SypherScore Vesper
Legal

Privacy policy

Last updated 5 September 2026. This describes what we collect and where it goes. Where something is uncomfortable (an analytics tag that runs before you agree to it, a wallet address that ends up in a server log) it is written down rather than left out.

Nowe never hold your funds
Nowe never store exchange API secrets
Yeswe do log your IP and wallet address
01

The short version

Your money stays in your own exchange account and we cannot move it. The key you connect can place and cancel orders and has no withdrawal permission, so the worst thing a compromise of our side could do is place orders you did not want, never move funds out.

We do hold some data about you: your wallet address, records of the trading sessions you ran, and ordinary web server logs. A Google Analytics tag runs on our pages. Details below, including how to ask us to delete what we hold.

  • We never take custody of funds and cannot withdraw them.
  • We do not store exchange API secrets on our servers.
  • We do store your wallet address and your session history.
02

What we do not have

We do not hold your funds. At no point does money move to us. It stays in the account you opened at the exchange, under your own credentials.

We cannot withdraw. The connection uses a key scoped to placing and cancelling orders. There is no withdrawal path for it to abuse. You can revoke it at the exchange at any time without asking us, and it also expires on its own.

We do not store exchange API secrets, seed phrases, mnemonics or wallet private keys. Never provide a wallet private key to us or to anyone claiming to be us: no part of this product ever needs one.

  • No custody. No withdrawal permission. No secret keys on our servers.
  • Revocable by you at the exchange, without our cooperation.
  • Anyone asking you for a seed phrase or private key is not us.
03

What we do collect

Your wallet address. It identifies your session and appears in our records and in our web server logs. It travels in the page address while you use the app, which means it is written into ordinary access logs in readable form. A wallet address is public on the blockchain, but it is still an identifier that points at you, and we would rather you know we have it than discover it later.

Your session records. When you start, stop, or complete a run we keep what happened: which venue and market, the settings you chose, counters, and the timestamps. We use these to run the product, to restore a session after a restart, and to measure whether our own strategy is working.

Ordinary web logs. Like any web server: your IP address, the time, the page requested, the browser you used. These rotate on the usual schedule and are used for operating the site and investigating faults.

Analytics. We run a Google Analytics tag on our public pages. It sets cookies and sends usage data to Google. We currently do this without asking for your consent first. That is accurate as of the date above and is being reviewed. If you would rather not be measured, browser-level tracking protection or an ad blocker stops it, and we will not treat you differently for using one.

  • Wallet address: stored, and present in server logs because it travels in the URL.
  • Session records: venue, market, settings, counters, timestamps.
  • Web logs: IP, time, page, browser.
  • Google Analytics: currently loads without a consent prompt.
04

Where data goes outside our servers

The exchange you connect. Orders and cancellations go there under your own key. What the exchange then does with that activity is governed by its own policy, not ours.

Google (Analytics). Usage data from public pages, as described above.

An AI assistant, if we enable it on a page. It is configured to run through a third-party model provider. Before anything is sent, the code strips a fixed list of sensitive fields (keys, secrets, signatures, tokens, mnemonics, passphrases, cookies) and shortens wallet addresses to their first six and last four characters. That redaction is part of the code, not a promise about our habits.

We do not sell your data, and we do not share it with advertisers.

  • The exchange, because that is where your orders belong.
  • Google Analytics: public page usage.
  • A model provider, if the assistant is enabled, with sensitive fields stripped first.
  • No sale of data. No advertising networks.
05

How long we keep it, and how to have it deleted

Session records are kept while they are useful for running and restoring your sessions and for measuring our own performance. Web server logs rotate on the ordinary schedule and are not kept indefinitely.

You can ask us to delete the data tied to your wallet address. Write to us on Telegram at t.me/sypherscore or on X at x.com/Cryptobalp, from an account you can show controls that address, and say which address you mean. We will confirm when it is done.

Two limits, stated plainly: we cannot delete anything from the blockchain, because we did not put it there and nobody can; and we cannot delete what the exchange holds about your account, which is between you and them.

  • Ask for deletion via Telegram or X, naming the address.
  • We cannot remove anything from a blockchain. Nobody can.
  • We cannot remove what your exchange holds about you.
06

Children, jurisdiction and changes

This product is not intended for anyone under 18.

If you are in a place where automated trading or these venues are restricted, that restriction is yours to observe; we do not check it for you and cannot advise you on it.

When this policy changes, the date at the top changes with it. We do not quietly rewrite it and pretend it always said that.

  • Not for anyone under 18.
  • Local restrictions are yours to check.
  • Changes are dated at the top of this page.
Questions

Questions

Can SypherScore withdraw my funds?

No. The key you connect can place and cancel orders and carries no withdrawal permission. Funds stay in your own exchange account throughout, and you can revoke the key at the exchange without our cooperation.

Do you store my exchange API secret?

No. We checked our own stored records while writing this: none of the session, launch, completed or stopped records contain an API secret, private key, mnemonic or signature.

Do you know my wallet address?

Yes. It identifies your session, it is stored in our records, and it appears in ordinary web server logs because it travels in the page address. It is public on-chain anyway, but we would rather say so than let you assume otherwise.

Do you use cookies or analytics?

We run a Google Analytics tag on public pages, which sets cookies. As of the date at the top it loads without asking for consent first. Browser tracking protection blocks it and we do not treat blocked visitors differently.

How do I get my data deleted?

Message us on Telegram (t.me/sypherscore) or X (x.com/Cryptobalp) from an account that can show it controls the wallet address, and name the address. We will confirm when it is done. We cannot delete blockchain records or anything your exchange holds.

Related SypherScore pages