Privacy
Last updated: September 6, 2026
The short version
We collect an email address so you can sign in, and we store the worldview you build — which indexes you track and what you have said you believe about them. Your worldview is private by default. We do not sell it, we do not expose individual beliefs, and we never infer protected characteristics from what you select. You can request deletion of your account-linked W.E.T. data at any time. Deletion is a verified operator process, not an automatic browser action, and the current scope and limits are stated below.
Who operates W.E.T.
World Event Trading (W.E.T.) is an unregistered brand operated by Jordan V Powell, a sole proprietor in Virginia. Corbin V King is the operator's public and editorial name. Privacy and deletion requests go to privacy@worldeventtrading.com.
What we collect
Your email address. Required to sign in. There is no password — we email a six-digit code and that is the whole account.
Your worldview. The positions you take in the worldview builder, the beliefs you record (direction, confidence, time horizon), and the indexes you add to your portfolio. Belief history is append-only: recording a new stance adds an entry, it does not overwrite the old one. That is deliberate — the sequence of how a view changed is the thing the dataset is for.
Sign-in security data. A hash of the one-time code (never the code), and salted hashes of the requesting IP address and browser user-agent, used only to rate-limit abuse of the sign-in endpoint. We do not store raw IP addresses against your account.
API keys and account automation. When you create a key, we store its name, visible prefix, one-way key hash, fixed scopes, creation and last-used times, revocation state, and metered usage. The complete key is shown once and is not stored in recoverable form. We also store watchlists, saved views, alerts, scanners, and the in-app delivery records you choose to create through the site or REST API, and through MCP only when that access is enabled.
MCP telemetry. MCP access is currently held pending source-rights and compliance clearance; held GET and POST calls are refused before tool-call telemetry. For MCP connections and tool calls processed when access is enabled, we record bounded client and protocol labels, a known tool name or an “unknown” bucket, outcome or refusal code, argument names and count, matched or returned counts, duration, and whether a credential header was present — not its value or validity. If a call contains a search query, we record only its length, token count, and a salted hash used to count repeated shapes, not the query text. We do not record an API key, authorization header, or raw IP address. A salted caller bucket changes each UTC day, and these MCP events explicitly disable PostHog person-profile creation.
Marketing email is currently disabled. Creating or signing in to a beta account does not subscribe you to the Daily Signal Sheet, and W.E.T. is not currently collecting newsletter signups or triggering newsletter broadcasts. The server defaults this channel off while no public marketing postal address is configured. If the channel is enabled later, enrollment will require a separate, unticked opt-in under versioned wording; the server will record the time, surface, country, and consent basis before it calls the newsletter provider. This control does not block transactional sign-in email or ordinary one-to-one business correspondence.
Optional browser analytics. Until you select “Accept analytics,” W.E.T. does not load Google Analytics, Vercel Web Analytics or Speed Insights, or the PostHog browser SDK, and does not create its analytics, attribution, or first-touch UTM identifiers. If you accept, those tools measure page use, explicit product events, performance, and affiliate click-outs. PostHog click autocapture may run on non-sensitive pages, and session replay runs for consenting visits on eligible pages. Replay masks form values, on-screen text, and DOM attribute values; authentication, account, checkout, and worldview-sensitive route bodies are excluded from replay and click autocapture. Query strings and fragments are removed from analytics URL fields. After verified sign-in, and only while analytics consent is present, the PostHog browser SDK can associate the consented browser history with the canonical W.E.T. account id and email. MCP request telemetry, when access is enabled, does not create a PostHog person profile.
Speed Insights performance copy. For consenting visits, Vercel forwards Web Vitals to a W.E.T.-controlled receiver. W.E.T. keeps the metric, collection time, route pattern, a query-free public path, sanitized element attribution, deployment context, and coarse country, device, connection, operating-system, and browser classes. It does not keep Vercel's owner or device id, city, region, device brand, granular software versions, or unrecognized payload fields. Sensitive account, authentication, checkout, and worldview instance paths are suppressed.
Community contributions. If you submit event context, request a new market, or vote on a request, W.E.T. can store the contribution, its time, your account id when signed in, and a pseudonymous browser voter id used for abuse controls. Contributions can become public community artifacts.
Why we collect it
To let you sign in; to save and show you your worldview across devices; to provide scoped API and, when enabled, MCP access to your own account state; to measure reliability, refusals, product use, and affiliate attribution; to build the longitudinal dataset that connects worldviews to market prices — in aggregate and de-identified form; to deliver transactional messages you request; to send marketing email only if that channel is later enabled and you explicitly ask for it; and to keep the sign-in endpoint from being used to send mail to people who did not ask for it.
Under GDPR, the sign-in code is processed to deliver a service you requested (Art. 6(1)(b)). If marketing email is enabled later, enrollment will rely on your consent (Art. 6(1)(a)), which you can withdraw at any time. Security rate-limiting rests on our legitimate interest in not operating an open email relay (Art. 6(1)(f)).
Optional browser analytics runs only after your consent. Rejecting it does not limit the site or account and does not affect the MCP release hold or any later MCP access. You can withdraw or grant that choice at any time through the persistent “Privacy choices” control. W.E.T.'s Google Analytics integration keeps advertising storage, advertising user-data, and advertising-personalization signals denied.
Who processes it
- Resend — sends the sign-in code. Receives your email address and the code.
- Google Workspace / Gmail — hosts W.E.T.'s business mailbox, including privacy, legal, support, rights-request, and ordinary business correspondence. It receives sender and recipient addresses, routing metadata, message content, and attachments sent to or from those addresses. This is separate from Resend's transactional sign-in delivery.
- Beehiiv — the optional newsletter list. Marketing enrollment and broadcasts are currently disabled, so account creation does not send your address to Beehiiv. If the channel is enabled later, Beehiiv will receive an address only after the separate explicit opt-in and the server's evidence checks pass.
- Neon — the Postgres database holding your account, worldview, account automation, community-contribution records, and W.E.T.'s minimized 30-day copy of consented Speed Insights performance measurements.
- Vercel — hosting, plus request logs and optional Web Analytics and Speed Insights after analytics consent.
- Google Analytics — optional page and interaction measurement after analytics consent. W.E.T. keeps the integration's advertising storage, advertising user-data, and advertising-personalization signals denied.
- PostHog — optional browser product analytics, click autocapture, and masked session replay on eligible pages after analytics consent and, after verified sign-in, an identified account timeline. MCP events explicitly disable person-profile creation and do not include raw query text, API keys, authorization headers, or raw IP addresses.
- Stripe — payment processing for paid memberships only. Card details go to Stripe directly and never touch WET's servers; a free account never reaches Stripe.
- Owner-alert destination, if enabled — a configured Discord, Slack, or owner-controlled webhook can receive a best-effort internal membership-transition alert. The current payload is limited to the event label and membership tier or status; it excludes the W.E.T. account id, subscription id, email address, and payment data. If no destination is configured, no owner alert is sent.
- Short-link or referral provider, if enabled — a click-through may use Dub or another configured link provider. When you choose such a link, that provider can receive the ordinary browser request, visible link parameters, and provider-generated click metadata. If no provider link or integration is configured, this processing does not occur.
Prediction market venues (Kalshi, Polymarket and others) receive no W.E.T. account record. When you click through, the venue—and a configured short-link provider, if the link uses one—receives an ordinary browser request and any visible referral or UTM parameters in that link. This external request occurs because you chose the link; rejecting W.E.T. analytics does not prevent the external destination from receiving ordinary request metadata. Before analytics consent, W.E.T. keeps only an aggregate click row without market/UTM detail or a browser id and sends no linked PostHog event. After analytics consent, W.E.T. may record the click with the consented pseudonymous browser id; after sign-in, product analytics may associate that id and earlier consented activity with your account as described above.
Cookies and browser storage
The consent record is necessary to remember the choice you made; the analytics identifiers below are optional. Changing the analytics disclosure version invalidates the earlier choice and asks again. Cookie names supplied by Google or PostHog can include a project-specific suffix.
- wet_analytics_consent: the versioned accepted or denied choice, with no user or device id; expires after 180 days.
- wet_anon: a random browser analytics and affiliate-attribution id; created only after acceptance and expires after at most 365 days.
- wet_ph_id: the canonical account id used by browser analytics after verified sign-in; created only while analytics is accepted and expires after at most 365 days.
- wet_first_utm: first-touch campaign fields; created only after acceptance, contains no complete page URL, and expires after at most 365 days.
- PostHog browser storage: project-specific
ph_…cookie and local-storage entries are created only after acceptance. The SDK cookie expiration is configured to 365 days; the local-storage copy remains until it is cleared or analytics consent is withdrawn. - Google Analytics storage: Google's
_ga-family cookies can be created only after acceptance. Their exact expiry follows the active Google tag/property configuration and browser controls; this codebase does not establish a separate fixed processor-side event-retention period.
Withdrawing analytics through “Privacy choices” disables the next document's optional analytics runtime and attempts to remove JavaScript-accessible W.E.T., PostHog, and Google analytics storage. Browser controls can also clear site data at any time.
How long we keep it
- Sign-in codes: deleted within 24 hours of expiring or being used.
- Rate-limit counters: 30 days.
- Sessions: 90 days maximum, or 30 days of inactivity, whichever comes first. Signing out revokes the session immediately.
- Your account and worldview: until you delete it.
- API keys and account automation: keys, watchlists, views, alerts, scanners, and delivery records remain until you revoke or delete them or complete a verified deletion request. A revocation or deletion marker can remain as an audit record while the account exists.
- W.E.T.'s Speed Insights copy: measurements are deleted after their browser collection time becomes more than 30 days old. Rows written by the receiver's original, less-minimized version are deleted in full by a one-time privacy migration.
- MCP and processor-side analytics: retained under the applicable PostHog, Google Analytics, or Vercel project configuration. This codebase cannot verify those administrator settings, so W.E.T. does not state a fixed processor-side event retention period here. This is separate from W.E.T.'s 30-day Speed Insights database copy. The browser-storage maxima controlled by this site are listed above. W.E.T. does not currently publish a separate fixed MCP telemetry retention period; the daily caller bucket itself cannot be joined across UTC days.
- Business correspondence and conditional providers: Google Workspace/Gmail messages, and any records held by a configured owner-alert or short-link provider, follow the relevant administrator and provider retention settings plus any documented need to preserve request, permission, security, or business records. Those settings still require production evidence, so W.E.T. does not state a fixed processor-side maximum here. A verified privacy request receives a case-specific deletion or retention review.
What we will not do
We will not sell or expose identifiable individual beliefs. We will not infer protected characteristics — political affiliation, religion, ethnicity, health, sexuality — from your worldview selections, and we will not build or sell a product that does. We will not make your portfolio public without an explicit act by you. Aggregate research uses de-identified data only.
Deleting your account
The current local worldview-erasure step removes your belief history, portfolio, builder answers, user-level worldview derivatives, and consent records, and revokes active sessions. It clears profile fields and leaves a soft-deleted account row so the address cannot be silently re-registered; that row carries no worldview data.
API keys, watchlists, saved views, alerts, scanners, community records, legacy marketing-list records, analytics, billing, and any professional-circuit records require separate handling as applicable. A request is not complete merely because browser storage was cleared or the worldview transaction ran. Public community artifacts may need to be de-identified rather than removed where deleting one contribution would also remove another person's record.
Selecting “Reject analytics” in Privacy choices attempts to remove JavaScript-accessible analytics and affiliate-attribution storage. Clearing site data in your browser removes local analytics, affiliate, and voter cookies immediately.
Floor-protected aggregate releases and historical aggregate records are not rewritten to remove one former participant. Future computations exclude deleted user-level worldview data.
You can delete your account yourself, at any time, without asking anyone. The page lists exactly what goes and what does not, before you confirm.
Email privacy@worldeventtrading.com to request a copy of your data, withdraw newsletter consent, or request removal of a legacy marketing-list record.
One thing worth knowing about email sign-in
Signing in by emailed code means anyone with access to your mailbox can access your WET account. That is an acceptable trade for a beta whose stakes are saved index selections, and it is why an email session on its own can never authorize a payment or a membership change — those stay behind Stripe's own checkout and billing portal.
Related
See also the risk disclaimer, which covers market data accuracy and trading risk, the security page, and the terms of use. W.E.T. is not an exchange and never takes your order flow.