Privacy Policy
Last updated: July 29, 2026
This policy describes what personal data Balauron collects, why it is processed, and what you can do about it. It is written to match what the software actually does — if you find a discrepancy, treat it as a bug and tell us.
1. Who we are
Balauron is operated by Răzvan Mareș, an individual based in Romania, who is the data controller for the purposes of the General Data Protection Regulation (EU) 2016/679.
Contact: [email protected]
There is no company entity, registered office, or VAT registration behind Balauron at this time, and we do not claim one. See the Imprint for the full service-provider identification.
2. What we collect
If you only read the site, we collect nothing that identifies you. There is no analytics, no tracking pixel, no advertising network, and no third-party script of any kind. Your browser's language preference is stored in a cookie on your own device.
If you create an account, we store:
- your email address
- the username you sign in with, and the display name you choose to show on leaderboards
- a cryptographic hash of your password — never the password itself
- whether your email has been verified, plus a short-lived single-use verification token
- the date your account was created
As you use the product, we store what you create: the calls you log (predictions and signals), the markets you watch, wallet addresses you look up, alert rules you set, and any contest entries. These are the point of the service.
We do not collect payment data, because Balauron takes no payments. We do not ask for your name, address, phone number, date of birth, or any identity document.
3. Why we process it, and on what legal basis
- To provide the service you asked for — running your account, recording your calls, and scoring them. Legal basis: performance of a contract (Art. 6(1)(b)).
- To keep the service secure — rate limiting, preventing abuse, and an administrative audit log of privileged actions. Legal basis: our legitimate interest in a functioning, non-abused service (Art. 6(1)(f)).
- To send you service email — email verification, and account notices you have opted into. Legal basis: performance of a contract (Art. 6(1)(b)).
- To remember your language — legal basis: your request, stored on your own device.
We do not profile you for advertising, we do not sell data, and we take no automated decisions that produce legal effects for you. Your skill score is a statistic about calls you deliberately made, visible to you and, if you appear on a leaderboard, to others.
4. Cookies
Balauron sets only strictly necessary cookies, which is why you have not been shown a consent banner. The full list, with purpose and lifetime, is in the Cookie Policy.
5. Who we share it with
We do not sell or rent your personal data, and we share it with no one for their own purposes.
We use one processor that handles personal data on our behalf:
- Resend — sends transactional email (address verification and account notices). It receives your email address and the message content.
Balauron also reads public market data from Polymarket and Binance. These are outbound, read-only requests made by our servers: they carry no information about you, and those venues receive nothing that identifies you or reveals that you exist. Looking up a public wallet address on Balauron queries Polymarket's public data for that address — the address, not your identity.
AI and machine-translation providers are wired into the codebase for authoring and translating blog posts. They ship unconfigured and are dormant; no user content is sent to them. If that changes, this policy changes first.
We may disclose data if we are legally required to, and will tell you unless we are prohibited from doing so.
6. Where your data is processed
Balauron's servers are located in Romania (EU). Your data does not leave the European Economic Area in the ordinary course of running the service.
Our email processor may process data outside the EEA. Where that happens, the transfer relies on the safeguards in Chapter V of the GDPR, such as Standard Contractual Clauses or an adequacy decision.
7. How long we keep it
- Account data — for as long as your account exists. Delete the account and it goes, immediately and without a waiting period.
- Email verification tokens — until used or expired, whichever comes first.
- Your calls, watchlists, wallets and alerts — for as long as your account exists (but see what survives deletion).
- Administrative audit log — records privileged administrator actions, deliberately never referencing member accounts, so it can be retained without conflicting with your right to erasure.
8. Your rights
Under the GDPR you have the right to access your data, correct it, erase it, restrict or object to processing, and receive it in a portable format.
Two of these are self-service, work immediately, and need no request form:
- Access and portability — download everything we hold about you as JSON.
- Erasure — delete your account yourself, confirming with your password.
See Your Data for what each one does and what it does not remove. For anything else, email [email protected].
9. How we protect it
Passwords are stored only as salted hashes. Session tokens live in cookies your browser will not expose to JavaScript, are restricted to this site, and expire after eight hours. All traffic is served over HTTPS. The administrative interface is not reachable from the public internet at all. Destructive and authentication endpoints are rate limited.
No system is perfectly secure, and we will not pretend otherwise. If we discover a breach affecting your personal data, we will notify the supervisory authority and, where the risk to you is high, you directly.
10. Age limit
Balauron is not intended for children. You must be at least 16 to create an account, in line with Romanian law implementing Art. 8 GDPR. We do not knowingly collect data from anyone younger; if you believe a child has an account, contact us and we will remove it.
11. Changes to this policy
When this policy changes materially, we update the date at the top of this page. If the change affects how we use data you have already given us, we will tell registered members by email before it takes effect.
12. Contact and complaints
Questions, requests, or corrections: [email protected]
If you think we have handled your data unlawfully, you have the right to complain to the Romanian supervisory authority, the National Supervisory Authority for Personal Data Processing (ANSPDCP) — dataprotection.ro — or to the authority in your own EU country of residence. We would rather you told us first, but that is your right, not our permission.