIp | The time and IP address of your last complete sign-in. |
Exchange connectionsconnections | Which exchanges you have connected, with the notes in the rows below. Your keys are not part of it. |
Settingssettings | Your own limit for one-click orders (below). |
Administrator notesnotes | Notes an administrator wrote about the account. You cannot see or add them; they appear only in the admin console. |
Two-factor: secretsecretEnc | The shared secret behind your authenticator app's six-digit codes, encrypted with AES-256-GCM. The encryption key is derived from a server secret that is kept outside the data files. |
Two-factor: set-up timeenabledAt | When you finished setting up two-factor. |
Two-factor: last code usedlastStep | The 30-second time step of the last accepted code, so the same code cannot be used twice. |
Recovery codes: codehash | Ten single-use codes. Only an HMAC-SHA256 fingerprint of each is kept, never the code itself; you see the codes once, at set-up. |
Recovery codes: usedusedAt | When a code was used (each works once). |
Exchange connection: labellabel | A name for the connection (up to 40 characters). It defaults to the exchange's name or the device you connected from. |
Exchange connection: key hintkeyHint | The last four characters of your key ID, so you can tell which key is connected. The server refuses anything longer than 12 characters, and refuses a connection note that carries any other field, such as a key. |
Exchange connection: environmentenvironment | Live, demo or paper trading, depending on the exchange. |
Exchange connection: connectedconnectedAt | When you recorded the connection. |
Settings: maximum per ordermaxOrderUsd | Your own cap on one one-click order in dollars (default $100, never above the site's cap). |
Administrator note: time and textat, text | When an administrator wrote the note, and what it says (at most 1,000 characters). |
Sign-in sessions
| Item | What it is and why it is kept |
|---|---|
Session IDid | A random public ID, shown in your list of signed-in devices so you can end a session. |
Cookie fingerprinttokenHash | A SHA-256 hash of the random token in your cookie. The token itself is only in your browser. |
AccountuserId | Which account the session belongs to. |
Stagestage | Where sign-in stands: set-up, code entry, forced password change, or complete. |
TimescreatedAt, lastSeenAt, expiresAt | When the session started, when it was last used (saved at most once a minute) and when it ends. |
IP addressip | The address the session was started from. You see it in your device list. |
Browser detailsuserAgent | Your browser's user-agent text, cut to 200 characters, used to name the device in your list. |
Wrong codestotpFailures | Wrong two-factor codes in this session; five end it. |
Pending set-up secretenrollSecretEnc | While you are setting up two-factor, the new secret, encrypted. It is cleared once the set-up completes. |
Security log
| Item | What it is and why it is kept |
|---|---|
Timeat | When it happened. |
Whoactor | user, admin or system. |
What happenedaction | A short action name, for example sign-up, sign-in (correct or failed), two-factor code (correct or failed), recovery code used, sign-out, password change, new recovery codes, session ended, exchange connected or removed, limit changed, account deleted, and every administrator action. |
AccountuserId, email | The account's ID and email. For a failed sign-in with an address that has no account, the address that was typed is recorded. |
IP addressip | The address the request came from. |
Extra factsdetail | Small details: a lock's end time, a reason, an exchange name, a new limit, or which administrator acted. Never passwords, codes, cookies, signatures or request bodies. |
One-click order records
| Item | What it is and why it is kept |
|---|---|
Order ID, account and timeid, userId, at | Assigned by the server when the record is written; a browser cannot set them. |
Exchangeexchange, environment | Kalshi, Polymarket US or Novig, and whether the order was live, demo or paper. |
Routevia | relay for Kalshi orders that passed through SlateProof's server, or direct for Polymarket US and Novig orders that your browser sent itself and then reported. |
Market and sidemarketId, side | The exchange's market ID, and yes, no, or a sale of one. |
What you asked forlimitPrice, contracts, maxCostUsd | The limit price, the number of contracts and the most the order could cost, all in dollars. |
What happenedstatus, filledContracts, avgPrice, costUsd | filled, partly filled, not filled, refused or error, with the contracts filled, the average price and the cost. |
Exchange replyexchangeOrderId, message | The exchange's order ID, and any error text it returned (up to 300 characters). |
What it was forcontext | Which move on the dashboard the order came from (below). |
Order context: kindkind | arbitrage, promo_hedge or bet. |
Order context: reference and titleref, title | The move's internal reference and the title the dashboard showed (up to 200 characters each). |
Where do my exchange keys go?
Your exchange API keys stay in your own browser. When you connect one, the page imports the private key into your browser's WebCrypto as a non-extractable key, which can sign but can never be read back, and keeps it in IndexedDB (a database named slateproof-trade) on that device. SlateProof's server never receives, stores or logs a private key. It refuses a connection note that carries anything beyond a label, a key hint and an environment, and keeps only the last four characters of the key ID as the hint. To trade from a second device, you add the key there. Signing out leaves the keys in that browser, so on a shared computer disconnect first.
Polymarket US and Novig. Your browser signs each request and sends it straight to the exchange. SlateProof's server is not in the path. After an order, the browser reports a summary to your order history (the order records above).
Kalshi. Kalshi rejects requests from browsers, so your browser signs the request and SlateProof's server forwards it unchanged to Kalshi (external-api.kalshi.com, or Kalshi's demo site). While it does, the server sees the request path and query, your Kalshi key ID, the timestamp and the signature (never the private key), the body of an order (market, side, number of contracts, price, time in force), and the response Kalshi returns, which can include your balance, positions or fills. It allows only a short list of requests (market data, balance, positions, fills, creating, looking up and cancelling an order), never a transfer or withdrawal, and checks your per-order and the site's caps before an order goes out. It does not store the key ID, signature, request or response. It stores only the order record described above, and that only when the request is an order. Kalshi sees SlateProof's server's address, not yours.
There is no automatic trading. Every order is one click of yours, as a fill-or-kill limit order at the price shown. The exchanges are Kalshi, Polymarket US and Novig.
What cookie does the site set?
None, until you sign in. Signing up or in sets one cookie, sp_session, holding a random 32-byte token. The server keeps only a SHA-256 hash of it. The cookie is HttpOnly (scripts cannot read it), SameSite=Strict, and Secure over HTTPS, and it is removed when you sign out. A step that is not finished (two-factor set-up, entering a code, a forced password change) lasts 10 minutes. A full session ends after 30 days, or after 7 days without use. These are the current settings, which an administrator can change.
How long is it kept?
| Data | Kept |
|---|---|
| Settings in your browser | Until you clear the site's data. Hidden moves are ignored after 20 hours. |
| Sessions | Until they expire or you end them. Expired ones are cleared when someone next signs in or the server restarts. |
| Your account | Until you delete it (below), or an administrator deletes it. |
| Security log and order records | No automatic expiry yet. They are kept after an account is deleted. |
| Rate-limit counts and lockouts for unknown emails | In the server's memory only; cleared when it restarts. |
How do I delete my account?
Open the Account section of the dashboard while signed in and choose Delete my account. You confirm with your password, a current two-factor code and the word DELETE. That removes your account record (email, password hash, two-factor secret, recovery codes, connection notes and settings) and your sessions, and the page also removes the exchange keys held in that browser. Your accounts at the exchanges are untouched.
What stays: the security log, which includes your email address and IP addresses, and your one-click order records. They are not erased when an account is deleted, and there is no automatic expiry yet. A public contact address for asking for that has not been published yet; when one is, it will be listed here.
Who can see my account data?
The site's owner and any administrator the owner appoints, in the admin console. It shows an account's email, status, sign-in times and IP addresses, devices, exchange connections, orders and administrator notes. It does not show password hashes, two-factor secrets or recovery codes. Administrators can reset a password or two-factor set-up, end sessions, disable or delete an account and add a note, and each action is written to the security log with who did it. SlateProof does not sell, rent or send account data to advertisers, analytics companies or anyone else. The only data about you that leaves the server is the Kalshi requests you trigger yourself.
What about children?
SlateProof is for adults. It does not ask your age and does not check it, and it is not meant for anyone under the age at which they may legally bet (21 in nearly every state, 18 at a few venues). If that is you, please do not use the account features. See responsible gambling for the age rules.
When does this page change?
When the code that stores data changes, this page changes with it and its Updated date moves.