Privacypolicy.
Effective · 2026-06-02 · Version 1.0
Plain-English summary. We collect the minimum we need to run the platform: email, your wallet address, basic usage logs. We do not collect government ID, do not have your private keys, and do not sell your data. Specific third parties (Turnkey, Stripe, Resend, Sentry, Anthropic, Hyperliquid, AWS) receive specific slices of your data to provide their parts of the service. You can request access, correction, or deletion at any time.
- // 01
Scope and identity
This Privacy Policy explains how KiheiRoad ("we," "us") collects, uses, discloses, and protects personal information when you use our website, dashboard, signal feed, API, or any related service (the "Service"). It applies to all users globally. For users in the European Economic Area or United Kingdom, we are the data controller for the personal data described herein. For users in California, we are the business that determines the purposes and means of processing.
- // 02
Information we collect
We collect three categories of information: (a) ACCOUNT INFORMATION — email address, optional display name, account creation timestamp, mode selection, risk-cap preferences, web push subscription endpoints; (b) USAGE INFORMATION — pages visited, signals received, actions taken (follows, approvals, trade placements), session timestamps, IP address, user-agent string, device characteristics, error reports; (c) ONCHAIN INFORMATION — your custodial wallet address, transaction history on Hyperliquid (publicly observable onchain), trade records associated with your account.
- // 03
Information we do NOT collect
We do not collect: (a) your private keys — these are split via threshold cryptography across Turnkey's secure-enclave hardware and we have no access to them; (b) government identification documents, social security numbers, or KYC-grade personal data — the Service does not currently require this; (c) financial account information for bank cards or institutions — payment processing for subscriptions is handled by Stripe under their privacy policy; (d) biometric data; (e) health, religious, political, or other sensitive personal data.
- // 04
How we collect information
Information is collected (a) directly from you when you submit a form, email address, or settings change; (b) automatically when you use the Service (server logs, cookies, web push registration); (c) from third-party services we integrate with (Turnkey for wallet provisioning, Stripe for billing, Hyperliquid for public onchain data, Anthropic for AI inference, Resend for email delivery, Sentry for error reporting).
- // 05
How we use information
We use collected information to (a) operate and improve the Service — provision wallets, route signals, execute trades within your authorizations, surface your trade history; (b) communicate with you — magic-link sign-in emails, transactional notifications, optional product updates; (c) ensure security — detect fraud, sybil accounts, compromised credentials, abusive behavior; (d) comply with legal obligations — sanctions screening, tax reporting where required, response to lawful requests; (e) analyze platform performance — aggregated, de-identified usage data for product decisions.
- // 06
Legal bases for processing (GDPR)
For users in the EEA or UK, we rely on the following legal bases under the General Data Protection Regulation: (a) PERFORMANCE OF A CONTRACT — to provide the Service you have requested; (b) LEGITIMATE INTERESTS — to maintain platform security, prevent fraud, and improve the Service, balanced against your interests and rights; (c) LEGAL OBLIGATION — to comply with applicable laws including anti-money-laundering and sanctions regulations; (d) CONSENT — for optional features such as web push notifications and marketing communications, which you may withdraw at any time.
- // 07
Subprocessors — third parties we share data with
We share specific data with the following subprocessors, each bound by data processing agreements and confidentiality obligations: (a) TURNKEY — wallet provisioning, signing operations (receives: email, KiheiRoad user ID); (b) STRIPE — subscription billing for Approval mode (receives: email, payment method, billing address if entered); (c) RESEND — transactional email delivery (receives: email, message content); (d) SENTRY — error tracking (receives: anonymized session IDs, error stack traces, redacted request metadata); (e) ANTHROPIC — AI inference for signal narration (receives: trade metadata, no personally identifiable information); (f) HYPERLIQUID — trade execution (receives: signed orders, wallet address — all of which are also publicly visible onchain); (g) AWS — hosting infrastructure (stores: all account and trade data). We do not sell your data to third parties for marketing or any other purpose.
- // 08
International data transfers
We are operating from outside the European Economic Area and United Kingdom (anticipated jurisdiction: Cayman Islands). When we transfer personal data from the EEA or UK to jurisdictions that the European Commission has not designated as providing adequate protection, we rely on Standard Contractual Clauses or equivalent legal mechanisms. Specific subprocessors may operate from the United States; we ensure equivalent protections through contractual safeguards.
- // 09
Your privacy rights
Subject to your jurisdiction, you may have the following rights regarding your personal data: (a) ACCESS — request a copy of the personal data we hold about you; (b) RECTIFICATION — correct inaccurate or incomplete data; (c) ERASURE — request deletion of your data, subject to legal retention requirements; (d) RESTRICTION — limit how we process your data; (e) PORTABILITY — receive your data in a structured, commonly used format (JSON export); (f) OBJECTION — object to processing based on legitimate interests; (g) WITHDRAW CONSENT — for consent-based processing, withdraw consent at any time; (h) AUTOMATED DECISION-MAKING — request human review of decisions made by automated processing, where applicable. California residents have additional rights under CCPA including the right to know, delete, correct, and non-discrimination. Submit any rights request through the contact form on the landing page; we respond within 30 days.
- // 10
Data retention
We retain personal data only as long as necessary: (a) ACCOUNT DATA — for the duration of your account, plus 12 months after closure for security and dispute resolution; (b) TRADE RECORDS — for 7 years to comply with typical financial recordkeeping regulations and tax obligations; (c) SERVER LOGS — 90 days, then deleted; (d) MARKETING EMAILS — until you unsubscribe, then suppressed in our system to honor your opt-out; (e) COMPLIANCE RECORDS (sanctions screening, AML logs) — retained per applicable law, typically 5–7 years. After applicable retention periods, data is deleted or fully anonymized.
- // 11
Cookies and similar technologies
We use cookies and similar technologies for: (a) ESSENTIAL — session management, sign-in state, security (you cannot opt out of these without breaking the Service); (b) PREFERENCES — your theme choice (light/dark), settings, locale; (c) ANALYTICS — aggregated, privacy-preserving page-view counts where applicable. We do not use third-party advertising cookies or cross-site tracking pixels. You may control non-essential cookies through your browser settings.
- // 12
Security
We implement industry-standard technical and organizational measures to protect your data, including: encrypted data at rest, TLS 1.3 in transit, role-based access controls with least-privilege defaults, multi-factor authentication for staff, regular dependency scanning and vulnerability monitoring, third-party security audits, structured logging with sensitive-field redaction, and immediate revocation of compromised credentials. No system is 100% secure. We will notify affected users and applicable authorities of any security incident as required by law and as soon as reasonably practicable after detection.
- // 13
Children
The Service is not directed to anyone under the age of 18 (or the age of majority in your jurisdiction, whichever is greater). We do not knowingly collect personal data from children. If we learn we have inadvertently collected such data, we will delete it. If you believe a minor has provided us with personal data, contact us through the form on the landing page.
- // 14
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. For material changes, we will notify you via email and an in-product banner at least 14 days before the effective date. The "Effective" date at the top of this document indicates the latest revision. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
- // 15
Contact and complaints
Privacy questions, data requests, and any complaints about how we handle your data should be submitted through the contact form on the landing page. We aim to respond within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority (in the EU: your member state's supervisory authority; in the UK: the Information Commissioner's Office).
// version 1.0 · pending final legal review prior to public launch