Hyperlens
Trade Portfolio Smart Money
Market Makers Points Liquidations Funding Arbitrage Blog
Theme
Notifications
Trade Portfolio Smart Money
More
Market Makers Points Liquidations Funding Arbitrage Blog
Hyperlens

Forgot password?

At least 8 characters. Not all numbers, and not a commonly used password.

By creating an account you agree to our Terms and Privacy Policy.

// Legal

Privacy Policy

Last updated: July 21, 2026

1. Who We Are

This Privacy Policy describes how Hyperlens ("Hyperlens," "we," "us," or "our") handles information when you use hyperlens.io, our analytics dashboards, trading interface, account features, support channels, and related services (together, the "Service"). The controller of your information is the legal entity operating Hyperlens; for privacy questions or requests, contact us at [email protected].

Hyperlens is a non-custodial interface over Hyperliquid. We do not custody user funds, do not perform KYC, and do not request seed phrases or main-wallet private keys.

2. Information We Collect

We collect information you provide, information generated by your use of the Service, and information available from public sources.

  • Account information: email, username, password hash, login state, and any wallet address linked to your account.
  • Wallet authentication: public wallet address, Sign-In with Ethereum message, nonce, signature, and chain ID.
  • Public blockchain and market data: wallet addresses, transactions, orders, fills, positions, liquidations, funding, open interest, and builder activity available from Hyperliquid or related public sources.
  • Trading activity in-app: selected market, order parameters, account mode changes, builder fee approvals, agent wallet status, and transaction responses generated when you use trading features.
  • Technical data: IP address, browser and device type, operating system, referring page, pages viewed, timestamps, approximate location derived from IP, logs, errors, and performance data.
  • Support and communications: your email, Telegram handle, messages, attachments, and any details you choose to send to us.
  • Session interactions: mouse movement, clicks, scrolls, and session replays captured by PostHog when replay features are enabled (see Section 6).

For California residents, the categories above correspond to "identifiers," "internet or other electronic network activity," "geolocation data" (approximate, IP-derived), and "inferences" under the CCPA/CPRA. We do not knowingly collect Sensitive Personal Information as defined by the CPRA.

3. How We Use Information

We use information to operate, secure, and improve the Service. Specifically:

  • Create and authenticate accounts, verify wallet ownership, and maintain sessions.
  • Display analytics, dashboards, leaderboards, and trading screens.
  • Route signed trading actions and builder fee approvals you initiate to Hyperliquid.
  • Debug errors, monitor uptime, prevent fraud and abuse, and protect the Service.
  • Respond to support requests and send service-related notices.
  • Measure usage and improve product design.
  • Comply with applicable law, respond to legal requests, and enforce our Terms.

4. Wallets, Signatures, and Agent Wallets

Your main wallet remains under your control. We never request, collect, or store your seed phrase or main-wallet private key. All wallet signatures are produced by your wallet provider.

  • Sign-In with Ethereum: your wallet signs a message proving control of a public address. We process the message, nonce, signature, and address to verify the login.
  • Trading connection: your browser wallet builds a signer for the selected account; the main-wallet key never leaves your wallet.
  • Agent wallets (one-click trading): when you opt in, your browser generates an agent key and your main wallet approves it on Hyperliquid. The agent record (master address, agent address, agent private key, expiry) is stored in your browser's local storage under a key prefixed hl_agent_. Hyperlens does not transmit, back up, or otherwise receive the agent key.
  • Revocation: disconnecting in Hyperlens removes the local agent record from that browser. To revoke at the protocol level, use the Hyperliquid API page or any Hyperliquid-supported agent management tool.

For an explanation of the risks of storing an agent key in browser local storage, see our Terms of Service.

5. Cookies and Local Storage

We use cookies, local storage, and similar technologies for the categories below.

  • Strictly necessary: session, authentication, and CSRF tokens. Required for the Service to function.
  • Preferences: trading layout, chart interval, order-book settings, leverage, confirmations, and other UI state.
  • Agent wallet storage: the hl_agent_ record described in Section 4, only if you enable one-click trading.
  • Analytics and session replay: Google Analytics and PostHog. Enabled PostHog replay features may record interactions and reconstruct sessions; we configure sensitive fields to be masked where supported, but on-screen content (such as displayed wallet addresses and balances) may be captured.

You can clear cookies and local storage at any time through your browser. Doing so may sign you out and remove locally stored agent records and preferences. You can opt out of Google Analytics with the official browser add-on.

6. Service Providers and Recipients

We share information only as needed to operate the Service:

  • Analytics: Google (Google Analytics) and PostHog — usage, event, and session data.
  • Hyperliquid infrastructure: read requests and signed actions that you initiate. Hyperliquid is independent infrastructure, not our processor; your interactions with it are also governed by Hyperliquid's own terms.
  • Wallet providers and browser extensions: handle connection and signing under their own privacy practices.
  • Hosting, database, security, logging, and email providers: process information needed to keep the Service available and secure.
  • Legal recipients: regulators, courts, or law enforcement when required by law, valid legal process, or to protect rights, safety, and security.
  • Corporate transactions: potential or actual acquirers, advisors, and auditors in connection with a merger, financing, or asset sale.

We do not sell or share Personal Information for monetary or other valuable consideration, including for cross-context behavioral advertising as those terms are defined by the CCPA/CPRA. We honor the Global Privacy Control (GPC) signal as a valid opt-out where applicable.

7. Public Blockchain Data

Blockchain data is permanent, replicated by many parties, and publicly visible. We may index, cache, transform, and display public blockchain and market data to provide analytics and trading context. We cannot alter records on Hyperliquid or any underlying chain.

If you make a valid erasure request, we will remove personal information we control and stop displaying or indexing information that identifies you to the extent feasible. We cannot delete the underlying on-chain records, and third parties may continue to display them.

8. Where We Process Data

We and our service providers process information primarily in the United States. By using the Service, you understand that your information may be transferred to, stored in, and processed in the United States and other countries where our providers operate.

9. Data Retention

  • Account records: retained while your account is active and for up to 24 months after deletion for security, fraud prevention, and dispute resolution.
  • Support communications: retained for up to 24 months from the date of the last related contact.
  • Server logs and error diagnostics: retained for up to 90 days.
  • Analytics data: retained according to our provider and project settings (Google Analytics: 14 months; PostHog: according to the configured project retention period).
  • Local browser data: remains on your device until you or the browser clears it.
  • Public blockchain records: outside our control and may persist indefinitely.

We may keep information longer where required by law, to enforce our Terms, or to resolve an active dispute.

10. Security and Breach Notification

We use access controls, secure session handling, CSRF protection, password hashing, monitoring, and least-privilege practices. No system is perfectly secure.

If a security incident affects your personal information, we will notify you and the appropriate authorities where required by law and within the applicable statutory time frames.

You are responsible for the security of your wallet, device, browser profile, seed phrase, private keys, and approved agents. Hyperlens will never ask for your seed phrase, main private key, password, or agent private key.

11. Your Rights

Subject to applicable law, you may have the right to access, correct, delete, port, or opt out of certain processing of your personal information. To exercise these rights, email [email protected]. We may need to verify your identity before acting. We will not discriminate against you for exercising your rights.

California, Colorado, Connecticut, Virginia, Utah, and similar U.S. states. You have the right to know, delete, correct, and opt out of "sale" or "sharing" of personal information (none of which we engage in for monetary consideration), and the right to limit use of Sensitive Personal Information (which we do not knowingly process). You may designate an authorized agent to act on your behalf and appeal a denied request by replying to our decision.

12. Children

The Service is intended for users who are at least 18 years old. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided information to us, contact [email protected] and we will delete it.

13. Changes to This Policy

If we make material changes to this Policy, we will update the date above and provide additional notice through the Service. Continued use of the Service after an update means the updated Policy applies.

14. Contact

Privacy questions and rights requests: [email protected]. General support: [email protected]. You can also reach us on Telegram at t.me/HyperlensIO — do not post private keys, seed phrases, passwords, or other sensitive information there.

© 2026 Hyperlens
Blog Terms Privacy Contact