Privacy Policy
Effective date: 15 September 2026
This Privacy Policy explains what happens to your information when you use Graphite: the web and mobile application at app.graphite.trade (the “App”) and the website at graphite.trade (the “Site”), together the “Service”. Graphite is published by its developer, reachable at tradegraphite@gmail.com (“Graphite”, “we”, “us”).
The short version: Graphite has no server, no database and no account system. We do not collect, store or sell your personal data. What follows explains what stays on your device, what goes to Hyperliquid and to your wallet, and what the hosting provider sees.
1. What we do not collect
- No account. You never give us a name, email address, phone number or password. Your Hyperliquid account is identified by your wallet address alone.
- No backend. The App runs entirely in your browser or on your device. There is no Graphite server it reports to, and nothing you do in it — orders, positions, settings, the trades you draw — is sent to us.
- No analytics, no trackers, no advertising. Neither the App nor the Site uses analytics services, marketing pixels, advertising networks or third-party cookies. The Site has no sign-up form and collects no email addresses.
- No third-party fonts or scripts. The App and the Site serve their own fonts and code and load nothing from anyone else.
2. What stays on your device
The App keeps what it needs to work in your browser’s storage or your device’s app storage. None of it is transmitted to Graphite.
- Settings: your default setup, risk, chart options and the market you last looked at.
- Session: the wallet address the App is trading for, so a linked device remembers its account.
- Agent key: the private key of the agent wallet that signs your orders, in the platform’s secure storage where one exists. See the Terms of Use, section 5.
- Consent: the version of the Terms of Use and Privacy Policy you accepted.
- The App’s own files, cached by your browser so it opens faster next time.
You can remove all of it by clearing the site’s data in your browser, or by uninstalling the App. Disconnecting a wallet or ending a linked session removes the session and the agent key it points to.
3. What leaves your device, and to whom
Hyperliquid. The App talks directly to Hyperliquid’s public API and WebSocket endpoints from your device. To show your account and place orders it sends Hyperliquid your wallet address, your orders and their signatures, and the approvals you sign. Hyperliquid also sees your IP address and technical details of your connection. How Hyperliquid handles that information is described in Hyperliquid’s own privacy policy, which you should read. Graphite does not sit in the middle: nothing passes through a Graphite server, and we do not receive copies.
Your wallet. When you connect a wallet or sign an approval, the request goes from the App to your wallet software on your device. Your wallet provider’s privacy policy governs what it does with it.
Hosting. The App and the Site are static files served by Cloudflare. Like any web host, Cloudflare receives your IP address, the address requested, your browser’s user agent and similar technical data for every request, and uses it to serve the request, to protect against abuse and for its own operational logging, under its own privacy policy. Graphite has no access to these logs and does not use them to identify or track you.
Nothing else leaves your device. The App does not contact any other service.
4. Device linking
When you link a second device, the App on the first one encodes your account address and agent key into a QR code, encrypted with a PIN you choose. The code is read by the second device’s camera or opened as a link on it. The payload is never uploaded anywhere; it travels only in the image and the URL. Anyone who obtains both the code and the PIN can decode it, so treat them as secrets.
5. Public blockchain data
Hyperliquid is a public blockchain. Your wallet address, your orders, fills, positions, deposits and withdrawals, and the approvals you sign are recorded on it and can be read by anyone, permanently. Graphite reads that public record to build your journal and position history; it does not create it and cannot remove it.
6. Legal basis and your rights
Because Graphite holds no personal data about you, there is nothing for us to access, correct, export or delete on request, and no profile to object to. The processing that does happen takes place on your own device (under your control), at Hyperliquid, at your wallet provider and at Cloudflare — each under its own privacy policy, and each the party to approach to exercise your rights over the data it holds.
If you are in the European Economic Area, the United Kingdom or Switzerland and believe we hold personal data about you, you can contact us at the address below to exercise your rights of access, rectification, erasure, restriction, portability and objection, and you have the right to lodge a complaint with your supervisory authority.
7. Children
The Service is not directed at anyone under 18, and we do not knowingly collect information from children. If you are under 18, do not use it.
8. Changes to this Policy
We may update this Policy when the Service changes. The effective date at the top changes when we do, and the App asks you to accept the new version before you can trade again. The current Policy is always available in the App and at graphite.trade/privacy.
9. Contact
Questions about this Policy: tradegraphite@gmail.com.