Privacy Policy
Last updated: 14 August 2026
This policy explains what taker (taker.trade and its subdomains, the “Interface”) collects, why, and what you can do about it.
taker has no accounts in the usual sense. There is no email address, no password, and no name. Your identity here is a wallet address you already control, and most of what follows falls out of that.
1. What we collect
Section titled “1. What we collect”Identity
- Your wallet address, and the signature you produce when signing in. This is your identity on the Interface.
- A session identifier, stored in an HttpOnly cookie, so you stay signed in.
Jurisdiction signals
- Country and network operator (ASN) derived from your IP address, and whether the connection appears to come from an anonymising network. These are used to decide which venues and features are available to you and to meet sanctions obligations. The country and ASN present at sign-up are retained with your profile.
- Sanctions screening results for your wallet address.
What you do here
- Conversations with the assistant — your messages, its replies, and the identifiers of any orders proposed in them.
- Preferences the assistant has saved at your instruction, such as a default leverage or size.
- Risk limits you configure, and the daily counters that enforce them.
- Execution records — what was submitted, when, and what the venue answered.
- Price and funding alerts you set.
Technical
- Request metadata — IP address, user agent, timestamps, and error diagnostics — used to operate the service, rate-limit abuse, and debug failures.
If you bring your own model key
- Your provider API key, encrypted before storage using envelope encryption.
2. What we never collect
Section titled “2. What we never collect”- Seed phrases and private keys. Never requested. There is nowhere in the Interface to enter one, and no support process that would ever ask.
- Your model API key in readable form. It is encrypted before storage, and there is no code path anywhere that reads it back out — not for support, not for debugging, not in an export.
- Email addresses, names, phone numbers, or government identifiers. We do not ask for them, so we do not hold them.
3. How we use it
Section titled “3. How we use it”We use the data above to:
- authenticate you and keep you signed in;
- determine which venues and features are lawfully available to you, and to comply with sanctions and other legal obligations;
- construct, price, and submit the orders you ask for;
- show you your positions, balances, history, and alerts;
- generate the assistant’s replies;
- enforce the risk limits you set;
- operate, secure, and debug the service, and prevent abuse; and
- keep records of transactions where we are required to.
We do not sell your data, and we do not use it for advertising or behavioural profiling.
4. Who it is shared with
Section titled “4. Who it is shared with”Using taker necessarily involves other parties:
- The trading venue (Hyperliquid). It sees your address, your orders, and your positions, because it is the venue executing them. Its handling of that data is governed by its own terms.
- Your language-model provider (Anthropic or OpenAI). It receives the conversation, because it generates the replies. If you bring your own key, that relationship is directly yours and billed to you. Free-tier turns run on our key.
- Infrastructure providers. Cloud hosting and database services (Amazon Web Services) store the data described above; a network provider (Cloudflare) fronts the site and sees request metadata.
We may also disclose data where required by law, regulation, or valid legal process, or to protect the rights, safety, or property of users or the service.
If the service is transferred to another entity, data may transfer with it, subject to this policy.
5. How long it is kept
Section titled “5. How long it is kept”- Conversations, preferences, and alerts are kept until you delete them.
- Execution records and the audit trail are retained for a regulatory window and are deliberately not user-deletable. They are records of trades you made, which is a different category from chat.
- Rate-limit counters and short-lived operational data expire automatically, typically within a day.
- Sanctions screening results are cached and refreshed periodically.
6. Your controls
Section titled “6. Your controls”- Export everything. Settings → Your data → Export my data downloads a JSON file of your saved preferences and full conversation history, with long messages rehydrated rather than truncated. API keys are never included, because no read-back path exists to include them with.
- Delete a conversation. The × on any thread in the chat sidebar removes its messages and any overflowed content behind them.
- Forget preferences. Settings → Chat memory → Forget everything.
- Remove your model key. Settings → Remove key. A hard delete, not a flag.
- Stop taker trading. Revoke the delegated key from the venue’s own interface. That takes effect immediately and does not involve us.
Depending on where you live, you may also have rights to access, correct, delete, restrict, or object to processing of your personal data, and to data portability. Write to the address below and we will respond as the law requires. Where we cannot delete something — execution records, for example — we will tell you why.
7. Security
Section titled “7. Security”- The delegated trading key taker holds cannot withdraw or transfer funds. Even a full compromise of our systems would yield a key that can trade your account, not empty it.
- Secrets are protected with envelope encryption under managed keys, and are never returned by any API.
- Session cookies are HttpOnly, Secure, and SameSite, with CSRF protection on every state-changing request.
- Sensitive values are redacted from logs and error traces centrally, rather than case by case.
No system is perfectly secure, and we cannot guarantee absolute security.
8. Cookies
Section titled “8. Cookies”We use cookies that are strictly necessary for the Interface to work: a session cookie to keep you signed in, and a CSRF token cookie to protect state-changing requests. We do not use advertising cookies and we do not run third-party analytics trackers.
9. International transfers
Section titled “9. International transfers”The Interface is operated from the United States and data is processed there. If you access it from elsewhere, you are transferring data to the United States, which may not offer the same protections as your home jurisdiction.
10. Children
Section titled “10. Children”The Interface is not directed at anyone under 18, and we do not knowingly collect data from children. If you believe a minor has used the Interface, contact us and we will delete what we hold.
11. Changes
Section titled “11. Changes”We may update this policy. The version published here is the version in force, and the date at the top reflects when it last changed. Material changes will be signalled on the Interface.
12. Contact
Section titled “12. Contact”taker is the controller of the data described in this policy. Privacy enquiries and requests — including access, correction, deletion, and portability — go to [email protected].
See also the Terms of Service and the plain-English summary in Your data.