
Exos has no accounts, no passwords, and no ad tracking. What we work with is mostly public blockchain data keyed to your wallet address. We do not sell data.
Wallet addresses and on-chain activity. Your address and your Hyperliquid trading activity (fills, fees, positions) are public blockchain data. We read them from the protocol's public API and store the subset needed to run points, referrals, and leaderboards.
Referral attribution. If you arrive through a referral link, the code is stored in your browser and, when you confirm it with a signature, alongside your address in our database.
Local preferences. Layout, slippage, and similar settings live in your browser's storage and never leave your device.
IP addresses. Processed transiently for rate limiting, security, and region blocking. Our hosting provider keeps standard server logs. We do not build profiles from them.
Email (only if you choose email login). Connecting with email or a social login creates an embedded wallet operated by Reown; your email is processed by Reown under their privacy policy, and Exos sees the resulting wallet address, not your login credentials. [COUNSEL: confirm processor terms with Reown before mainnet.]
To enforce the regional restrictions in the Terms of Use, an approximate country and region is derived from your IP address on each page request. Requests from restricted regions are refused and the refusal (country, region, and path, never the IP itself in our records) may be logged for compliance evidence.
No advertising trackers, no analytics identifiers, no selling or renting of data, no profiling beyond the trading statistics visible in the product itself.
Infrastructure providers process data to run the service: Vercel (hosting), Supabase (database), Reown (wallet connections and optional embedded wallets), and the public Hyperliquid API. Each receives only what its function requires.
We disclose information if legally compelled, and to investigate abuse of the points, referral, or competition systems.
Growth-programme records (addresses, fills, bindings) are retained while programmes run because standings must remain auditable. You can disconnect at any time; local storage clears with your browser. For questions or requests, contact [COUNSEL: contact channel + data rights wording per applicable regime].
Updates to this policy change the date above; material changes will be announced in the app.