BTCETHVolumeActive Agents0 / 8ScannedOpportunitiesSignals

Privacy Policy

What this site processes, where it is kept, who else receives it, and how to stop.

Effective date: September 13, 2026

Nothing on HIPPO AI is investment, financial, legal or tax advice, and nothing on it promises a profit.

The original of this document is written in Japanese. Translations are provided for convenience; if a translation differs from the Japanese text, the Japanese text prevails.

1.About this policy

This policy explains how HIPPO AI (the “Service”), provided by the operator of HIPPO AI (the “Operator”), handles information. It describes how the Service works as of the effective date.

The Service does not ask for your name, email address or phone number, and has no password-based accounts. As of the effective date it loads no advertising or analytics trackers.

2.What the Service never receives

The Service never receives your private keys or seed phrases. Signatures and transactions are created inside your wallet app; the Service only receives the resulting signature, or reads the transaction once it is on-chain. Never enter a seed phrase on any website.

3.Wallet address, sign-in and cookies

  • When you connect a wallet, your browser reads your wallet address and network. The address is sent to the server when you view your portfolio or holdings, simulate a trade, sign in, or use automatic trading.
  • To use automatic trading and referral totals you sign in by signing a message in your wallet. The message states that it does not move funds and costs no gas. The server issues a one-time sign-in code (valid for 10 minutes), verifies your signature and records which address used the code.
  • After sign-in the server sets a session cookie named hippo.session. It is HttpOnly (page scripts cannot read it), sent only with requests to this site, marked Secure in production, and expires after 7 days. It contains your address, its expiry time and a signature — no secret.
  • A cookie named hippo.lang remembers the display language you choose, for one year.

4.Records kept on the server

If you sign in and use automatic trading or referrals, the Service keeps the following in its database (Neon Postgres):

  • Account: your wallet address, your trading account address and the value used to derive it, when it was deployed, your referral code, and the referrer or referral code you arrived with.
  • Automatic trading settings: on or off, paused, mode, score threshold, order size, daily budget, position limit, daily loss limit, take-profit, stop-loss, trailing stop, cooldown, whether large sales are allowed, and when the worker last checked your account with its note.
  • Permissions: the delegations you signed, their type, hash, expiry and revocation time.
  • Trading records: positions (token, amounts, prices, profit and loss) and every automatic order attempt with its status, reason and transaction hash.
  • Fees and referral credits: fee amounts and transaction hashes, and the credits recorded for referrers.
  • Sign-in codes: the one-time code, the address that used it, and when.

Independently of sign-in, the server also caches the last portfolio and holdings response for a wallet address that is looked up, and public token data, so they can be shown with their fetch time while a data provider is rate-limited.

To protect the Service from abuse, the server counts requests per visitor on some routes (for example sign-in, trade simulation, portfolio and automatic-trading requests) in one-minute windows. It stores only a keyed hash of your IP address (for IPv6, of its /64 network) together with the route name, the window start time and the count — never the IP address itself.

5.Stored in your browser

These items stay in your browser's local storage. They are not sent to the server except where stated:

  • hippo.watchlist — tokens on your watchlist (address and symbol).
  • hippo.strategy-weights — score weights you saved on the Strategy page.
  • hippo.trade-settings — your manual per-order cap, default slippage, and whether large manual sales are allowed. The permission for a large sale is sent with that sell request.
  • hippo.referrer — the referral code from the link you first arrived with. It is sent to the server when you create a trading account.
  • hippo.wallet — which wallet app you chose to connect.
  • hippo.agentDrafts — agent descriptions you saved as drafts on the Agents page.
  • hippo.risk-ack.auto and hippo.risk-ack.trade — which wallet addresses confirmed the risk notice in this browser before using automatic or manual trading, and for which version of the notice.

6.Third parties

Data providers are called by the Service's server, not by your browser, so they see the server rather than your IP address. A request can still include a token address or wallet address that you are viewing.

  • Vercel — hosts the Service and runs its servers and the scheduled worker. Like any host, it processes your IP address and request details to deliver pages and may keep logs.
  • Neon — hosts the database described above.
  • GMGN — market, token, holder, trader and wallet data. Wallet addresses you view, including your own portfolio, are sent to GMGN.
  • GoPlus Security — token security checks.
  • DexScreener, GeckoTerminal and DefiLlama — prices, pools, token links and chain statistics.
  • OpenNews / OpenTwitter (6551) — news headlines and social posts.
  • CoinGecko — BTC and ETH prices.
  • Robinhood Chain RPC — the server reads balances and simulates and sends transactions through it.
  • Wallet apps such as MetaMask, Rabby or Trust Wallet — hold your keys, create signatures and connect to the chain under their own terms.

Each provider handles data under its own terms and privacy policy. The Service does not sell your information or use it for advertising.

7.Public blockchain data

Your wallet address, trading account, transactions, fees, balances and permissions redeemed or revoked on-chain are recorded on Robinhood Chain. This data is public, can be linked to you, and cannot be changed or deleted by anyone, including the Operator.

8.How the information is used

To show your portfolio, positions and trade history; to run automatic trading within your permissions; to calculate fees and referral credits; to keep sign-in secure; and to prevent abuse and diagnose errors. Server error logs may contain request details.

9.How long it is kept

  • Sign-in codes: expire after 10 minutes. Codes older than one day are deleted automatically the next time anyone starts a sign-in.
  • Cached portfolio, holdings and token data: overwritten when refreshed. Entries older than 48 hours are deleted automatically once an hour.
  • Request counters: needed only for one minute. Entries more than an hour old are deleted automatically when the periodic cleanup runs.
  • Session cookie: expires after 7 days.
  • Account, settings, permissions, trading records, fees and referral credits: there is currently no automatic deletion. They are kept so that trades, fees and referral credits can be accounted for.
  • Browser storage: kept until you clear it.
  • Hosting and provider logs: kept under those providers' own policies.

10.Your choices and how to stop

  • Pause or turn off automatic trading on the Auto Trade page, and revoke the permissions to disable them on-chain.
  • Withdraw ETH from your trading account to your own wallet.
  • Disconnect your wallet. This only makes this site forget the connection — remove the site's access in your wallet app as well.
  • Clear this site's cookies and local storage in your browser settings. This also ends your session.
  • For questions about records linked to your address, contact the Operator through the official channels listed on this site. On-chain data cannot be deleted, and records needed to account for trades and fees may have to be kept.

11.Security

Session cookies are signed, sign-in codes can be used only once, and automatic-trading permissions are limited as described in Risks and Disclosures. No method of transmission or storage is completely secure.

12.Changes to this policy

This policy may be updated when the Service changes. The effective date at the top of the page shows which version applies.

Privacy Policy · HIPPO AI