Linceo

Privacy Policy

Last updated: 2026-10-01

1. Who is responsible

Linceo is a personal project. The person responsible for the data it processes is identified below; the fields not yet filled in are not shown.

2. What we keep, and why

Only what the product needs. Legal basis: providing the service you ask for (GDPR art. 6.1.b), your consent where it says so (6.1.a) and the security of the service (legitimate interest, 6.1.f).

  • Your wallet address — public on-chain data. When you sign in we also keep when we first and last saw it and how many times you signed in.
  • Your session — the sign-in message you sign (SIWE) opens a session that lasts 7 days; nothing moves with that signature.
  • Telegram, if you link it — your chat id and @username, your language and your alert settings, to send you the alerts you asked for. Telegram is the only alert channel.
  • Your lists and settings — watchlist, copy portfolio, preferences (bankroll, filters), the Polymarket demo and your LinceBot link and level.
  • Agent keys, encrypted — if you turn on copy trading or link LinceBot, the key of the agent you authorise is generated and kept on our server encrypted (AES-256-GCM). It can place orders and cannot withdraw. Your wallet's key never reaches us.
  • Your consents — which version of the terms and notices you accepted, when, and the IP of the request, as proof of that consent (GDPR art. 7.1).
  • Account activity log — each account action (sign-in, including failed ones; lists, settings, consents, Telegram, contact, LinceBot, agents, data deletion) with its date, your IP and your browser (User-Agent), for security. Kept 30 days.
  • The contact form — your message, how to reach you if you say so, the page you were on and your wallet if you are signed in. It is forwarded to the operator's Telegram.
  • Where you came from — if you arrive from a link with campaign tags (utm_*), those tags, the page and the referrer, and your wallet if you later sign in. No IP and no browser data.
  • Server logs — the application log keeps no IP and is deleted after 14 days; the web server and container logs do record IP and browser and rotate by size (up to 50 MB per service, usually a few days).
  • Backups — encrypted (GPG) daily copies of all of the above, kept up to about 3 months.

3. What we do not keep

  • Your funds or your wallet's key: they never leave your wallet.
  • Bank or card details: we never ask for them.
  • Your name or ID: only what you choose to write in a message.
  • Advertising or third-party analytics: there are none.

4. Cookies and browser storage

All of them are needed for the site to work or remember a choice you made; none is for advertising or tracking.

  • hyperedge_session — your sign-in session (httpOnly, 7 days).
  • csrf_token — protects your actions against forged requests (until you close the browser).
  • hel, hev, hetheme — language, platform (Hyperliquid or Polymarket) and theme (1 year).
  • wagmi.store and other wagmi.* — the state of your wallet connection (address, network, connector), so it survives a reload (until you close the browser).
  • Local storage — your preferences, the copy cart, onboarding, the date you accepted the notice, campaign tags and your wallet connector's own data. It stays in your browser.

5. Who else takes part, and transfers

  • Hosting — Contabo GmbH, data centre in Lauterbourg (France, EU).
  • Hyperliquid and Polymarket — we query their public APIs with public addresses and send them the orders your agent signs.
  • Telegram — delivers your alerts and the contact messages to the operator.
  • WalletConnect / Reown — when you connect a wallet by QR or from your phone, the connection goes through their relay.
  • publicnode — your browser reads blockchain data (for example balances for a donation) from their nodes, which see your IP and the addresses queried.

Some of these services can process data outside the European Economic Area under their own terms. We sell no data and share none for advertising.

6. How long

Your account data stays until you delete it (there is no automatic deletion for inactivity). The activity log, 30 days; contact messages already read, the record of the alerts we sent and the traces of a data deletion, 90 days (unread messages are kept until they are handled); the application log, 14 days; the web server logs, a few days; backups, up to about 3 months. The record of your consents is kept after you delete your data, as proof that you gave them.

7. Your rights

Under the GDPR you can:

  • Access and portability — Account → «Download my data» gives you a copy of your account data (the consent record is shown on its own; the logs are not included).
  • Rectification — change your lists, settings and Telegram link from the site, or ask through the contact form.
  • Erasure — Account → «Delete my data» deletes your account data and closes your sessions. What remains: the consent record (as proof), the activity log until its 30 days run out and the backups until they rotate.
  • Withdraw consent — unlink Telegram or revoke your agents at any time.
  • Complain — to the Spanish Data Protection Agency (aepd.es).

8. Security

Agent keys are encrypted; sessions are signed and can be revoked; backups are encrypted. If a breach affected personal data, we would tell the affected users and the AEPD within 72 hours.

9. Contact

For anything about your data, the contact form at /contact.