Legal
Privacy Policy.
This policy describes information the Molecule site and API actually process. Molecule is currently operated as an independent early-stage software project. It does not hold customer funds, and it does not sell personal information.
Updated 28 September 2026
1. Information we collect
If you create an account, Molecule stores an email address, a password hash, an organization name, a role, and a subaccount name. The password is not stored in plaintext. It is hashed with PBKDF2-HMAC-SHA256 at 210,000 rounds.
A session record stores a hash of the session token, an expiry, and whether the session was revoked. The browser receives an HttpOnly cookie named molecule_session (SameSite=Lax, 12 hours, Secure when the API runs in production). The desk also keeps that token in sessionStorage for the open tab and removes it on logout. It is not written to localStorage.
API keys store the public key, permissions, status, and a last-used time. The private key is returned once at creation and is not stored. Venue credentials, if you connect one, are stored as AES-GCM ciphertext together with the venue name and status.
The API stores the orders, fills, positions, balances, and PnL it needs to show the desk, plus risk-limit state and a note when a risk check rejects an order. Instrument rows can include a venue payload used to describe the contract.
The marketing site does not require an account. It does not run an analytics or error-monitoring product. The contact form does not save your message on the server. It opens an email draft in your mail client.
The desk saves UI preferences in localStorage on your device: watchlists, favorites, chart options, column order, and similar settings. That stays in the browser.
2. How we use information
Account and session data are used to sign you in and to scope the desk to your organization and subaccount. Orders, fills, positions, balances, and PnL are used to show the blotter and to send the instructions you submit. Risk state is used to apply the limits configured on the account. Contact email is used to answer the message you chose to send.
3. Connected venue information
If you connect Kalshi or Polymarket, Molecule processes what those connections need: the encrypted credential, market data for the contracts you look at, and the orders, executions, positions, and balances required to show and reconcile the book. Public market data is requested from those venues’ APIs through the Molecule host so the browser can read it. The venue sees the request as coming from that host. Molecule does not decide contract outcomes and does not take custody of the balance the venue reports.
4. How we share information
Connected venues receive the orders and credentialed requests you authorize. The public site is hosted on Vercel. The API is hosted on Railway. Those providers process traffic as part of running the service, which can include connection logs on their side. Molecule does not sell personal information and does not share it with advertisers. There is no separate analytics vendor in the site.
5. Security
Passwords are stored as PBKDF2-HMAC-SHA256 hashes. Venue secrets are encrypted with AES-GCM before they are written down. API private keys are not stored after the one-time display. The session cookie is HttpOnly. These are the controls in the current code. They are not a certification, and they are not a promise that the service cannot be compromised.
6. Data retention
There is no fixed deletion schedule. Information is kept as reasonably necessary to operate the service, keep it secure, resolve a problem, meet an obligation that actually applies, and enforce the terms. The current API deployment can lose its database when the service is redeployed. Do not treat it as a permanent archive. The venue keeps its own records, and Molecule cannot delete those.
7. Your rights and choices
There is no separate privacy office. You can log out, which clears the tab session, and you can clear site data in the browser to remove local desk preferences. Disconnecting a venue stops new use of that credential. It does not erase the venue’s own history.
8. Cookies and similar technologies
The API sets one session cookie, molecule_session, described above. The desk uses sessionStorage for the tab session and localStorage for UI preferences. The marketing site does not set analytics cookies or advertising cookies.
9. Children's privacy
Molecule is not directed at children. It does not knowingly collect personal information from anyone under 13. If a child has submitted an account, that account can be removed.
10. Changes to this Policy
If what the software stores or shares changes in a material way, this page will be updated and the date above will change.