Privacy Policy
- Last updated
- 6 August 2026
- Effective
- 6 August 2026
01 Introduction
This Privacy Policy (the “Privacy Policy”) explains how BOSCRAE LIMITED, a business company incorporated under the laws of the British Virgin Islands (the “Company”, “we”, “us” or “our”), collects, uses, discloses and otherwise processes information about you when you access or use our web-based or mobile-based user interface known as “Hypro” (the “Interface”) that enables you to access and interact with the Hyperliquid decentralized perpetual-futures and spot trading protocol (the “Hyperliquid Protocol”), including connecting or generating a wallet, viewing market data, constructing and broadcasting transactions, and using builder codes (collectively, the “Functionality”).
This Privacy Policy forms part of, and should be read together with, our Terms of Use (the “Terms”). Capitalized terms used but not defined in this Privacy Policy have the meanings given to them in the Terms. By accessing or using the Interface or the Functionality, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, you must not access or use the Interface or the Functionality.
For the purposes of the British Virgin Islands Data Protection Act, 2021 (the “DPA”) and, to the extent applicable, the EU General Data Protection Regulation (the “GDPR”) and the UK GDPR, the Company is the data controller in respect of the personal data described in this Privacy Policy, except where this Privacy Policy states that a third party acts as a separate or independent controller.
02 Non-custodial service; what we never collect
What we never collect
The Interface is non-custodial. The Company never requests or receives your seed phrase, recovery phrase, wallet password, PIN, biometric template, or any other secret that can be used to control your Wallet. If you use Import Private Key, your key is stored only in your device’s secure storage and is processed locally for signing; it is not transmitted to the Company or our service providers. We can never access, freeze, recover, reverse or move the Digital Assets in your Wallet.
You are solely responsible for the custody and security of your wallet and your Authentication Means, as further described in the Terms. Because we do not hold this information, we cannot help you recover a lost wallet, lost credentials, or lost Digital Assets.
03 Information we collect
We collect the categories of information described below. The amount and type of information we process is deliberately limited, consistent with the non-custodial, software-only nature of the Interface. We do not knowingly collect or process special categories of personal data (such as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade-union membership, genetic data, biometric data processed to uniquely identify a person, health data, or data concerning a person’s sex life or sexual orientation), and we ask that you do not submit any such data to us.
3.1 Information you provide to us
Communications. If you contact us (for example, by email, a support form, feedback submission, or via social or community channels), we collect the information you choose to provide, such as your name or handle, email address, the contents of your message, and any attachments.
Intellectual-property and other notices. If you submit a copyright or intellectual-property notice or counter-notice (as described in the Terms), we collect the information contained in that notice, which may include your name, address, telephone number and email address.
3.2 Information we collect automatically
When you access the Interface, the following technical information may be processed automatically:
- Web delivery and connection data: our hosting, content-delivery-network and security providers necessarily process your Internet Protocol (IP) address, request headers, browser type, requested URL and timestamps to deliver and protect the web Interface. Those providers may derive an approximate country or region from the IP address.
- Mobile diagnostics: when a production Mobile App sends a crash or diagnostic event to Sentry, the event may include the device model, operating-system version, app version and build, runtime and error information, crash stack traces, limited performance information associated with the error, and the operational breadcrumbs described in Sections 3.7 and 3.8, and the randomly generated installation identifier described in Section 3.7.
- Authentication context: if you use Privy authentication, Privy may process your IP address, IP-derived location, device and operating-system type, authentication events and account identifiers to authenticate you, secure the account and provide the Embedded Wallet, as described in Section 3.4.
The Mobile App does not use an advertising identifier, continuous product-usage analytics, session replay or precise location collection.
3.3 On-chain and wallet information
When you connect a third-party Wallet or generate an Embedded Wallet and use the Functionality, we process your public wallet address(es) and associated on-chain information, which may include public transaction data, balances, positions, order activity, and builder-fee approvals and fills associated with your wallet address. You acknowledge that:
- Blockchain data is public, transparent and, by design, permanent and immutable. Transactions you broadcast (including via the Interface) are recorded on a public blockchain that we do not own or control and cannot alter or erase.
- A wallet address is pseudonymous, but it may constitute personal data where it can be linked, directly or indirectly, to an identifiable individual. We do not, by ourselves, link wallet addresses to your real-world identity unless you provide identifying information to us or such linkage results from third-party data described below.
3.4 Information relating to the Embedded Wallet (Wallet Infrastructure Provider)
If you choose to generate an Embedded Wallet through the Interface, that wallet is provided in cooperation with our Wallet Infrastructure Provider (currently Privy.io, Inc. and/or its affiliates, “Privy”). Depending on the login method you select, Privy may collect and process identifiers such as your email address, social-login account identifiers, passkey or device credentials, and key-management metadata, in order to authenticate you and to generate and secure your Embedded Wallet. We may receive from Privy your wallet address and limited account metadata (for example, the authentication method used and account status), but we do not receive your private key material. Privy processes information under its own terms and privacy policy and may act as an independent controller and/or as our processor depending on the processing activity. We encourage you to review Privy’s privacy policy before generating or using an Embedded Wallet.
3.5 Information from other third parties
- Crash-diagnostics providers, currently Sentry, which process the limited diagnostic events described in Sections 3.7 and 3.8.
- Authentication and wallet-connectivity providers, including Privy and Reown, which process information needed to authenticate you or relay encrypted WalletConnect communications.
- Infrastructure providers, including the Hyperliquid Network, RPC nodes, indexers, hosting, Cloudflare R2, content-delivery-network (CDN) and security providers, which process requests and technical connection data needed to provide the Interface.
3.6 Cookies and similar technologies
On the web version of the Interface, we and our service providers may use cookies, local storage, software development kits (SDKs), pixels and similar technologies for purposes such as keeping the Interface functioning, remembering your preferences, maintaining security, and measuring usage and performance. Where required by applicable law, we will request your consent for non-essential cookies and similar technologies, and you can manage your preferences through your browser settings or any consent mechanism we make available. Some browsers transmit “Do Not Track” signals; because there is no common industry standard for responding to them, we currently do not respond to such signals.
3.7 App diagnostics and safety configuration
Production release builds of the Mobile App use Sentry, provided by Functional Software, Inc., to diagnose crashes and operational failures and to improve app reliability. Sentry may process crash stack traces, error classes, device model, operating-system version, app version and build, runtime information, limited performance information associated with an error, and the operational breadcrumbs described in Section 3.8. Sentry’s handling of information is also governed by its own privacy policy, available at https://sentry.io/privacy/.
We configure Sentry with default personally identifiable information disabled. The Sentry SDK does, however, generate a random identifier on first launch, store it on your device and attach it to diagnostic events, so that events originating from the same app installation can be grouped and the number of affected installations counted. That identifier is not derived from your account, email address or wallet address, and we do not link it to them. We do not enable Sentry tracing, profiling or session replay, and we do not use a mobile analytics SDK or advertising identifiers. Before a diagnostic event is sent, the Mobile App removes WalletConnect connection URIs, long hexadecimal secrets and mnemonic-like text from event messages and breadcrumbs. We do not intentionally send seed phrases, private keys, imported private keys, wallet credentials, payment-card data, authentication secrets, wallet addresses, account identifiers, balances, order sizes or order prices to Sentry.
The Mobile App fetches signed safety flags from a Cloudflare R2 endpoint to operate controls such as maintenance mode, read-only mode, order-submission disable flags and minimum supported runtime version. The response contains only the signed configuration. Cloudflare necessarily processes ordinary request connection data, such as the IP address and request headers, to serve it.
3.8 Trading and wallet telemetry
The Mobile App records limited operational breadcrumbs in memory, such as the current screen path, order submission result, market type, order side, time-in-force, reduce-only flag, network, signed-in state, operation timing and broad error category. A breadcrumb is transmitted to Sentry only when it accompanies a crash or diagnostic event; it is not sent as continuous product analytics.
We do not intentionally include order size, order price, balances, wallet addresses, account identifiers, seed phrases, private keys, imported private keys, authentication secrets or wallet credentials in these diagnostic events.
3.9 Imported private keys and local storage
If you import a private key, the key is processed locally on your device to derive the Wallet address and to sign actions. The imported key is stored in your device’s secure storage and is read only when needed for signing. We do not intentionally transmit imported private keys to our servers, Sentry, the Wallet Infrastructure Provider, the Hyperliquid Network, Reown, Cloudflare or any other service provider.
Local app settings — such as selected network, base currency, market favorites, recent markets, biometric-lock setting, notification preference, and locally generated agent keys — may be stored on your device. You can remove local app data by logging out, clearing app data, uninstalling the Mobile App, or using operating-system controls.
3.10 Camera, biometrics, and notifications
The camera is used only to scan WalletConnect and transfer-address QR codes. Camera frames are processed on-device for QR scanning and are not intentionally stored or uploaded by us.
If you enable biometric app lock, biometric authentication is handled by your device operating system. We do not receive or store biometric templates.
If you enable notifications, the Mobile App may request notification permission. The Mobile App currently stores your notification preference locally and does not currently register or transmit a push-notification token for push messaging operated by us. If we add server-side push notifications in the future, we will update this Privacy Policy before using that functionality.
04 How we use information
We use the information described above for the following purposes:
- To provide, operate, maintain and improve the Interface and the Functionality, including connecting your Wallet, displaying market and account data, and constructing and broadcasting transactions that you sign;
- To enable and account for builder codes, including processing your on-chain builder-fee approvals and the builder fees associated with fills submitted through the Interface;
- To provide the Embedded Wallet feature in cooperation with the Wallet Infrastructure Provider;
- To maintain the security, integrity and availability of the Interface, and to detect, investigate and prevent fraud, abuse, security incidents and other prohibited or unlawful activity;
- To comply with legal and regulatory obligations, including sanctions, anti-money-laundering and counter-terrorism-financing requirements, and to operate access controls that restrict access by Restricted Persons (see Section 6);
- To respond to your communications and provide any support we choose to offer;
- To diagnose crashes and operational failures, to measure the reliability and performance of app features from the diagnostic events described in Sections 3.7 and 3.8, and to develop reliability and product improvements; and
- To establish, exercise or defend legal claims, to enforce the Terms, and to protect the rights, property and safety of the Company, our users and others.
05 Legal bases for processing
To the extent the GDPR or UK GDPR applies to our processing of your personal data, we rely on the following legal bases:
- Performance of a contract: to provide the Interface and Functionality you request under the Terms;
- Legitimate interests: to secure, maintain and improve the Interface, to prevent fraud and abuse, and to protect our rights, provided such interests are not overridden by your interests or fundamental rights;
- Compliance with a legal obligation: to meet sanctions, anti-money-laundering and other legal and regulatory requirements; and
- Consent: where required, for example for certain non-essential cookies or similar technologies; you may withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal.
06 How we share and disclose information
We do not sell your personal data. We may share information in the following circumstances:
- Service providers and processors. With vendors that perform services on our behalf, such as Privy for authentication and Embedded Wallet infrastructure, Sentry for crash diagnostics, Reown for encrypted WalletConnect relay services, Cloudflare for hosting and signed safety-flag delivery, and other hosting, CDN, RPC, indexer, infrastructure and security providers, in each case subject to appropriate confidentiality and data-protection obligations.
- Compliance and access controls. We may use hosting and security providers to enforce access controls and may restrict, suspend or terminate access where required by applicable law or the Terms. The current Mobile App does not integrate a separate blockchain-analytics or sanctions-screening SDK. You may contact us as described in Section 15 if you wish to query an access decision.
- Legal and regulatory disclosures. With courts, regulators, law-enforcement agencies, or other authorities or parties, where we believe in good faith that disclosure is necessary to comply with applicable law, regulation, legal process or governmental request, or to protect rights, property or safety.
- Corporate transactions. In connection with, or during negotiations of, any merger, acquisition, financing, reorganization, sale of assets, insolvency or similar transaction, in which case information may be transferred to the successor or counterparty subject to this Privacy Policy.
- With your direction or consent. When you ask us to share information, or otherwise consent to sharing.
Separately, you acknowledge that transactions you broadcast through the Interface are published to a public blockchain by design. Such on-chain disclosure is inherent to the technology, is outside our control, and is not a disclosure by the Company under this Privacy Policy.
07 International data transfers
We operate from the British Virgin Islands, and our service providers may be located in, and may process information in, jurisdictions other than your own. Where we transfer personal data internationally and applicable law (including the DPA, the GDPR or the UK GDPR) requires it, we will implement appropriate safeguards for such transfers, such as standard contractual clauses or transfers to jurisdictions recognized as providing an adequate level of protection. You may contact us for more information about the safeguards we use.
08 Data retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to provide the Functionality, to comply with our legal, regulatory, accounting and reporting obligations, to resolve disputes, and to establish, exercise or defend legal claims. The applicable retention period depends on the nature of the information and the purpose of processing. When personal data is no longer needed, we will delete or anonymize it. You acknowledge that on-chain data is permanent and immutable and cannot be deleted by us.
09 Data security
We implement reasonable technical and organizational measures designed to protect the information we process against unauthorized access, loss, misuse or alteration. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. The non-custodial design of the Interface means that we do not hold your keys or Digital Assets; accordingly, the security of your Wallet, Authentication Means and devices remains your responsibility, as further described in the Terms.
10 Your privacy rights
Subject to, and to the extent provided by, applicable law (including the DPA and, where applicable, the GDPR and UK GDPR), you may have the following rights in respect of your personal data:
- to request access to, and a copy of, the personal data we hold about you;
- to request rectification of inaccurate or incomplete personal data;
- to request erasure of your personal data in certain circumstances;
- to request restriction of, or to object to, certain processing;
- to request portability of personal data you provided to us, in certain circumstances;
- to withdraw consent where processing is based on consent; and
- to lodge a complaint with a competent supervisory authority, including the Information Commissioner of the British Virgin Islands or, where applicable, your local data-protection authority.
To exercise your rights, please contact us as set out in Section 15. We may need to verify your identity before responding, and certain rights are subject to legal exceptions and limitations. You acknowledge that we may be unable to identify you from a wallet address or other technical identifier alone, and that we cannot alter, restrict or erase information recorded on a public blockchain, which is outside our control.
11 Children’s privacy
The Interface is not directed to, and is not intended for use by, anyone under the age of majority in their jurisdiction, and in any event not by anyone under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without an appropriate legal basis, we will take steps to delete it. If you believe a child has provided us with personal data, please contact us as set out in Section 15.
12 Third-party services and links
The Interface relies on, links to, or interoperates with third-party services, including the Hyperliquid Protocol and Hyperliquid Network, third-party Wallets, the Wallet Infrastructure Provider, RPC, oracle, data and infrastructure providers, bridges, on- and off-ramps, the App Stores, and others. These third parties are independent of us, process information under their own privacy policies, and are not governed by this Privacy Policy. We encourage you to review the privacy policies of any third-party service you use. We are not responsible for the privacy practices of third parties.
13 App store and mobile applications
If you obtain the Mobile App through the Apple App Store or Google Play (each an “App Store”), the App Store and your device platform may collect and process information in accordance with their own privacy policies and platform settings, including device identifiers, advertising identifiers (where applicable), diagnostic and usage data, and, if you enable them, push-notification tokens and approximate or precise location. You can manage permissions (such as notifications and location) through your device settings. Any privacy disclosures we provide through an App Store’s data-disclosure framework are intended to summarize the practices described in this Privacy Policy; in the event of a conflict, this Privacy Policy governs as between you and the Company, subject to the App Store’s own terms and policies.
14 Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by posting the updated Privacy Policy in the Interface and updating the “Last Updated” date above, and, where appropriate or required by law, by other reasonable means. Your continued access to or use of the Interface after the effective date of the updated Privacy Policy constitutes your acknowledgement of the updated Privacy Policy.
15 How to contact us
If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us at:
Hypro Team
Email: contact@hypro.one