Privacy Policy

Last updated: August 6, 2026

This Privacy Policy explains how HL Vaults ("Platform", "we", "us", "our") handles your information when you use the Platform. It aligns with our Terms of Service.

What we store locally

The analytics features of the Platform run entirely in your browser. The following data is stored in IndexedDB and localStorage and is never transmitted to any server we control:

  • Wallet addresses you enter for portfolio tracking
  • Vault notes and annotations
  • Custom screen configurations
  • AI provider settings (endpoint URL, API key, model preferences)
  • Performance threshold settings
  • Signed agreement messages ("Remember Me")
  • UI preferences (privacy mode toggles, theme, dismissed banners)

What we store server-side

If you subscribe to a paid plan (Growth or Pro), we store the following information to manage your subscription:

  • Wallet address — used to identify your account and verify payment status
  • Subscription tier — Free, Growth, or Pro
  • Subscription status — active, expired, or cancelled
  • Billing period dates — when your current billing period starts and ends
  • Account balance — USDC deposits credited to your account after on-chain confirmation, applied to subscription payments
  • Account credit ledger — records of all movements on your account balance (deposits, credits granted to or reversed against your account, and subscription payments drawn from it; including amount, reason, and the operator who recorded them), retained for audit and billing purposes

This information is considered personal information. We store the minimum necessary to operate the subscription service. Your wallet address may be considered personal data under applicable privacy laws (e.g., GDPR) when linked to your subscription information.

Payments

Paid plans are funded by depositing USDC to the deposit address shown for your account. The deposit address is an on-chain smart contract address, and the deposit transaction is public blockchain data. We do not operate a wallet or payment processor, and we never receive or store payment card numbers, bank account details, or any other financial instrument data.

What we never collect

  • Your name, email, phone number, or physical address
  • Passwords or private keys
  • Payment card numbers, bank account details, or financial instrument data
  • Browser fingerprints or device identifiers
  • Session recordings or click tracking

We may process technical information (such as your IP address) transiently for security and abuse prevention (for example, rate limiting). It is not used to build a profile of you and is not retained beyond what is operationally necessary.

Cookies

The Platform uses cookies and similar local storage technologies for the following purposes:

  • Essential cookies: Required for basic functionality, including session management, user preferences (privacy mode, theme, performance settings), and security features. These cannot be disabled through the cookie consent banner.
  • Preference cookies: Used to remember your settings and choices, such as column layout, screen configurations, and vault type filters.
  • Analytics cookies: Used to understand how users interact with the Platform and how it can be improved.

Upon your first visit, a cookie consent banner is displayed offering you the choice to accept all cookies or reject non-essential cookies. Cookie data is kept entirely in your browser's localStorage and IndexedDB and is not transmitted to any server we control. You can change your choice at any time by clearing your browser data for this site.

We do not use third-party advertising cookies. The Platform may load resources from third-party CDNs and API endpoints (Hyperliquid RPC), which may set their own cookies subject to their respective policies.

How we use your data

Locally stored data

Data stored in your browser is used exclusively to power the analytics features you interact with. It is never transmitted to our servers.

Server-side data (paid subscriptions)

Your wallet address, subscription tier, billing dates, and account balance are used solely to:

  • Verify your access to paid features
  • Manage billing cycles and your account balance
  • Communicate about subscription status changes (e.g., expiry notifications)

Data that leaves your browser

  1. Public blockchain queries — Wallet addresses you enter are sent to Hyperliquid RPC endpoints to fetch public on-chain data. This is necessary for the Platform to function.
  2. AI API requests — If you configure an AI provider in Settings, vault data is sent to your chosen LLM provider for analysis. This is sent under your API key, not ours. We have no access to these requests or responses.

Third-party services

The Platform integrates with:

  • Hyperliquid RPC endpoints — For querying public vault and wallet data. Your wallet address may be included in these requests.
  • Your configured AI provider (e.g., OpenAI, Groq, OpenRouter) — Vault context is sent to your chosen provider under your API key.

We are not responsible for the data handling practices of these third-party services. Please review their respective privacy policies.

Data retention

Local data

All locally stored data remains in your browser until you:

  • Clear your browser data (settings → privacy → clear site data)
  • Disconnect your wallet (clears agreement messages)
  • Remove individual vault notes or wallet entries

Server-side data (paid subscriptions)

Subscription data is retained for the duration of your subscription plus a reasonable period thereafter for billing and legal purposes. Account credit ledger records are retained for as long as needed for audit, billing, and legal purposes. You may request deletion of your subscription data by reaching out through the HL Vaults app.

Data security

Your data is protected by:

  • Local data — Protected by your browser's security model. IndexedDB and localStorage are sandboxed per origin.
  • Server-side data — Stored securely with access limited to authorized systems and personnel necessary for subscription management.
  • Your control — You can clear locally stored data at any time through browser settings.

We recommend keeping your browser updated and using strong device security practices.

Your rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal information we hold about you
  • Request correction or deletion of your personal information
  • Withdraw consent where processing is based on consent
  • Lodge a complaint with a data protection authority

To exercise these rights, reach out through the HL Vaults app.

Children's privacy

The Platform is not intended for users under 18 years of age (or the age of majority in your jurisdiction). We do not knowingly collect information from minors.

Changes to this policy

We may update this Privacy Policy from time to time. Changes will be posted on this page. Continued use of the Platform after changes constitutes your acceptance of the updated policy.

Contact

For questions about this Privacy Policy, please reach out to the project maintainers through the HL Vaults app.


HL Vaults — Privacy Policy v1.4

This site stores data locally in your browser for essential functionality — vault data, preferences, and settings are saved via localStorage and IndexedDB. We also use cookies and similar technologies for analytics and preference remembrance. You can accept or reject non-essential cookies. Learn more.