Privacy Policy
Effective date: July 2, 2026 Version: 1.0 Applies to: https://hyperfx.pro and all related HyperFX services, applications, and features (collectively, the "Service").
1. Introduction
This Privacy Policy explains how HyperFX ("HyperFX", "we", "us", or "our") collects, uses, discloses, and protects personal data when you visit https://hyperfx.pro, create an account, or otherwise use the Service.
HyperFX is an information and educational resource only. It provides AI-assisted analysis of user-uploaded chart screenshots, a trade journal, strategy and setup feeds, and tracking of public traders' prediction accuracy, for the crypto and forex markets. Such tracking is informational only and does not guarantee the accuracy of any prediction or any future result (see our Risk Disclosure and Disclaimer). HyperFX does not provide financial, investment, or trading advice, personalized recommendations, solicitations, offers to buy or sell any asset, or portfolio management, and is not a broker, exchange, financial advisor, or fiduciary. HyperFX is not regulated or authorized by any financial authority unless expressly stated. Crypto and forex are high-risk; you can lose all of your capital, leverage magnifies losses, and past performance does not indicate future results. This Privacy Policy describes our data practices only; for the terms governing your use of the Service, please see our Terms of Service, and for risk-related disclosures, our Risk Disclosure and Disclaimer.
We have structured this policy in layers: each section begins with the essentials, followed by detail. Please read it together with our Cookie Policy, which describes our use of cookies and similar technologies.
By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, please do not use the Service.
2. Data controller and contact details
The data controller responsible for your personal data is:
- Controller: HyperFX, owner of the domain hyperfx.pro (support@hyperfx.pro)
- Registration / VAT number (if applicable): Not applicable
- Privacy / data protection contact: support@hyperfx.pro
Based on our current assessment of Article 37 of the GDPR, we are not required to appoint a statutory Data Protection Officer (DPO). We keep this assessment under review, in particular in light of any large-scale processing, behavioural tracking, or AI processing we carry out, and we will appoint a DPO and update this policy if that becomes necessary. You may direct all privacy enquiries to support@hyperfx.pro.
EU/UK representative (Article 27 GDPR): We have not appointed a representative in the European Economic Area (EEA) or the United Kingdom under Article 27 GDPR. Not applicable. You may direct all privacy enquiries to support@hyperfx.pro.
3. Summary — at a glance
| Topic | Summary |
|---|---|
| What we collect | Account details, uploaded chart images, journal and usage content, device data, and payment metadata (crypto payments are handled by a third-party, non-custodial crypto payment processor; we never receive or store card details). |
| Why we collect it | To provide and secure the Service, process subscriptions, improve the product, communicate with you, and comply with the law. |
| Legal bases (GDPR) | Performance of a contract, your consent, our legitimate interests, and legal obligations. |
| Who we share with | Vetted service providers (sub-processors): a third-party crypto payment processor (billing), a third-party AI processing provider (AI analysis), and hosting providers. We do not use third-party web analytics or error-tracking services. |
| Selling data | We do not sell your personal data or share it for cross-context behavioural advertising. |
| Retention | Only as long as necessary; concrete ranges are set out in Section 9. Uploaded chart images are retained only briefly. |
| Your rights | Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. US state rights where applicable. |
| International transfers | Where data leaves your region (including to the US), we rely on adequacy decisions or Standard Contractual Clauses. |
| DNT / GPC | We honour recognized Global Privacy Control (GPC) opt-out signals where required by law (see Section 8.1). |
4. The personal data we collect
We collect the following categories of personal data. Not all of it applies to every user; the data we hold about you depends on how you use the Service.
4.1 Account and profile data
- Name or username, email address, and password (stored in hashed form).
- Account preferences, such as your interface language (EN/RU/ES/TR) and display settings.
- Authentication identifiers if you sign in via a third-party login provider (OAuth), such as your provider user ID and the email address associated with it.
- Referral data: your referral code, and the relationship between referring and referred accounts where you participate in our referral program.
4.2 Content you provide
- Uploaded chart images / screenshots that you submit for AI-assisted analysis. These images, and any text they contain, are processed to generate analysis and may incidentally include any information you have chosen to include in the screenshot.
- Trade journal entries, notes, tags, strategies, setups, and other content you create or store in the Service.
- Communications you send us, such as support requests, feedback, and survey responses.
4.3 Usage and analytics data
- Pages and features viewed, actions taken, session duration, referring/exit pages, and interaction events.
- Aggregated and event-level product analytics used to understand and improve the Service.
4.4 Device and technical data
- IP address, approximate location derived from IP (e.g., country/region), browser type and version, operating system, device type, screen/viewport size, language settings, and time zone.
- Log data, including timestamps, requested URLs, status codes, and diagnostic information.
- Error and crash reports, which may include technical context and, occasionally, fragments of data present at the time of an error.
4.5 Payment data
- Payments are made in cryptocurrency (USDT/USDC) and are handled by a third-party, non-custodial crypto payment processor. HyperFX does not accept card payments and never receives or stores your card details or other regulated payment credentials.
- We receive and retain limited payment metadata, such as subscription/plan type, status, transaction (including on-chain transaction) identifiers, the wallet address or network used, invoice records, and the start/renewal/cancellation dates of your subscription.
4.6 Cookies and similar technologies
- We and our providers use cookies and similar technologies for authentication, security, preferences, and analytics. See Section 8 and our Cookie Policy for details.
We do not intentionally collect special categories of personal data (such as data revealing health, political opinions, or religious beliefs). Please do not include such data in chart screenshots, journal entries, or communications.
4.7 Whether providing data is mandatory, and consequences of not providing it
Some personal data is necessary to create an account and use the Service; without it, we cannot provide the Service or specific features. In particular:
- Email address and password (or OAuth identifier): required to register and access your account. Without these, you cannot create or use an account.
- Payment metadata (via our crypto payment processor): required to purchase or maintain a paid subscription or lifetime plan. Without it, you cannot access paid features.
- Uploaded chart images: required only if you choose to use the AI analysis feature. Declining means you simply cannot use that feature; the rest of the Service remains available.
- Strictly necessary cookies: required for the Service to function securely. Other cookies are optional and depend on your consent.
Providing analytics consent, marketing consent, and optional profile details is voluntary; declining will not prevent you from using the core Service, though some optional features may be unavailable.
5. Sources of personal data
We obtain personal data from:
- You directly, when you register, upload content, configure settings, communicate with us, or use the Service.
- Automatically, through cookies and similar technologies, and through your interaction with the Service (usage, device, and log data).
- Third parties, such as our payment processor (subscription and billing metadata) and any OAuth/login provider you choose to authenticate with.
6. How and why we use your data
We use personal data for the following purposes:
1. To provide the Service — creating and maintaining your account; processing uploaded chart images to produce AI-assisted analysis; storing your journal entries and content; delivering strategy/setup feeds and public-trader accuracy tracking; and enabling core features. 2. To process payments and manage subscriptions — handling sign-ups, renewals, cancellations, lifetime purchases, invoicing, and the referral program (via our payment processor). 3. To communicate with you — sending service and transactional messages (e.g., account, billing, security, and policy-change notices) and responding to your enquiries. 4. To secure the Service — authenticating users, preventing and detecting fraud, abuse, and unauthorized access, and maintaining the integrity and availability of the Service. 5. To improve and develop the Service — analyzing usage, diagnosing errors, performing research, and developing new and existing features. 6. To send marketing communications — where permitted, informing you about features, offers, and updates. You can opt out at any time (see Section 13). 7. To comply with legal obligations — meeting tax, accounting, and other statutory requirements, and responding to lawful requests from authorities. 8. To enforce our terms and protect rights — establishing, exercising, or defending legal claims and enforcing our Terms of Service.
6.1 AI processing and automated analysis
When you upload a chart screenshot, it is sent to and processed by one or more third-party AI processing provider(s) to generate analysis. This AI-generated analysis is informational and educational only. It may be incomplete, inaccurate, or wrong, and is not financial or investment advice. We make no guarantee of any profit, accuracy, or outcome. You must independently verify all output before relying on it.
We do not consider this analysis to involve solely automated decision-making producing legal or similarly significant effects within the meaning of Article 22 of the GDPR: the analysis is a tool you choose to use, and we do not use it to make any decision about you. This reflects HyperFX's current view (subject to review by counsel) rather than a binding legal conclusion. To the extent that Article 22 GDPR is found to apply, you have the rights described in Section 15, including the right to obtain human intervention, to express your point of view, and to contest the decision.
6.2 Profiling and behavioural analytics
We do not use third-party web analytics or error-tracking services. We may use first-party, essential logging to understand how features are used at an aggregate level, to diagnose problems, and to secure and improve the Service. We do not carry out automated profiling that produces legal or similarly significant effects about you, and we do not use third-party analytics or advertising trackers. Where any such processing relies on our legitimate interests or your consent, you may object to it, or withdraw consent, at any time by adjusting your cookie/consent settings or contacting support@hyperfx.pro (see Sections 8.1, 13, and 15).
7. Legal bases for processing (GDPR)
Where the GDPR applies, we rely on the following legal bases under Article 6(1):
| Purpose | Legal basis |
|---|---|
| Creating/maintaining your account; processing uploaded charts and journal content; delivering core features | Performance of a contract (Art. 6(1)(b)) |
| Processing subscriptions, payments, and referrals | Performance of a contract (Art. 6(1)(b)) |
| Service and transactional communications | Performance of a contract (Art. 6(1)(b)) / legitimate interests (Art. 6(1)(f)) |
| Security, fraud prevention, and ensuring availability | Legitimate interests (Art. 6(1)(f)) |
| Product analytics, profiling, and service improvement | Legitimate interests (Art. 6(1)(f)) and/or consent (Art. 6(1)(a)) where required for non-essential cookies/trackers |
| Marketing communications and non-essential cookies | Consent (Art. 6(1)(a)) |
| Tax, accounting, and other legal requirements | Legal obligation (Art. 6(1)(c)) |
| Establishing, exercising, or defending legal claims | Legitimate interests (Art. 6(1)(f)) |
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may object to such processing at any time (see Section 15). Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
8. Cookies and similar technologies
We use cookies and similar technologies that are strictly necessary (e.g., authentication and security), as well as functional, analytics, and—where applicable—marketing technologies. Non-essential cookies are only set with your consent, which you can give, refuse, or withdraw at any time.
For a full description of the cookies we use, their categories, purposes, durations, and how to manage your preferences, please see our Cookie Policy.
8.1 Do Not Track (DNT) and Global Privacy Control (GPC)
"Do Not Track" (DNT) is a browser setting that signals a preference not to be tracked. There is currently no industry or legal consensus on how to interpret DNT signals, and we therefore do not respond to DNT signals at this time.
Some browsers and extensions transmit a Global Privacy Control (GPC) signal, which communicates a request to opt out of the "sale" or "sharing" of personal information and of certain targeted advertising. Where required by applicable law (including the California Consumer Privacy Act as amended by the CPRA, and other US state privacy laws that recognize such signals), we treat a recognized GPC signal received from your browser or device as a valid opt-out request for that browser or device. Because such signals are tied to a specific browser/device and are typically not associated with a logged-in account, the opt-out may not extend across all of your devices or sessions.
9. Data retention
We keep personal data only for as long as necessary for the purposes set out in this policy, after which it is deleted or anonymized. The retention periods below are indicative ranges that will be confirmed against final legal and operational requirements:
- Uploaded chart images: retained only briefly (typically deleted within 24–72 hours, or sooner) to perform the requested AI analysis and deliver the result to you. Under our agreement with the AI provider, uploaded images are processed only to generate your analysis and, per that provider's terms in force, are not used to train the provider's AI models. We do not control the provider's internal practices in perpetuity and will update this statement if the provider's terms change. Where you save analysis output to your journal, the saved output (not necessarily the original image) is retained as part of your account content.
- Account and profile data: retained for the life of your account and deleted (or anonymized) typically within 30–90 days after account closure, subject to legal retention requirements.
- Journal entries and user content: retained while your account is active; you may delete individual entries at any time, and remaining content is removed when your account is deleted (typically within 30–90 days of deletion).
- Payment and billing metadata: retained as required for tax, accounting, and audit purposes, typically 6–10 years depending on applicable law.
- Usage, analytics, and log data: retained for a limited period sufficient for security, troubleshooting, and analysis — typically up to 12–24 months — then deleted or aggregated. Security and access logs may be kept for a shorter period (e.g., 30–90 days) unless needed for an investigation.
- Support communications: retained for as long as needed to handle your request and typically up to 24 months thereafter.
- Consent and opt-out records: retained for as long as needed to demonstrate compliance (typically the duration of the relationship plus the applicable limitation period).
Where exact periods are not stated, we determine retention based on the criteria above: the purpose of processing, the sensitivity of the data, legal obligations, and the need to defend legal claims.
9.1 Closing your account and deleting your data
You can close your account and trigger deletion of your account data at any time by:
- using the in-Service account settings / "Delete account" option (self-service), where available; or
- emailing support@hyperfx.pro with a deletion request from the email address associated with your account.
On account closure or a valid deletion request, we will delete or anonymize your account and content within the timeframes in Section 9, except where we are required or permitted by law to retain certain data (for example, payment and tax records) or where retention is necessary to establish, exercise, or defend legal claims. We may retain anonymized/aggregated data that no longer identifies you.
10. How we share your data — third parties, processors, and sub-processors
We do not sell your personal data, and we do not share it for cross-context behavioural advertising or with third parties for their own independent marketing.
We share personal data with carefully selected service providers ("sub-processors") who process it on our behalf under contractual obligations (including, where the GDPR applies, data processing agreements). The categories and current key providers are:
| Category | Provider(s) | Purpose | Data involved | Principal processing location |
|---|---|---|---|---|
| Billing / payments | A third-party, non-custodial crypto payment processor | Crypto (USDT/USDC) payment processing, subscriptions, lifetime purchases, invoicing | Account email, subscription and on-chain payment metadata | The region where our servers are hosted |
| AI chart analysis | A third-party AI processing provider | Processing uploaded charts to generate AI-assisted analysis (receives the submitted chart image/text, not identity data) | Uploaded chart images and related prompts | The region where our servers are hosted |
| Product analytics | Not applicable — we do not use any third-party web analytics provider | Not applicable | Not applicable | Not applicable |
| Error / performance tracking | Not applicable — we do not use any third-party error-tracking provider | Not applicable | Not applicable | Not applicable |
| Hosting | Our own self-managed private servers | Hosting the Service, storage, and content delivery | All data processed by the Service, as needed for hosting | The region where our servers are hosted |
| Email / communications | Not applicable — we do not currently use a third-party email or marketing provider | Not applicable | Not applicable | Not applicable |
We may also disclose personal data:
- to professional advisers (e.g., lawyers, accountants, auditors) under confidentiality;
- to authorities, regulators, or courts where required by law or to protect our rights, users, or the public;
- in connection with a merger, acquisition, financing, or sale of assets, in which case we will require the recipient to honour this policy or notify you of any material change.
10.1 Sub-processor list and change notifications
We maintain a current list of our sub-processors, which we make available at https://hyperfx.pro/subprocessors (or on request at support@hyperfx.pro). Where the GDPR applies and we act as a processor, or where we have otherwise committed to do so, we will give advance notice (where reasonably practicable, at least 14–30 days) before adding or replacing a sub-processor that processes your personal data, and you may object to a new sub-processor on reasonable, data-protection-related grounds within the notice period. If we cannot reasonably accommodate a valid objection, you may be entitled to terminate the affected paid service in accordance with the Terms of Service.
11. International data transfers
We and our sub-processors may process personal data in countries outside your own, including outside the EEA, the United Kingdom, or your country of residence, which may have different data-protection laws. In particular, our key sub-processors (including our third-party crypto payment processor and our third-party AI processing provider) and our self-managed hosting may process data in the region where our servers are hosted, as indicated in Section 10.
Where we transfer personal data internationally, we rely on appropriate safeguards, such as:
- transfers to countries covered by an adequacy decision of the European Commission (or the relevant authority); or
- Standard Contractual Clauses (SCCs) approved by the European Commission (and the UK International Data Transfer Addendum, where applicable); together with
- supplementary technical and organizational measures where appropriate.
You may request more information about the safeguards applied to a specific transfer, including a copy of the relevant clauses, by contacting support@hyperfx.pro.
12. Service availability and your eligibility
The Service is offered on a global basis, but its legal and regulatory availability is not guaranteed in every jurisdiction. Some countries and regions restrict or prohibit access to crypto- and forex-related information services, tools, or trading. We make no representation that the Service, or your trading or use of crypto/forex more generally, is lawful or appropriate in your location.
You are solely responsible for determining your own eligibility and for complying with all laws applicable to you, including those governing access to crypto/forex services and the use of such information. By using the Service, you confirm that doing so is lawful in your jurisdiction. We may restrict or block access from certain jurisdictions at our discretion. Our processing of data about cross-border users is carried out in accordance with this policy and the safeguards in Section 11.
13. Data security
We implement appropriate technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, or destruction. These include, as appropriate: encryption in transit (and at rest where applicable), access controls and authentication, the principle of least privilege, network and application security controls, logging and monitoring, and vendor due diligence.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential and for using a strong, unique password.
13.1 Marketing opt-out
Where we send marketing communications based on your consent or, where permitted, our legitimate interests, you can opt out at any time by using the unsubscribe link in our messages or by contacting support@hyperfx.pro. Opting out of marketing does not affect service or transactional messages necessary to operate your account.
14. Data breach handling and notifications
We maintain procedures to detect, assess, and respond to personal data breaches.
EEA/UK (GDPR): Where a breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by Article 33 of the GDPR. Where a breach is likely to result in a high risk to you, we will also inform affected individuals without undue delay, in accordance with Article 34.
United States and other regions: Where applicable US state breach-notification laws (or other laws applicable to you) require it, we will notify affected residents and any relevant authorities within the timeframes and by the methods those laws require. As a general commitment, regardless of your location, where a confirmed breach is likely to materially affect you, we will take reasonable steps to notify you (for example, by email or in-Service notice) and to describe the nature of the breach, the likely consequences, and the measures we are taking.
Security contact: To report a suspected security issue or vulnerability, or if you believe your account has been compromised, contact us at support@hyperfx.pro.
15. Your rights
Subject to applicable law, you have the following rights in respect of your personal data:
- Access — obtain confirmation of whether we process your data and a copy of it.
- Rectification / correction — have inaccurate or incomplete data corrected.
- Erasure ("right to be forgotten") — have your data deleted in certain circumstances.
- Restriction — limit how we process your data in certain circumstances.
- Portability — receive certain data in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
- Objection — object to processing based on legitimate interests, including profiling, and to direct marketing at any time.
- Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior lawful processing.
- Rights relating to automated decisions — to the extent Article 22 GDPR applies, the right not to be subject to a solely automated decision producing legal or similarly significant effects, and to obtain human intervention, express your view, and contest the decision (see Section 6.1).
15.1 How to exercise your rights
To exercise any of these rights, contact us at support@hyperfx.pro, or use the self-service tools in your account settings where available. We may need to verify your identity before acting. We will respond within one month of receipt (or within the timeframe required by your local law); this period may be extended by up to two further months for complex or numerous requests, in which case we will inform you. We do not charge a fee unless your request is manifestly unfounded or excessive.
15.2 Right to complain
If you are in the EEA, the UK, or another jurisdiction with a data protection authority, you have the right to lodge a complaint with your local supervisory authority. We would, however, appreciate the chance to address your concerns first — please contact us at support@hyperfx.pro.
15.3 United States — California (CCPA/CPRA) and other state privacy rights
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), provides the rights described below. Residents of other US states with comparable laws may have similar rights.
Categories of personal information we collect (mapped to CCPA/CPRA statutory categories), and whether each is disclosed to a service provider for a business purpose:
| Statutory category | Examples we collect | Collected? | Disclosed to a service provider for a business purpose? |
|---|---|---|---|
| Identifiers | Name/username, email, account ID, IP address, OAuth ID | Yes | Yes (hosting, crypto payment processor) |
| Customer records / financial information | Subscription and on-chain payment metadata, wallet address/network | Yes | Yes (crypto payment processor) |
| Commercial information | Subscription history, plan type, transactions, referral activity | Yes | Yes (crypto payment processor, hosting) |
| Internet / network activity | Usage events, pages viewed, interactions, log data | Yes | Yes (hosting) |
| Geolocation data | Approximate location derived from IP (country/region) | Yes | Yes (hosting, security) |
| Audio/visual / user content | Uploaded chart images, journal entries, support messages | Yes | Yes (AI processing provider, hosting) |
| Inferences | Inferences about feature usage and preferences | Limited | No (we do not use third-party analytics) |
| Sensitive personal information | Account log-in credentials (password is stored hashed) | Limited | Used only to provide the Service; not used to infer characteristics |
We collect this information from the sources described in Section 5 and disclose it to the categories of service providers described in Section 10 for the business purposes in Section 6.
We do not "sell" personal information and do not "share" it for cross-context behavioural advertising as those terms are defined under the CCPA/CPRA. We do not knowingly sell or share the personal information of consumers under 16.
Your California rights:
- Right to know the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties to whom it is disclosed.
- Right to delete personal information we have collected, subject to legal exceptions.
- Right to correct inaccurate personal information.
- Right to opt out of any sale or sharing of personal information (we do not sell or share; we also honour recognized GPC signals — see Section 8.1).
- Right to limit the use and disclosure of sensitive personal information to what is necessary to provide the Service.
- Right to non-discrimination — we will not discriminate against you for exercising any of these rights (for example, by denying service, charging different prices, or providing a different level of quality).
How to exercise: submit a request to support@hyperfx.pro, or use the in-Service controls where available. We will verify your request as required by law.
Authorized agents: you may use an authorized agent to submit requests on your behalf. We may require the agent to provide proof of your written authorization (or a valid power of attorney) and may require you to verify your own identity directly. We will respond to verifiable consumer requests within the timeframes required by the CCPA/CPRA (generally 45 days, extendable by a further 45 days with notice).
15.4 Other regional rights
Depending on your location, you may have additional rights under local law. To make a request under any such law, contact support@hyperfx.pro.
16. Children
The Service is intended for adults and is not directed to children. We do not knowingly collect personal data from anyone under the age of 18 (or the higher minimum age required in your jurisdiction). If you believe a minor has provided us with personal data, please contact support@hyperfx.pro and we will take steps to delete it.
17. Third-party links and content
The Service may contain links to third-party websites, brokers, exchanges, or content (including affiliate/referral links and tracking of public traders). Affiliate and referral links to brokers or exchanges may earn us commissions, are disclosed as such, and are not endorsements, recommendations, or advice. This Privacy Policy does not apply to third-party sites or services, which have their own privacy practices. We encourage you to review their policies before providing personal data.
18. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, sub-processors, or legal requirements. When we make material changes, we will update the "Effective date" and version above and notify you by appropriate means (for example, by email or an in-Service notice). Where required, we will seek your renewed consent. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
We keep prior versions on record and can provide them on request.
19. Language
This Privacy Policy is provided in English, Russian, and Spanish. In the event of any conflict or inconsistency between versions, the English version shall prevail, to the extent permitted by applicable law.
20. Contact us
If you have any questions, requests, or concerns about this Privacy Policy or our data practices, please contact:
- HyperFX
- Email: support@hyperfx.pro
- Operator: HyperFX, owner of the domain hyperfx.pro (support@hyperfx.pro)
- Governing jurisdiction for data-protection purposes: the jurisdiction in which the owner of hyperfx.pro is established