Tennis Magic AIThe intelligence layer for smart trading on Kalshi, Polymarket & beyond

Security

A short, honest summary of how we protect your data and your money.

Paper balances are not real funds

Ordinary subscriber and promo accounts receive a simulated $100,000 wallet. Tennis Magic AI does not request their Kalshi password or API key, does not connect their Kalshi account, and cannot send a real subscriber order.

Where your card information lives

Your full card number lives at Stripe. Stripe is a PCI-DSS Level 1 service provider. Card data enters Stripe's hosted iframe and never touches our servers. We see only the tokenised customer ID, the last-4 digits of the card, the subscription status, and dispute/refund events.

Ordinary accounts do not store Kalshi credentials

Transport security

Account security

What we deliberately do not store

If we discover a breach

We will notify affected users without undue delay and as required by applicable law (GDPR/UK 72-hour rule for serious incidents). Notifications go to the email tied to your Stripe subscription. We will explain what happened, what we did, and what you should do next.

Reporting a security issue

If you have found a security issue, please send a private report through /contact with the topic "Security / privacy" and we will route it to the engineering team within one business day. Please do not disclose the issue publicly before we have responded. We treat responsible reporters well.

Full data handling is described in our Privacy Policy. Full legal terms are in our Terms of Use.