PolyTrace

Chrome extension

PolyTrace for Polymarket — privacy policy

Last updated: 2026-10-01

What the extension does

PolyTrace for Polymarket shows analytics from polytrace.app for the Polymarket event or profile page you are viewing, when you click the extension icon or use its right-click menu on a Polymarket link.

On a Polymarket market page (/event/…, /market/…, /sports/…) it also adds a small PolyTrace badge to each row of that market’s Top Holders list and trade Activity feed, showing that wallet’s published 90-day return on polytrace.app.

Data the extension processes

Current tab address (URL) — read only after you click the extension icon (Chrome’s activeTab permission) or right-click a specific link. The URL is parsed locally in the extension to detect a Polymarket event slug, wallet address, or username.

The identifier you are inspecting — that single event slug, wallet address, or username is sent to polytrace.app over HTTPS to fetch the data shown in the popup.

Wallet addresses on polymarket.com market pages — on polymarket.com only, and there only on a market page (/event/…, /market/…, /sports/…), the extension reads the page to collect the wallet addresses that Polymarket itself displays in that market’s Top Holders list and Activity feed (each row links to /profile/0x…, or to a language-prefixed /zh/profile/0x… when Polymarket is shown in another language; the address comes from that link). It looks inside those two panels only — located by the page’s own structure (the section where Polymarket shows its Comments, Top Holders, Positions and Activity tabs, and the shape of the holder and trade rows), not by their wording, so it works the same in every language Polymarket is displayed in — so the wallet addresses shown elsewhere on the site (the home feed, leaderboards, your portfolio, profile pages, the comment thread, the Positions tab) are not collected. Those addresses are sent to polytrace.app over HTTPS to look up their published 90-day return, which is shown in the badge. Wallet addresses are the only thing sent. Nothing else from the page is transmitted: not the page text, not usernames, not trade amounts, not the market, and not the address of the page you are on.

What is read but never sent — each Activity row’s visible text is read locally to work out the trade’s size, because rows below $1,000 are not badged (PolyTrace records no trade below that). The amount stays in the browser; it is not part of any request.

Anonymous reliability counters — a future version may send counts of how many rows the extension saw and how many it could annotate, so that a silent failure after a Polymarket redesign is detectable. Counters only: no wallet address, no page, no market, no identifier of you. This sending is turned off in the current version (0.3.1).

Server and CDN logs — polytrace.app is served through Cloudflare (CDN and Workers) and a server hosted by Hetzner. Like any website, they keep standard request logs: the time, your IP address, and the requested URL. For a badge lookup that URL contains the wallet addresses being looked up; for the popup and the right-click menu it contains the event slug, wallet address, or username you inspected. The request logs on our server are size-capped and rotated, are deleted whenever the service is redeployed, and are not archived; Cloudflare standard logs apply to the requests Cloudflare serves. Our application’s own diagnostic logs, kept for up to 30 days, may also note an inspected event slug, username, or shortened wallet address when a lookup fails or starts a data refresh. Logs are used only to operate and secure the service.

Data the extension does not retain or access

  • No browsing history is built or stored: the extension processes only the active tab or link you explicitly ask it to inspect, plus the wallet addresses shown in the two panels of a polymarket.com market page you open, and keeps no record of visited pages.
  • Nothing beyond those wallet addresses leaves your browser: the extension does not transmit page text, your positions, your balances, or anything you type. Its page script runs on polymarket.com only and on no other site; the right-click items appear on Polymarket links on any site and read only the link you chose.
  • What it changes on the page: it adds one badge element and one data attribute (data-pt-badge) to each row it annotates, and nothing else. No existing Polymarket element is moved or removed and no Polymarket attribute is changed.
  • No accounts, credentials, cookies, or wallet keys are read, and the extension never asks you to sign, approve, or send a transaction.
  • No third-party services: the only host the extension contacts is polytrace.app, served through our hosting and CDN providers, Cloudflare and Hetzner, which process requests only to deliver the service.
  • No sale or sharing of data; no advertising or unrelated analytics.

Storage

The extension keeps no persistent local storage of your activity. Badge lookups are cached in memory for 60 seconds to avoid repeat requests, and that cache is discarded when the browser or the extension’s background worker stops.

Changes and contact

Material changes to this policy will be reflected in the extension’s store listing and on this page with an updated date. Questions: polytrace.app.