Privacy Policy

Last updated: March 2026

1. Introduction

Auspex Trade Ltd ("we", "us", "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard your information when you use our software-as-a-service platform at auspex-trade.com ("Service"), which provides AI-powered cryptocurrency trading tools, signals, and optional automated execution features.

2. Information We Collect

Account Information: When you register, we collect your email address. If you authenticate via a third-party provider (such as Privy), we receive your email and a unique user identifier. Passwords, where applicable, are stored in hashed form.

Wallet Addresses: When you use the Service, an embedded cryptocurrency wallet is created on your behalf by our wallet infrastructure provider (Privy). We store the associated Ethereum and Solana wallet addresses. We do not store or have access to your wallet private keys, which are managed by Privy's secure key-management infrastructure.

Trading Data: When you use the auto-execution or trading features of the Service, we collect and store: trade positions (symbol, side, entry price, exit price), leverage settings, take-profit and stop-loss levels, realised and unrealised profit-and-loss, execution history, and order identifiers from connected exchanges.

Usage Data and IP Addresses: We collect your IP address, browser type, device information, pages visited, signals viewed, and feature interactions. This data is used to provide the Service, detect abuse, and improve the platform.

Payment Information: Subscription payments are processed through Stripe and Coinbase Commerce. We do not store payment card details, bank account numbers, or cryptocurrency payment wallet private keys. We retain only transaction identifiers and subscription status.

User Preferences: We store your settings including preferred leverage, risk profile, position sizing, market preferences, notification preferences, and auto-execution consent status.

3. Lawful Basis for Processing

We process your personal data on the following legal bases under the UK GDPR and EU GDPR:

  • Contract performance: Processing necessary to provide the Service you have signed up for, including account management, trade execution, signal delivery, and subscription billing.
  • Legitimate interest: Processing necessary for platform security, fraud prevention, abuse detection, service improvement, and analytics. We balance our interests against your rights and freedoms.
  • Consent: Where we send marketing communications or use non-essential cookies, we rely on your explicit consent, which you may withdraw at any time.
  • Legal obligation: Processing necessary to comply with applicable laws, regulations, or lawful requests from authorities.

4. How We Use Your Information

We use your information to: (a) provide and maintain the Service, including executing trades on your behalf when auto-execution is enabled; (b) process your subscription payments; (c) send you trading signals and notifications you have opted into; (d) monitor positions and manage risk on your behalf; (e) improve and personalise the Service; (f) detect and prevent fraud, abuse, and unauthorised access; (g) communicate important updates about your account or the Service.

5. Data Storage and Security

Your data is stored on secure servers provided by our hosting and database infrastructure partners (see Section 6). Passwords are hashed using industry-standard algorithms. All data in transit is encrypted using TLS 1.2 or higher. We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction.

Storage Locations: Our primary database is hosted by Supabase (servers located in the United States). Our web application is hosted by Vercel (servers located in the United States and globally distributed via CDN). Our trading infrastructure runs on dedicated servers in the European Union (Germany).

6. Data Sharing and Third-Party Processors

We do not sell, trade, or rent your personal information to third parties. We share data with the following categories of service providers who assist in operating the platform:

  • Privy Inc. (United States) — Embedded wallet creation, key custody, and user authentication. Receives your email and manages your wallet private keys.
  • Hyperliquid (decentralised protocol) — Trade execution on perpetual futures markets. Receives your wallet address, order details, and leverage settings. On-chain transaction data is publicly visible on the Hyperliquid L1 blockchain.
  • Supabase Inc. (United States) — Database hosting and authentication infrastructure. Stores account data, trading history, and user settings.
  • Vercel Inc. (United States) — Web application hosting, serverless functions, and content delivery.
  • Stripe Inc. (United States) — Subscription payment processing for card payments.
  • Coinbase Commerce (United States) — Cryptocurrency payment processing for subscription payments.
  • Finnhub (Finland) — Economic calendar and market data used in trading signal generation.
  • Cloudflare Inc. (United States) — Network security, DDoS protection, and traffic proxying.

We may also share data with law enforcement if required by law or in response to valid legal process.

7. Cookies

We use essential cookies required for authentication and session management. We do not use advertising or tracking cookies.

8. International Data Transfers

Your personal data is transferred to and processed in the United States and other countries outside the European Economic Area (EEA) and the United Kingdom. Our key service providers (Supabase, Vercel, Stripe, Privy, Coinbase Commerce, Cloudflare) are based in the United States.

Where we transfer personal data outside the EEA/UK, we ensure appropriate safeguards are in place in accordance with GDPR Article 46, including: (a) transfers to countries with an adequacy decision from the European Commission or UK Secretary of State; (b) Standard Contractual Clauses (SCCs) approved by the European Commission; (c) the service provider's participation in recognised data protection frameworks.

Additionally, transactions executed on the Hyperliquid blockchain are recorded on a public, decentralised ledger. Once data is written to the blockchain, it cannot be modified or deleted by any party, including Auspex.

9. Your Rights

Under the UK GDPR, EU GDPR, and other applicable data protection laws, you have the right to: (a) access your personal data; (b) rectify inaccurate data; (c) request deletion of your data (right to erasure); (d) restrict or object to processing; (e) data portability; (f) withdraw consent at any time where processing is based on consent; (g) lodge a complaint with a supervisory authority.

Please note that certain data cannot be deleted once written to a public blockchain (e.g., Hyperliquid transaction records and wallet addresses associated with on-chain activity).

To exercise your rights, contact us at support@auspex-trade.com or use the account deletion page at auspex-trade.com/delete-account.

10. Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Service. Upon account deletion, your data will be permanently removed from our systems within 30 days, except: (a) data we are required to retain by law; (b) anonymised and aggregated data that cannot identify you; (c) data recorded on public blockchains, which cannot be modified or deleted.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. For significant changes, we may also notify you by email.

12. Contact

For questions about this Privacy Policy, contact us at support@auspex-trade.com.