Privacy Policy
1. Who we are
Dexly is a non-custodial trading interface for the Hyperliquid protocol, operated by Hyper Lion Ltd.
Hyper Lion Ltd, of Unit 501, Leroy House, 434-436 Essex Road, London, England, N1 3FY, is the data controller for the personal data described in this Privacy Policy.
Contact: hi@dexly.trade.
2. Scope
This Privacy Policy covers the Dexly web interface at dexly.trade and the Dexly mobile app. Both are operated by Hyper Lion Ltd.
Where data practices differ between the web interface and the mobile app, this policy says so. A statement about one is not a claim about the other.
This policy does not cover the Hyperliquid protocol, wallet providers, or other third-party services you reach through Dexly. Those have their own privacy practices, which we do not control.
3. What we collect
Dexly collects the following categories of personal data.
- Wallet address. The public address of the wallet you connect. This is the main identifier we use for you.
- IP address. Processed automatically by our hosting and security providers, including to derive your country.
- Device and browser information. Device type, operating system, browser, and similar technical data sent automatically by your browser.
- Usage events. Pages and screens you view and features you use, on the web interface and the mobile app.
- Session recordings. A replay of your session on the web interface, where analytics are active. See Analytics and session recording, below.
- Country. A two-letter country code derived from your IP address by our hosting provider's edge network, stored in a cookie for 30 days, and used to order wallet login options.
- Email address or social account identifier. If you sign in with an email address, Google, or Apple through Privy, we receive that identifier from Privy.
- Push notification token. If you use the Dexly mobile app and enable notifications.
- Referral code. If you sign up using a referral link, we link your wallet address to the referral code and to the wallet address that referred you.
3.1 Is any of this required?
A wallet address is necessary to use the trading interface. Without connecting one, there is nothing to trade with. That is a practical requirement of the service, not a statutory or contractual one.
An email address or social account identifier is only collected if you choose to sign in with Privy that way. Connecting a self-custodial wallet instead avoids this entirely.
Analytics and session recording are never required. Refusing them in the EEA or the UK costs you nothing functionally: the interface works the same either way.
4. What we never collect
Dexly is non-custodial by design. Regardless of how you use it, Dexly never collects:
- Your private keys.
- Your seed phrase or wallet recovery phrase.
- Custody of your funds. Dexly cannot move, freeze, or access your funds, because it never holds them.
5. How we use your data, and our legal basis
This table sets out each purpose we use your data for and the legal basis we rely on for it.
| Purpose | Data used | Legal basis |
|---|---|---|
| Operate the interface, including connecting your wallet and letting you trade | Wallet address, session data | Performance of a contract (our Terms and Conditions) |
| Authenticate you and keep you signed in | Wallet address, signed sign-in message, session tokens | Performance of a contract |
| Count page views in aggregate | Page address, referrer, device and browser type. No cookie or browser storage, no identifier lasting beyond the tab, no profile, no IP address retained | Our legitimate interest in knowing whether the site is used. This is the only measurement that runs in the EEA and the UK without your consent, and rejecting does not switch it off. |
| Understand how the interface is used and improve it, including by recording sessions | Wallet address as an analytics identifier, usage events, session recordings, device and browser data | Your consent, in the EEA and the UK. Our legitimate interest in improving Dexly, elsewhere. |
| Show and measure advertising, and attribute app installs to a campaign or referral | IP address, device and browser data, campaign and referral parameters | Your consent, in the EEA and the UK. Our legitimate interest in understanding which marketing works, elsewhere. |
| Secure the interface and prevent abuse, including the bot check on wallet export | IP address, device and browser data | Our legitimate interest in keeping Dexly secure |
| Order wallet login options for your country | Country, derived from your IP address | Our legitimate interest in showing you working login options |
| Send push notifications, on the mobile app | Push notification token | Your consent, given through your device notification permission |
| Administer the referral programme | Referral code, wallet address | Performance of a contract |
| Meet legal obligations and enforce our Terms and Conditions | Any of the data above, as relevant | Legal obligation. Our legitimate interest in enforcing our Terms and Conditions and preventing misuse. |
6. Analytics and session recording
PostHog identifies you in analytics by your wallet address. When you connect a wallet, we lowercase the address and set it as your persistent analytics identifier, so your activity is linked to that address rather than kept anonymous.
In the EEA and the UK, PostHog only starts once you accept analytics cookies. Outside the EEA and the UK, it starts automatically, because consent is not legally required there. See our Cookie Policy for how consent works.
Once active, PostHog may record a replay of your session on the web interface. A session recording can show your balances, open positions, and order sizes exactly as they appeared on screen.
You can stop analytics and session recording at any time using the Cookie settings link in the footer of every page.
9. International transfers
Some of the providers named above process data outside the UK and the EEA, including in the United States.
For those transfers we rely on the safeguards in Article 46 of the UK and EU GDPR, in practice the UK International Data Transfer Addendum (IDTA) or the EU Standard Contractual Clauses (SCCs), as offered by each provider. We are reviewing our agreements provider by provider to confirm which instrument applies to each, and will name them here once that is complete.
10. Retention
We keep personal data only as long as this table explains.
| What | How long |
|---|---|
| Country cookie (dexly_country) | 30 days from your last visit. |
| Cookie consent choice | Until you change it using Cookie settings. It does not expire on its own. |
| Agent wallet key | Held encrypted in your own browser only. We never receive a copy, so we cannot retain or delete it ourselves. Clearing your browser storage, or revoking the agent, removes it. |
| Sign-in message (one-time code) | 10 minutes, then it expires unused. |
| Session tokens (access and refresh) | Your access token lasts 15 minutes by default. It refreshes automatically while you keep using Dexly, so an active session rolls forward indefinitely rather than expiring on a fixed schedule. A session that goes unused expires 30 days after its last refresh, and you need to sign in again. |
| Account, wallet, and trade agent data (Supabase) | For as long as your account is active. If you ask us to delete your account, we delete or anonymise this data, other than what we must keep to meet a legal obligation. |
| Analytics events and session recordings (PostHog) | For as long as they remain useful for the purposes in the table above, then deleted or aggregated. |
| Advertising and attribution data (Google Ads, AppsFlyer, Firebase) | Set by each provider under its own privacy policy, not by Dexly. |
11. Your rights
Subject to conditions and exceptions under UK data protection law, you have the following rights.
To exercise any of them, contact us at hi@dexly.trade. We respond within one month, or tell you why we need longer.
You also have the right to complain to the Information Commissioner's Office (ICO), the UK's data protection regulator, at ico.org.uk. We would appreciate the chance to address your concern first, but you do not have to contact us before you contact the ICO.
- Access the personal data we hold about you.
- Rectification, to have inaccurate data corrected.
- Erasure, to have your data deleted.
- Restrict processing, to limit how we use your data.
- Data portability, to receive your data in a portable, machine-readable format.
- Object to processing based on our legitimate interests.
- Withdraw consent at any time, where processing is based on consent, without affecting processing that happened before the withdrawal.
12. Children
Dexly is not for individuals under 18. We do not knowingly collect data from anyone under 18.
If you believe a minor has provided personal data to us, contact hi@dexly.trade and we will delete it.
13. Security
We apply administrative and technical measures to protect the data described in this policy, including encrypting your agent wallet key before it is stored in your browser.
No system connected to the internet can be guaranteed completely secure. You are responsible for securing your own device, your wallet, and any private keys or seed phrases you hold outside Dexly.
14. Changes
We may update this Privacy Policy. The current version is always available at https://dexly.trade/legal/privacy. Continuing to use Dexly after a change takes effect means you accept the update.
15. Contact
For any question about this Privacy Policy, or to exercise your rights, contact:
Hyper Lion Ltd
Unit 501, Leroy House, 434-436 Essex Road, London, England, N1 3FY
Email: hi@dexly.trade
Website: https://dexly.trade
Owned and operated by Hyper Lion Ltd, London, United Kingdom.
Website: https://dexly.trade