Privacy Policy
Last updated: June 2026
HyperDCA is built around a simple principle: we collect as little as possible, encrypt what's sensitive, and never touch what could put your funds at risk. This page explains exactly what that means.
What we collect
- Wallet address — your Hyperliquid main wallet address, used to identify your account and look up your positions.
- Trading settings — the DCA strategies you configure (pairs, intervals, sizing, risk toggles) so the engine can run them.
- Push token — an anonymous device token (from Apple/Google via Expo) so we can send you the trading alerts you opt into.
What we encrypt
Your agent wallet key is encrypted at rest using Fernet (AES-128 in CBC mode with HMAC authentication). It is only decrypted in memory at the moment a trade is placed. Without the master key — held separately from the database — the stored value is unreadable.
What we don't store
- Withdrawal keys — we never ask for or hold any credential that can move funds. The agent wallet is trade-only.
- Personal identity — no name, no government ID, no KYC. HyperDCA never asks who you are.
- Email — not required to use the app.
- Browsing history — we don't track you across the web or sell data to anyone.
Third parties
We use a small number of services strictly to operate the app:
- Sentry — error monitoring, so we can fix crashes. Reports are scrubbed of secrets.
- Expo — delivery of the push notifications you enable.
We do not use advertising networks or analytics trackers.
Data deletion
You can delete your account at any time from the app's Settings. This removes your stored wallet address, encrypted agent key, trading settings and push tokens from our servers. Your funds and on-chain history are unaffected — they live on Hyperliquid, not with us.
Contact
Questions about privacy? Email privacy@yourdomain.com.