Privacy Policy
Last updated:
1. What we collect
HyperTap is non-custodial — we never see your seed phrase or master-wallet private keys. We do receive: (a) your master wallet address when you sign in with Ethereum (SIWE) or Privy; (b) the public address of the trading key your master wallet approves; (c) a device identifier we generate locally for install attribution; (d) an Expo push token if you grant notification permission; (e) order metadata (asset, side, size, price) when you submit a trade so we can relay it to Hyperliquid and persist bracket-order linkages; (f) preferences you set in Settings.
2. What we do not collect
We do not collect browsing history outside the App, or data from third-party apps. We do not sell personal data to advertisers. Email addresses are collected only when you use social login (via Privy) or contact support.
3. Why we collect it
To authenticate you, relay your signed orders to Hyperliquid, deliver alerts and fill notifications, calculate and pay referral fees, and enforce geographic restrictions required for leveraged derivatives.
4. Where it lives
User records, sessions, bracket-order linkages, alerts, push tokens, and referral attributions live in our managed Postgres database. Live price data is cached in Redis. Aggregate logs are retained for 30 days. WalletConnect users: the trading-key private key stays on your device in the secure enclave. Email/social-login users: the trading key is encrypted under AWS KMS on our servers — it has the same Hyperliquid permissions and still cannot withdraw.
5. Third parties
Hyperliquid (your signed orders go to api.hyperliquid.xyz). WalletConnect / Reown (wallet connection). Privy (optional social login + embedded wallet). Expo Push (notification delivery via APNs / FCM). Apple App Store + Google Play (distribution + crash reports per their policies). We do not use third-party advertising or session-replay tools.
6. Your rights
You can revoke your trading key, sign out, and delete your local data at any time from Settings. To request deletion of server-side records, email [email protected]; we'll respond within 30 days. We retain the minimum data necessary to comply with regulatory requirements (notably referral payouts and audit logs).
7. Security
All traffic is TLS-encrypted. Sessions are signed and rotated. WalletConnect trading keys are stored in iOS Keychain / Android Keystore behind biometric authentication when you enable it. KMS-held keys are encrypted at rest with AWS KMS in production. We do not store master wallet private keys.
8. Children
HyperTap is not directed to children under 18. We do not knowingly collect data from anyone under 18.
9. Changes
We may update this policy from time to time. Material changes will be surfaced in-app before they take effect.
10. Contact
Privacy questions: [email protected].