Privacy Policy
Last updated: July 24, 2026
This Privacy Policy explains how HL Vaults (“Platform”, “we”, “us”, “our”) handles your information when you use the Platform. It aligns with our Terms of Service.
What we store locally
Section titled “What we store locally”The analytics features of the Platform run entirely in your browser. The following data is stored in IndexedDB and localStorage and is never transmitted to any server we control:
- Wallet addresses you enter for portfolio tracking
- Vault notes and annotations
- Custom screen configurations
- AI provider settings (endpoint URL, API key, model preferences)
- Performance threshold settings
- Signed agreement messages (“Remember Me”)
- UI preferences (privacy mode toggles, theme, dismissed banners)
What we store server-side
Section titled “What we store server-side”If you subscribe to a paid plan (Growth or Pro), we store the following information to manage your subscription:
- Wallet address — used to identify your account and verify payment status
- Subscription tier — Free, Growth, or Pro
- Subscription status — active, expired, or cancelled
- Expiry date — when your current billing period ends
- Payment transaction reference — identifier returned by our payment processor
This information is considered personal information. We store the minimum necessary to operate the subscription service. Your wallet address may be considered personal data under applicable privacy laws (e.g., GDPR) when linked to your subscription information.
Payment processing
Section titled “Payment processing”Payments are processed by a third-party payment processor. We do not receive or store full payment card numbers, bank account details, or any other financial instrument data. The payment processor operates under its own privacy policy and terms of service.
What we never collect
Section titled “What we never collect”- Your name, email, phone number, or physical address
- Passwords or private keys
- IP addresses (we do not operate logging infrastructure)
- Browser fingerprints or device identifiers
- Session recordings or click tracking
Cookies
Section titled “Cookies”We may use cookies and similar technologies to improve your experience, analyze usage patterns, and maintain platform security.
Types of cookies we use
Section titled “Types of cookies we use”| Type | Purpose | Duration |
|---|---|---|
| Strictly Necessary | Session management, CSRF protection, security | Session or persistent |
| Preferences | Remember your UI settings (theme, dismissed banners, privacy mode state) | Persistent |
| Analytics | Anonymous usage statistics to understand how the Platform is used | Persistent |
Your cookie choices
Section titled “Your cookie choices”You can configure your browser to reject cookies or notify you when a cookie is set. Most browsers provide controls in their settings menu.
If you disable cookies, core Platform functionality will not be affected, but some preference features may not persist between sessions.
Third-party cookies
Section titled “Third-party cookies”We do not use third-party advertising cookies. The Platform may load resources from third-party CDNs and API endpoints (Hyperliquid RPC), which may set their own cookies subject to their respective policies.
How we use your data
Section titled “How we use your data”Locally stored data
Section titled “Locally stored data”Data stored in your browser is used exclusively to power the analytics features you interact with. It is never transmitted to our servers.
Server-side data (paid subscriptions)
Section titled “Server-side data (paid subscriptions)”Your wallet address, subscription tier, and expiry date are used solely to:
- Verify your access to paid features
- Manage billing cycles
- Communicate about subscription status changes (e.g., expiry notifications)
Data that leaves your browser
Section titled “Data that leaves your browser”- Public blockchain queries — Wallet addresses you enter are sent to Hyperliquid RPC endpoints to fetch public on-chain data. This is necessary for the Platform to function.
- AI API requests — If you configure an AI provider in Settings, vault data is sent to your chosen LLM provider for analysis. This is sent under your API key, not ours. We have no access to these requests or responses.
Third-party services
Section titled “Third-party services”The Platform integrates with:
- Hyperliquid RPC endpoints — For querying public vault and wallet data. Your wallet address may be included in these requests.
- Your configured AI provider (e.g., OpenAI, Groq, OpenRouter) — Vault context is sent to your chosen provider under your API key.
- Payment processor — For processing subscription payments. We do not receive or store your full financial details.
We are not responsible for the data handling practices of these third-party services. Please review their respective privacy policies.
Data retention
Section titled “Data retention”Local data
Section titled “Local data”All locally stored data remains in your browser until you:
- Clear your browser data (settings → privacy → clear site data)
- Disconnect your wallet (clears agreement messages)
- Remove individual vault notes or wallet entries
Server-side data (paid subscriptions)
Section titled “Server-side data (paid subscriptions)”Subscription data is retained for the duration of your subscription plus a reasonable period thereafter for billing and legal purposes. You may request deletion of your subscription data by reaching out through the HL Vaults app.
Data security
Section titled “Data security”Your data is protected by:
- Local data — Protected by your browser’s security model. IndexedDB and localStorage are sandboxed per origin.
- Server-side data — Stored securely with access limited to authorized systems and personnel necessary for subscription management.
- Your control — You can clear locally stored data at any time through browser settings.
We recommend keeping your browser updated and using strong device security practices.
Your rights
Section titled “Your rights”Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you
- Request correction or deletion of your personal information
- Withdraw consent where processing is based on consent
- Lodge a complaint with a data protection authority
To exercise these rights, reach out through the HL Vaults app.
Children’s privacy
Section titled “Children’s privacy”The Platform is not intended for users under 18 years of age (or the age of majority in your jurisdiction). We do not knowingly collect information from minors.
Changes to this policy
Section titled “Changes to this policy”We may update this Privacy Policy from time to time. Changes will be posted on this page. Continued use of the Platform after changes constitutes your acceptance of the updated policy.
Contact
Section titled “Contact”For questions about this Privacy Policy, please reach out to the project maintainers through the HL Vaults app.
HL Vaults — Privacy Policy v1.1