| Data | Purpose | Retention |
|---|---|---|
| Wallet address | Authentication, allocation tracking | While account is active |
| 2FA secret (hashed) | Authenticator-app verification | Until 2FA is disabled |
| IP address | Security audit, geolocation, abuse prevention | 30 days, rolling |
| Trading history | Performance reporting, risk gauges | While account is active |
| Session token | Keep you signed in (HTTP-only cookie + localStorage) | 24 hours, rolling |
| User-agent string | Browser-fingerprinting for SOC anomaly detection | 30 days |
We use only essential cookies for authentication and CSRF protection. localStorage holds your session token, UI preferences (workspace layout, theme), and your 2FA acknowledgement flag. No tracking cookies are used. See Cookies Notice for the full list.
For EU residents:
We do not sell, rent, or share your data with advertisers, brokers, or analytics providers. We share data only:
Under GDPR, CCPA, and similar regimes, you have the right to:
To exercise any right, email privacy@evolvingbot.tech from the email tied to your account, or signed by your wallet. We respond within 30 days.
We protect data with: 2FA-mandatory authentication, IP whitelisting per user, GeoIP filtering of restricted jurisdictions, encrypted secrets (AES-256-GCM), threat-intelligence IP blocking, and continuous SOC monitoring (HIDS, FIM, anomaly detection). API keys for Hyperliquid are encrypted at rest with a master key stored separately from the data.
Data may be processed in the country where our servers are hosted. For EU residents, transfers outside the EEA are made under Standard Contractual Clauses (SCCs).
The service is not intended for children under 18. We do not knowingly collect data from minors.
Material changes to this policy will be announced via the platform interface and via email if you have provided one.
Privacy questions: privacy@evolvingbot.tech · Data Protection Officer: TBD on entity formation.