Privacy policy
What we collect, why, and how to get rid of it. Written to be read, not to be survived.
The short version. We collect your email address, a display name, an optional profile photo, your phone number, and the predictions you make. Your display name, your photo, your points and your standing are public — that is the product. Your email address is not. Your named probability on an event stays private from the field until that event locks; accepted friends can see it once they have called the same event, and can leave a private note on that number that only the two of you see. Your profile at /me (and /p/… for anyone else) shows your name, photo, ranks, and any links you added; accepted friends also see which stories you liked and which you have called. Scroll and the tournament slate show a histogram after you release the slider — the field's anonymous buckets once that question has a thousand calls, or a shape drawn from a pinned public-market price until then, labelled as a citation of that market — with named friend avatars on that bar after you have saved yours. There is no advertising, and nothing follows you onto other websites. We use PostHog to see which pages are used; it does not advertise or sell your data. A generated for/against argument of related coverage, when shown, is written by OpenRouter from those headlines and article extracts — not from anything about you. If you type a follow-up on a story, that question is sent to OpenRouter with a Google News search; we do not keep it. You can export everything we hold or delete your account yourself, at any time, from your account page.
1 Who we are
Leaderboard is a free game about forecasting real-world events, at www.theworldleaderboard.com. Leaderboard is operated by its founding team in Australia. An operating company is being established; when it is registered, its name and ABN will be published here and will assume these obligations.
This policy covers the website and the emails we send. It does not cover anything you reach by leaving the site — the resolution sources we link to have their own policies.
For anything in this policy, including a request or a complaint, write to theworldleaderboard@gmail.com.
2 What we collect
All of it, in full:
- Your email address
- From Google if you sign in with Google, or from you if you sign in by emailed link. It is your account identity and how we send you results. We never sell or share it.
- Your phone number
- Collected once, the first time you sign in, alongside a tick box confirming you are 18 or over. We do not verify either — the checkbox is self-attestation, not identity verification — and neither is public.
- Your display name
- Taken from your Google profile or chosen by you, and changeable at any time. It is public. If you would rather not be identifiable, use something that isn't your name — nothing checks it.
- Your profile photo
- Optional. You upload it from your account page; we store the file and show it wherever your display name appears (standings, comments, friends, your track record). It is public. You can replace or remove it at any time. If you do not set one, we show initials from your display name. A coloured ring around the photo (or the initials) shows how many calls you have made and, once at least three of those have resolved, your average accuracy. That ring is computed from your predictions when the page loads — we do not store a separate level. The ladders are on the progression page.
- Public links you choose to publish
- Optional. Substack, Linktree, and a website URL, stored in
player_linksand shown on your profile. You add or remove them on your account page. https only; Substack and Linktree have to be on those hosts. Anyone who can see the profile can open them. - Whether the account is an operator test bot
- A flag on the account used only for synthetic players we mint while testing (local development only). A real account is never a bot. The flag is included in a data export. Test bots show a robot icon wherever a photo or initials would appear, are not sent to PostHog, and never receive result emails.
- Your predictions and entries
- The probability you set on each event (the number that scores), the first probability you released before you saw the field histogram (`predictions.pre_reveal_probability_bp`, kept even if you then moved the slider), which event you designated as THE CALL, which tournaments you entered, and when each was saved. Saving also stamps two reference numbers alongside your call — where the field average and the pinned market's price stood at that moment (`predictions.field_mean_bp_at_call`, `predictions.market_yes_bp_at_call`) — so the scroll can tell you what has moved since. The pinned market at first release (`predictions.market_yes_bp_at_first`) is kept separately, even if the pin arrives later or you move the slider, so standings can say how far you sat from the pinned public-market price before you saw the field and after. The field average is about other callers; the two market stamps are about the pin, not about you; all three are in your export. Friends, standings, and the field histogram use the scoring number, not the first-release one.
- Your groups
- Groups you create or join — including groups an accepted friend added you to — their names, and their invite codes. If you did not create the group, you can leave it.
- Your friends
- Friend requests you send or receive, and the accepted friendships that follow. A friendship is mutual: both people have to agree. We do not store a colour for a friend — the colour you see is assigned when the page loads, unique among your friends, and is not a fact we hold about them.
- What you post
- Comments on events, including replies nested under other comments at any depth (`comments.parent_id`), comments you like, comments you report, questions you like, and private notes on a friend's call (`call_notes`) — a 1:1 thread on their probability, visible only to the two of you, not the event's public CHATTER. You can start that thread from the question page or by tapping their avatar on Scroll. Incoming notes show in your Inbox. A question like is on the wording, not a particular tournament slot — two events that share a question share one count. The count is public; who liked it is not listed on the story. Accepted friends can see the list of questions you liked on your profile. Reports identify the reporter to us so the same comment or note cannot be reported repeatedly by one person; they are not shown to the person reported.
- Follow-up questions on a story
- If you type a question under THE STORY, we send that text, the forecasting question, and article extracts from the coverage on the card to OpenRouter, and we run a Google News search for it. We do not store the question or the answer — they live only for that request. Signed-in only.
- A record of what you did
- Timestamped entries for signing in, submitting or updating a slate, creating or joining a group, and posting or reporting a comment. We use it to understand how the product is used and to investigate abuse. Opening Inbox records the time (`players.call_inbox_seen_at`) so we can badge notes you have not seen yet — it is a cursor, not a copy of the messages.
- Emails we generated for you
- A copy of each notification — its subject, its text, and whether it sent — so we can tell whether you were told about a result. Two kinds: a notice when an event you called resolves, corrects, or voids, and a daily nudge on the mornings one of your calls resolves or locks. The nudge stamps when it last went out (`players.last_nudged_at`) so you never get two in a day. The result-email switch on your account turns both off.
- Sign-in records
- If you use Google, the sign-in library stores your name, email, whether the address is verified, your profile image URL, and the access tokens Google issues. We do not request access to anything in your Google account beyond your basic profile.
- How you use the site
- Which pages you open, what you click, your browser and device, and a rough location derived from your IP. This is processed by PostHog so we can see how the product is used. Until you sign in it is tied to a random identifier in your browser, not to you. After you sign in it is tied to your player id and display name — never your email. Operator test bots are not identified. We do not record a video of the session.
- Standard server logs
- Our hosting provider records the usual request data — IP address, browser user agent, the page requested, the time — for security and operations. We do not use it to build a profile of you.
What we deliberately do not collect. No passwords, because there are none to choose. No payment details, because nothing is for sale. No advertising pixels, and nothing that follows you onto other websites. PostHog is product analytics for this site, not a tracker that reports you elsewhere.
3 What is public and what is not
Public to anyone, signed in or not: your display name, your profile photo if you uploaded one (or a robot icon if the account is an operator test bot), the coloured ring around it that shows your call count and accuracy, your position and points in any tournament you entered, your track record across tournaments, the public links you added (Substack, Linktree, a website), your comments, and the number of likes on a question. Each player has a profile at /p/…; yours is also /me when you are signed in.
Visible to anyone holding a group's invite code: that group's name, everyone in it by display name, and their standings. Invite codes are meant to be shared, and a link has to work before the person clicking it has joined — so treat a code as public once you have sent it, and expect a group you are in to be as visible as its most careless member's sharing. An accepted friend who is already a member can add you in one click; that is the same visibility as if you had joined yourself.
Visible to your accepted friends: the probability you set on an event (the number that scores — not the first-release guess stored when the field histogram appeared), once they have also called that event. This is the one named-person exception to the field staying hidden until lock. Strangers never see your number next to your name until then. A friend who can see your number can leave a private note on it; only the two of you see that thread — your other friends cannot. On your profile they also see which questions you liked and which events you have called; the named percent on those calls still waits until they have called the same event. On Scroll and on your tournament slate, a signed-in player who releases the slider sees a histogram under the track. Once that question has a thousand calls, the bars are an anonymous 10-point bucket of everyone else — not a name. Until then, if the event is pinned to a public prediction market, the bars are a crowd-shaped stand-in around that market's last stored Yes, labelled as a citation of the market, not as a player headcount. After they lock that call in, accepted friends who have called the same event appear as named avatars on that bar at their percent. You can tap an avatar to send a private note on their call; incoming notes land in your Inbox. A friend-add link identifies your account the same way a group invite identifies a group — treat it as public once you have sent it.
Private from the field until an event locks: the probability you set on it. Nobody outside your accepted friends sees that you called a named percentage — not other players, not the published field average — until that event's lock passes. On Scroll and the tournament slate, once someone releases the slider they see a histogram under the track: the field's anonymous buckets after a thousand calls on that question, or a market-shaped placeholder until then. Your number can sit in a 10-point bucket there without your name. After they have saved, an accepted friend who has also called sees your named avatar on that bar. After the lock, your number contributes to the published field statistics.
Public only by your hand: a resolved call of yours — your display name, your number, the field's, the outcome, the points — appears on a page and a share image at a signed link (/called/…) that only you can mint, from the Share button on the results card or the link in your result email. Anyone you send it to can see it and pass it on; nobody can guess it. Open calls are never shared this way.
Never public: your email address, your sign-in records, which comments you liked or reported, your activity log, private notes on a call, when you last opened Inbox, and the first probability you released before the field histogram — friends, standings, and the field see only the later scoring number. Question likes are listed to accepted friends on your profile, not to everyone.
Because standings are public, a search engine may index a page your display name or photo appears on. Changing your display name or photo changes it everywhere on the site at once, including on finished tournaments, but we cannot recall a copy someone else has already made.
5 Who else handles your data
We do not sell your data and we do not share it for anyone else's marketing. It is handled by the services that run the product, and by nobody else:
- Vercel — hosting, content delivery and server logs.
- Supabase — the database everything is stored in, hosted in Singapore, and the sign-in service: Google confirmation and magic-link emails when that path is on. The app queries Postgres as the table owner, not through Supabase's Data API.
- Google — to confirm who you are if you choose to sign in with Google, and, when you ask a follow-up on a story, as the Google News RSS search for that question (the query is the story plus what you typed; it is not attached to your account).
- Our email provider — to deliver the notices telling you an event resolved and the daily nudge on the mornings a call of yours resolves or locks. Sign-in links are sent by Supabase when that path is on, or by this same SMTP sender on the older Auth.js path.
- PostHog — product analytics. Pages you visit, clicks, browser, and (once you sign in) your player id and display name. Hosted in the United States unless we switch the project to the EU. Session recordings are off. PostHog's privacy policy.
- OpenRouter — when a related-coverage argument is shown (on Scroll and the question page), the headlines, publisher names, and article extracts we fetch from those pages — not the full pages, and nothing about you — are sent to OpenRouter to write THE STORY brief and the for/against card. If you ask a follow-up on a story, the question you typed is sent too, with those extracts; we do not keep it. If the key is not configured, no card is shown, the follow-up field fails closed, and nothing is sent. OpenRouter's privacy policy.
Your data is stored outside Australia. The database is in Singapore, our hosting provider is a United States company, and PostHog is too, so your information is held and accessed overseas. Headlines and article extracts sent to OpenRouter for a coverage argument, and a follow-up you type on a story, also leave our servers (United States). If that is not acceptable to you, the remedy is not to create an account.
We will disclose data if the law requires it, and we will tell you when we are permitted to.
6 How long we keep it
While your account exists, we keep it. Your predictions and results are the point of the product, so they are not expired on a timer.
When you delete your account, the deletion runs immediately: your predictions, entries, slates, group memberships, friendships, likes, reports, notes on friends' calls, notification records, profile photo and sign-in records are erased, the text of your comments is removed, and your name is unlinked from anything that survives. Your record of activity is kept but de-identified — the rows stay so our usage counts remain honest, with nothing left connecting them to you. We also ask PostHog to delete the person tied to your player id.
Two honest caveats. Deleted comments leave an empty "[removed]" placeholder where someone has replied, at any depth in the thread, so the conversation still makes sense; nothing of yours remains in it. Notes on a friend's call are deleted outright — that thread is only the two of you, so there is nobody else who needs a placeholder. And for a short period afterwards your data may still exist in our database provider's routine backups, which are overwritten on a rolling schedule — we do not read them and we do not use them to restore a deleted account.
7 Your control over it
- See it
- Your account page downloads everything we hold about you in our database as a single file, immediately, no request needed. Two things are deliberately left out, and the file says so where they would have been: the access tokens your sign-in provider issued (credentials rather than information about you), and page views processed by PostHog (they are not stored in our database; deleting your account asks PostHog to delete them too).
- Correct it
- Change your display name, profile photo, and public links yourself on the same page. To change the email address your account is under, write to us — it is your identity here, so we move it by hand rather than let it be reassigned in a form.
- Delete it
- Also on your account page, immediately and permanently, without asking anyone. There is no cooling-off period and no undo, which is why the page makes you type your name to confirm.
- Stop the email
- Turn off result notifications on your account page. Sign-in links keep working, because that is how you get in.
- Complain
- Write to theworldleaderboard@gmail.com and we will answer. If you are in Australia and we have not resolved it, you can take a privacy complaint to the Office of the Australian Information Commissioner.
8 Security
The site is served over HTTPS. Session cookies are signed and inaccessible to JavaScript. We store no passwords at all, which removes the single most damaging thing a breach of a site like this could leak — there is nothing here that would unlock your other accounts.
No system is immune. If we ever suffer a breach affecting your data we will tell you and the relevant authority, promptly and in plain language.
9 Age
Leaderboard is for people aged 18 and over, and accounts are not knowingly created for anyone younger. You confirm this yourself with a tick box the first time you sign in — a self-attestation, not an identity check — before you can do anything else on the site. If you believe a child has an account, tell us and we will delete it.
10 Changes to this policy
The date at the top of this page is the date the text last changed in substance. If we change something that matters — what we collect, who handles it, what becomes public — we will say so on the site rather than quietly reissue the page.