Legal
Privacy Policy
Last updated: July 14, 2026
Legal review status: pending external legal review before unrestricted public launch
1. Information We Collect
We collect information you provide directly:
- Email address and identity information provided through Privy authentication
- Wallet addresses connected to the platform and public strategy-permission addresses
- Algorithm metadata, workflow configuration, prompts, chat messages, generated artifacts, and approval decisions
- Hyperliquid account, market, position, order, fill, fee, and portfolio data you permission or request
- Cloud-provider and private-server status needed to connect customer-owned compute
- Bring-your-own-key AI provider metadata needed to route model requests
We also collect information automatically:
- Operational log data such as request identifiers, route names, timestamps, feature interactions, and error states
- Usage data such as API call frequency, quota state, model usage, runner health, and beta analytics events
- Cookies and similar technologies needed for authentication, session management, and beta operations
2. How We Use Your Information
- To provide and operate the Service
- To generate AI-assisted research, summaries, workflow drafts, historical tests, paper sessions, and execution previews you request
- To route prompts and context to selected AI providers, including providers configured with your own API keys
- To connect, authenticate, and monitor a customer-owned private server
- To process transactions and send billing communications
- To monitor platform health and detect abuse
- To comply with legal obligations
4. Data Retention
We retain account and product data while your account is active and then according to configured security, billing, dispute, abuse-prevention, and legal requirements. Temporary cloud-provider credentials are not retained as ordinary account data and are destroyed after successful provisioning or expiration.
Execution, fill, order, approval, policy-decision, revocation, reconciliation, security, and operational audit records may be retained or pseudonymized after account closure when necessary to preserve financial and security evidence. Billing and tax records may also be retained where required.
When AI memory or personalization is enabled, Mattheus may retain preferences, conversation summaries, lessons, and inferred context until you delete them or their configured validity or staleness period ends. Expired and stale items are excluded from normal AI retrieval. Tool and context access audit records use the configured audit-retention period, currently 90 days by default, subject to approved legal, security, and incident-response requirements.
Strategy source, raw research documents, datasets, full runtime logs, local memory, and local artifacts normally remain on a server owned by you. Revoking a Mattheus runner prevents future tasks, but Mattheus cannot truthfully erase an offline customer-owned disk. You must export, wipe, or destroy that server through your server provider.
5. Security
We implement security measures including encryption in transit, access controls, one-time pairing, short-lived credentials, credential rejection, log and receipt redaction, scoped strategy permissions, and security reviews. Sentry PII collection defaults off, and session replay or error events must mask text input and sensitive request fields. No system is perfectly secure. Protect your cloud account, API keys, wallet authorization, and server.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion or deactivation
- Object to or restrict processing
- Data portability
The account export provides a bounded, redacted copy of accessible central Mattheus data and clearly labels customer-server data that was not exported. Deactivation blocks new execution and revokes central credentials first. Deletion removes accessible product data and pseudonymizes retained records while preserving required financial, security, billing, and legal evidence.
Privacy actions require the signed-in user and explicit confirmation. Export or deletion may be partial while a customer-owned server is offline, because Mattheus cannot inspect or erase data that remains solely on that server.
8. International Transfers
Your data may be processed and stored in the United States and other countries, including a region you choose for your private server. If you are located in the European Economic Area, legally recognized transfer mechanisms or other safeguards are used where required.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes as appropriate. The updated policy will be posted at this URL with a revised date.
10. Contact
Privacy contact details are supplied through the verified controlled-beta support process.