Privacy policy
What we collect, why, and how to get rid of it. Written to be read, not to be survived.
The short version. We collect your email address, a display name, an optional profile photo, your phone number, the job and area of expertise you choose to publish, an optional forecast instruction (My Prompt), the time you spend reading stories (grouped by topic on your profile), and the predictions you make. Your display name, your photo, your points and your standing are public — that is the product. Your email address is not. A My Prompt instruction is public as the prompt text on Prompts standings. Your display name appears as the creator only if you tick that box on your account page. Your named probability on an event stays private from the field until that event locks, except: if you comment after calling, that comment shows the number you had at that moment (not later slider moves) as a public mark. Accepted friends can see your live number once they have called the same event, and can leave a private note on that number that only the two of you see. Your profile at /me (and /p/… for anyone else) shows your name, photo, ranks, any job and expertise you added, any links you added, and how long you have spent reading stories by topic; accepted friends also see which stories you liked and which you have called. Scroll and the tournament slate show a histogram after you release the slider — the field's anonymous buckets once that question has a hundred calls, or a shape drawn from a pinned public-market price until then, labelled as a citation of that market — with named friend avatars on that bar after you have saved yours. There is no advertising, and nothing follows you onto other websites. We use PostHog to see which pages are used; it does not advertise or sell your data, and it does not run until this browser accepts analytics (the first-visit bar, or the switch on your account page). A generated coverage argument (a both-sides take, and when shown the for/against cases), when shown, is written by OpenRouter from those headlines and article extracts — not from anything about you. Related coverage may also include a YouTube clip from a news desk we already allowlist (BBC, Reuters, AP, and the rest of that masthead list). We store the public video id, title, channel, poster, and description on the question, not on your account. The cron may also fetch that clip's public captions so a model can score whether the video is about the question and so THE ARGUMENT can cite a line from the transcript. Tapping Watch loads a player from YouTube; we do not embed that player until you ask. The same class of article text is sent so several models can each call YES, NO, or MAYBE on the question; those calls are public on /agents and a full-screen per-story page, and they are not about you. If you type a follow-up on a story, that question is sent to OpenRouter with a Google News search; we do not keep it. If you save a My Prompt instruction, that text is sent with the coverage when DeepSeek forecasts the story; identical wording shares one forecast row. You can export everything we hold or delete your account yourself, at any time, from your account page.
1 Who we are
Leaderboard is a free game about forecasting real-world events, at www.leaderboard-alpha.com. Leaderboard is operated by its founding team in Australia. An operating company is being established; when it is registered, its name and ABN will be published here and will assume these obligations. Until that company exists, the founding team is the controller of this processing.
This policy covers the website and the emails we send. It does not cover anything you reach by leaving the site — the resolution sources we link to have their own policies.
For anything in this policy, including a request or a complaint, write to theworldleaderboard@gmail.com. We answer those ourselves. There is not yet a designated EU or UK representative under GDPR Article 27 — that arrives with the operating company.
2 What we collect
All of it, in full:
Why we collect it (lawful basis). Where UK or EU data protection law applies, each purpose has a basis under GDPR Article 6:
- The game itself
- Creating an account, storing your predictions, comments, friends, groups, and profile, scoring them, and showing standings is contract — you asked to play. The same basis covers a My Prompt instruction you save so DeepSeek can forecast a story, and the 18+ tick plus phone collected at onboarding.
- Product analytics
- PostHog page views and clicks are consent. Nothing is sent until this browser accepts analytics. You can withdraw on the first-visit bar's counterpart on your account page.
- Result emails
- Telling you that a call of yours resolved is legitimate interest in running the game you joined. You can turn them off on your account page. Sign-in links are contract — they are how you get in.
- Security and operations
- Server logs (IP, user agent, the page requested) are legitimate interest in keeping the site up and investigating abuse. We do not use them to build a profile of you.
- Coverage arguments and model forecasts
- Headlines, article extracts, and (for a news clip) the public transcript sent to OpenRouter are not about you. YouTube video ids and titles we store for a story are public metadata of that clip, not of you. A follow-up you type, or a My Prompt instruction, is sent because you asked for that feature (contract).
The records themselves:
- Your email address
- From Google if you sign in with Google, or from you if you sign in by emailed link. It is your account identity and how we send you results. We never sell or share it.
- Your phone number
- Collected once, the first time you sign in, alongside a tick box confirming you are 18 or over. We do not verify either — the checkbox is self-attestation, not identity verification — and neither is public.
- Your display name
- Taken from your Google profile or chosen by you, and changeable at any time. It is public. If you would rather not be identifiable, use something that isn't your name — nothing checks it.
- Your profile photo
- Optional. You upload it from your account page; we store the file and show it wherever your display name appears (standings, comments, friends, your track record). It is public. You can replace or remove it at any time. If you do not set one, we show initials from your display name. A coloured ring around the photo (or the initials) shows how many calls you have made and, once at least three of those have resolved, your average accuracy. That ring is computed from your predictions when the page loads — we do not store a separate level. The ladders are on the progression page.
- Your job and area of expertise
- Optional. You add them on your account page as Background; we store them on the player row (
players.job,players.expertise) and show them on your profile. Anyone who can see the profile can read them. Leave a field blank to take it down. - Your forecast instruction
- Optional. You add it on your account page or the My Prompt tab on a story (
players.forecast_prompt). DeepSeek reads it before it forecasts that story. Saving a new instruction keeps the previous wording inplayer_forecast_prompts(started and ended). Identical wording shares one row inlm_forecasts(hashed, no player id). That prompt text, its accuracy, Brier, and how many resolved questions it forecast are public on Prompts standings. Your display name is in the Creator column only whenplayers.forecast_prompt_publicis on (the checkbox on your account page). House models with no instruction are on Agents. Deleting your account clears the instruction and the history rows; shared forecast rows stay so someone else using the same wording is not wiped. Leave it blank to clear. - Public links you choose to publish
- Optional. Substack, Linktree, and a website URL, stored in
player_linksand shown on your profile. You add or remove them on your account page. https only; Substack and Linktree have to be on those hosts. Anyone who can see the profile can open them. - Time you spend reading
- While you are signed in, we count seconds THE STORY or THE ARGUMENT stays on screen with the tab in front (
reading_subjects). A card with no coverage, or still waiting on a summary, is not counted. We group those seconds by topic — China, politics, oil — inreading_areasand show the totals on your profile and at /reading. Anyone who can see the profile can read them. Operator test bots are not counted. A fast swipe does not register; the clock pauses when you switch away. Education articles are not counted. - Whether the account is an operator test bot
- A flag on the account used only for synthetic players we mint while testing (local development only). A real account is never a bot. The flag is included in a data export. Test bots show a robot icon wherever a photo or initials would appear, are not sent to PostHog, and never receive result emails.
- Your predictions and entries
- The probability you set on each event (the number that scores), the first probability you released before you saw the field histogram (`predictions.pre_reveal_probability_bp`, kept even if you then moved the slider), which event you designated as THE CALL, which tournaments you entered, and when each was saved. Saving also stamps two reference numbers alongside your call — where the field average and the pinned market's price stood at that moment (`predictions.field_mean_bp_at_call`, `predictions.market_yes_bp_at_call`) — so the scroll can tell you what has moved since. The pinned market at first release (`predictions.market_yes_bp_at_first`) is kept separately, even if the pin arrives later or you move the slider, so standings can say how far you sat from the pinned public-market price before you saw the field and after. The field average is about other callers; the two market stamps are about the pin, not about you; all three are in your export. Friends, standings, and the field histogram use the scoring number, not the first-release one.
- Your groups
- Groups you create or join — including groups an accepted friend added you to — their names, and their invite codes. If you did not create the group, you can leave it.
- Your friends
- Friend requests you send or receive, and the accepted friendships that follow. A friendship is mutual: both people have to agree. We do not store a colour for a friend — the colour you see is assigned when the page loads, unique among your friends, and is not a fact we hold about them.
- What you post
- Comments on events, including replies nested under other comments at any depth (`comments.parent_id`), and the probability you had called when you posted (`comments.called_probability_bp` — write-once; absent if you had not called yet). Comments you like, comments you report, questions you like, and private notes on a friend's call (`call_notes`) — a 1:1 thread on their probability, visible only to the two of you, not the event's public CHATTER. You can start that thread from the question page or by tapping their avatar on Scroll. Incoming notes show in your Inbox. A question like is on the wording, not a particular tournament slot — two events that share a question share one count. The count is public. Accepted friends see who liked a story on Scroll (named avatars on the card) and the list of questions you liked on your profile. Not-interested hides a wording from your Scroll and is not shown to anyone else; every like, unlike, not-interested, and undo press is also stored as a permanent log (`question_feedback`) so the feed can learn, and both that log and the current hide are in your export and are erased if you delete your account. Reports identify the reporter to us so the same comment or note cannot be reported repeatedly by one person; they are not shown to the person reported.
- Follow-up questions on a story
- If you type a question under THE STORY, we send that text, the forecasting question, and article extracts from the coverage on the card to OpenRouter, and we run a Google News search for it. We do not store the question or the answer — they live only for that request. Signed-in only.
- A record of what you did
- Timestamped entries for signing in, submitting or updating a slate, creating or joining a group, and posting or reporting a comment. We use it to understand how the product is used and to investigate abuse. Opening Inbox records the time (`players.call_inbox_seen_at`) so we can badge notes you have not seen yet — it is a cursor, not a copy of the messages.
- Emails we generated for you
- A copy of each notification — its subject, its text, and whether it sent — so we can tell whether you were told about a result. Two kinds: a notice when an event you called resolves, corrects, or voids, and a daily nudge on the mornings one of your calls resolves or locks. The nudge stamps when it last went out (`players.last_nudged_at`) so you never get two in a day. The result-email switch on your account turns both off.
- Sign-in records
- If you use Google, the sign-in library stores your name, email, whether the address is verified, your profile image URL, and the access tokens Google issues. We do not request access to anything in your Google account beyond your basic profile.
- How you use the site
- Which pages you open, what you click, your browser and device, and a rough location derived from your IP. This is processed by PostHog so we can see how the product is used, and only after this browser grants analytics. Until you sign in it is tied to a random identifier in your browser, not to you. After you sign in it is tied to your player id and display name — never your email. Operator test bots are not identified. We do not record a video of the session.
- Standard server logs
- Our hosting provider records the usual request data — IP address, browser user agent, the page requested, the time — for security and operations. We do not use it to build a profile of you.
What we deliberately do not collect. No passwords, because there are none to choose. No payment details, because nothing is for sale. No advertising pixels, and nothing that follows you onto other websites. PostHog is product analytics for this site, not a tracker that reports you elsewhere, and it is off until you accept it.
3 What is public and what is not
Public to anyone, signed in or not: your display name, your profile photo if you uploaded one (or a robot icon if the account is an operator test bot), the coloured ring around it that shows your call count and accuracy, your position and points in any tournament you entered, your track record across tournaments, the job and area of expertise you added, the public links you added (Substack, Linktree, a website), a My Prompt instruction as the prompt text on Prompts standings (your display name as creator only if you opted in), how long you have spent reading stories grouped by topic, your comments (and, if you had called when you posted, the probability you had at that moment), and the number of likes on a question. News-only model forecasts on a question (each model's probability and short rationale, written from the articles — not from your account) are public on /agents, a full-screen per-story page, THE MODEL card on Scroll, and as named pins on the field histogram (Claude, Gemini, GPT, DeepSeek icons — not the robot mark used for operator test bots). Each player has a profile at /p/…; yours is also /me when you are signed in.
Visible to anyone holding a group's invite code: that group's name, everyone in it by display name, and their standings. Invite codes are meant to be shared, and a link has to work before the person clicking it has joined — so treat a code as public once you have sent it, and expect a group you are in to be as visible as its most careless member's sharing. An accepted friend who is already a member can add you in one click; that is the same visibility as if you had joined yourself.
Visible to your accepted friends: the probability you set on an event (the number that scores — not the first-release guess stored when the field histogram appeared), once they have also called that event. This is the one named-person exception to the field staying hidden until lock. Strangers never see your live number next to your name until then — they can see the number you had when you commented, on that comment. A friend who can see your live number can leave a private note on it; only the two of you see that thread — your other friends cannot. On your profile they also see which questions you liked and which events you have called; the named percent on those calls still waits until they have called the same event. On Scroll and on your tournament slate, a signed-in player who releases the slider sees a histogram under the track. Once that question has a hundred calls, the bars are an anonymous 10-point bucket of everyone else — not a name. Until then, if the event is pinned to a public prediction market, the bars are a crowd-shaped stand-in around that market's last stored Yes, labelled as a citation of the market, not as a player headcount. After they lock that call in, accepted friends who have called the same event appear as named avatars on that bar at their percent. House model forecasts (Claude, Gemini, GPT, DeepSeek) pin on the same bar with their own icons — they are not operator test bots and they are not mixed into the anonymous buckets or the field average. You can tap a friend avatar to send a private note on their call; incoming notes land in your Inbox. A friend-add link identifies your account the same way a group invite identifies a group — treat it as public once you have sent it.
Private from the field until an event locks: the probability you set on it, except the mark on comments you posted after calling. Nobody outside your accepted friends sees your live named percentage — not other players, not the published field average — until that event's lock passes. On Scroll and the tournament slate, once someone releases the slider they see a histogram under the track: the field's anonymous buckets after a hundred calls on that question, or a market-shaped placeholder until then. Your number can sit in a 10-point bucket there without your name. After they have saved, an accepted friend who has also called sees your named avatar on that bar. After the lock, your number contributes to the published field statistics.
Public only by your hand: a resolved call of yours — your display name, your number, the field's, the outcome, the points — appears on a page and a share image at a signed link (/called/…) that only you can mint, from the Share button on the results card or the link in your result email. Anyone you send it to can see it and pass it on; nobody can guess it. Open calls are never shared this way.
Never public: your email address, your sign-in records, which comments you liked or reported, your activity log, private notes on a call, when you last opened Inbox, and the first probability you released before the field histogram — friends, standings, and the field see only the later scoring number. Question likes are listed to accepted friends on the story and on your profile, not to everyone. Not-interested marks and the like / hide press log are held only for you.
Because standings are public, a search engine may index a page your display name or photo appears on. Changing your display name or photo changes it everywhere on the site at once, including on finished tournaments, but we cannot recall a copy someone else has already made.
5 Who else handles your data
We do not sell your data and we do not share it for anyone else's marketing. It is handled by the services that run the product, and by nobody else:
- Vercel — hosting, content delivery and server logs.
- Supabase — the database everything is stored in, hosted in Singapore, and the sign-in service: Google confirmation and magic-link emails when that path is on. The app queries Postgres as the table owner, not through Supabase's Data API.
- Google — to confirm who you are if you choose to sign in with Google, and, when you ask a follow-up on a story, as the Google News RSS search for that question (the query is the story plus what you typed; it is not attached to your account). When you tap Watch on a news clip, YouTube (a Google service) loads a privacy-enhanced player from youtube-nocookie.com to play that video. We do not send YouTube your account. The clip's public id, title, channel, poster, and description sit on the question's coverage row for every visitor. The cron may fetch that clip's public captions (not attached to your account) so a model can score the video against the question and THE ARGUMENT can cite the transcript.
- Our email provider — to deliver the notices telling you an event resolved and the daily nudge on the mornings a call of yours resolves or locks. Sign-in links are sent by Supabase when that path is on, or by this same SMTP sender on the older Auth.js path.
- PostHog — product analytics, only after this browser grants it. Pages you visit, clicks, browser, and (once you sign in) your player id and display name. Hosted in the United States unless we switch the project to the EU. Session recordings are off. PostHog's privacy policy.
- OpenRouter — when a related-coverage argument is shown (on Scroll and the question page), the headlines, publisher names, article extracts, and news-clip transcripts we fetch — not the full pages, and nothing about you — are sent to OpenRouter to score whether an item is about the question, and to write THE STORY brief, the both-sides take, and the for/against cases (which may cite a clip by its watch URL). House model forecasts send the same headlines (and a desk brief when we have one) with no player text. If you run My Prompt, the instruction you saved is sent too. The same article pack (never a Polymarket or Kalshi price, never anything about you) is sent so a small panel of models can each call YES, NO, or MAYBE; those calls are stored and shown on /agents and a full-screen page per story. If you ask a follow-up on a story, the question you typed is sent too, with those extracts; we do not keep it. If the key is not configured, no card is shown, the follow-up field fails closed, the model board stays on whatever was last stored, and nothing new is sent. OpenRouter's privacy policy.
Your data is stored outside Australia. The database is in Singapore, our hosting provider is a United States company, and PostHog is too, so your information is held and accessed overseas. Headlines, article extracts, and news-clip transcripts sent to OpenRouter for a coverage argument, a house or My Prompt model forecast, a news-only agent forecast, a My Prompt instruction, and a follow-up you type on a story, also leave our servers (United States). If that is not acceptable to you, the remedy is not to create an account.
Where UK or EU law applies, those transfers rely on each provider's Standard Contractual Clauses (or an equivalent transfer tool they publish) covering the UK/EEA → Singapore or United States route. We do not add a second set of clauses on top: there is not yet a company here that can sign them. Switching the PostHog project to eu.i.posthog.com is an operations change, not a product one.
We will disclose data if the law requires it, and we will tell you when we are permitted to.
6 How long we keep it
While your account exists, we keep it. Your predictions and results are the point of the product, so they are not expired on a timer.
When you delete your account, the deletion runs immediately: your predictions, entries, slates, group memberships, friendships, likes, not-interested marks, the like / hide press log, reports, notes on friends' calls, notification records, profile photo, reading time, and sign-in records are erased, the text of your comments is removed, and your name is unlinked from anything that survives. Your record of activity is kept but de-identified — the rows stay so our usage counts remain honest, with nothing left connecting them to you. We also ask PostHog to delete the person tied to your player id.
Two honest caveats. Deleted comments leave an empty "[removed]" placeholder where someone has replied, at any depth in the thread, so the conversation still makes sense; nothing of yours remains in it. Notes on a friend's call are deleted outright — that thread is only the two of you, so there is nobody else who needs a placeholder. And for a short period afterwards your data may still exist in our database provider's routine backups, which are overwritten on a rolling schedule — we do not read them and we do not use them to restore a deleted account.
7 Your control over it
- See it (access and portability)
- Your account page downloads everything we hold about you in our database as a single JSON file, immediately, no request needed — that is also the portable copy. Two things are deliberately left out, and the file says so where they would have been: the access tokens your sign-in provider issued (credentials rather than information about you), and page views processed by PostHog (they are not stored in our database; deleting your account asks PostHog to delete them too). Your analytics choice lives in this browser, not in that file.
- Correct it
- Change your display name, profile photo, Background (job and expertise), public links, and My Prompt instruction yourself on the same page. To change the email address your account is under, write to us — it is your identity here, so we move it by hand rather than let it be reassigned in a form.
- Delete it
- Also on your account page, immediately and permanently, without asking anyone. There is no cooling-off period and no undo, which is why the page makes you type your name to confirm. Shared model-forecast rows keyed only by prompt text are not deleted — they are not your row.
- Object or restrict
- Turn off product analytics on your account page — that is the objection to PostHog, and it takes effect in this browser at once. Turn off result emails the same way. Restriction (pause processing while we look at a dispute) and any other objection are a mail to theworldleaderboard@gmail.com — say which processing you want paused; we will not invent a half-running game.
- Withdraw consent
- Analytics consent is withdrawn with the same control that granted it. Session cookies and the rest of the account do not use consent, so turning analytics off does not sign you out.
- Stop the email
- Turn off result notifications on your account page. Sign-in links keep working, because that is how you get in.
- Complain
- Write to theworldleaderboard@gmail.com and we will answer. If you are in the UK you can also complain to the Information Commissioner's Office. If you are in the EU, complain to the data-protection authority of the country you live in. If you are in Australia, the Office of the Australian Information Commissioner publishes guidance; we are not registered as an APP entity, so that office may not treat us as bound by the Australian Privacy Act until we opt in or an exemption stops applying.
8 Security
The site is served over HTTPS. Session cookies are signed and inaccessible to JavaScript. We store no passwords at all, which removes the single most damaging thing a breach of a site like this could leak — there is nothing here that would unlock your other accounts.
No system is immune. If we ever suffer a breach affecting your data we will tell you and the relevant authority, promptly and in plain language.
9 Age
Leaderboard is for people aged 18 and over, and accounts are not knowingly created for anyone younger. You confirm this yourself with a tick box the first time you sign in — a self-attestation, not an identity check — before you can do anything else on the site. If you believe a child has an account, tell us and we will delete it.
10 Changes to this policy
The date at the top of this page is the date the text last changed in substance. If we change something that matters — what we collect, who handles it, what becomes public — we will say so on the site rather than quietly reissue the page.