MirrorTrade

Privacy policy

Last updated 6 October 2026 Version 1.0
Contents

The short version

  • No email needed to use it. Your MirrorTrade account is your wallet address. We never see your wallet's private key or seed phrase.
  • We hold one key, and it can only trade. We create it for your account and keep it encrypted. It cannot withdraw, and you can revoke it from your wallet at any time.
  • Your trades are public. Everything on Hyperliquid is. We cannot make it private.
  • No ads, no analytics, no trackers. This site sets no cookies. The app sets one, to keep you signed in.
  • We don't sell your data. Section 4 lists everyone else who sees any of it.
  • Ask and we'll show it or delete it. Through the contact page, answered within a month.

This summary is here so you actually read something. The numbered sections below are the policy, and where the two differ, the numbered sections win.

Contents
  1. Who we are
  2. What we collect
  3. What we use it for
  4. Who else sees it
  5. Public by design
  6. Cookies and browser storage
  7. How long we keep it
  8. Keeping it safe
  9. Your rights
  10. Where your data is
  11. Children
  12. Changes
  13. Contact

Who we are

MirrorTrade is run by one person, not by a company, as section 1 of the terms explains. In this policy "MirrorTrade", "we", "us" and "our" mean the operator of the service, as they do in the terms.

We decide how the personal data described here is used, which makes us its controller under data-protection law. This policy covers this site, the MirrorTrade app, and the copying engine behind it.

What we collect

Your wallet address

You sign in by signing a short message with your wallet. We keep the wallet address, and a record of each sign-in: when it started, when it was last used and when it ended. We never receive your wallet's private key or seed phrase.

Your account

The trader you follow, and every trader you have followed before. The wallet that trades, the size and risk limits you set, the coins you block, and any name you give the account. Whether you have approved the agent key and our fee, whether the account is live, any launch code you redeemed, and which button on our site you started from.

The agent key

When you set up copying, we create a trading key for your Hyperliquid account and keep it, encrypted. We record every time it is unlocked and why. What the key can and cannot do is in section 5 of the terms.

Your copying record

Every trade we copied or skipped for you, with its coin, side, size and price, and the reason for any skip. Your lifetime copied volume, which sets your fee. The details of any automatic freeze.

Telegram, if you link it

Your Telegram chat ID, so our bot can tell you about your first copied trade, a key that needs renewing, a freeze, or planned maintenance. We read nothing else from your Telegram account.

Messages you send us

The topic, name, email address and message you type into the contact form.

The sign-up list

The email address you enter in the sign-up box at the foot of each page, the page you were on, and which version of our sign-up pop-up you saw, if you saw one.

Server logs

Like any website, our servers log each request: your IP address, the time, and the address of the page you asked for. In the app that address includes your wallet address, and on this site it can include a launch code. The log also keeps what your browser sends about itself, such as its type and the page that linked you here.

What we don't collect

We don't ask for your name, ID documents, phone number or home address to use MirrorTrade. We take no card or bank details, because our fee is paid out of each copied order by Hyperliquid (terms section 9). We use no analytics, advertising or tracking services, on this site or in the app.

What you have to give us

Nothing, by law. To have an account you sign in with a wallet, because the wallet is the account. To get a reply you give an email address. Everything else in this section is created as you use the service.

What we use it for

Each use below names the reason data-protection law lets us do it.

  • Running the service you asked for: signing you in, copying trades, charging the fee, showing you your record, and sending the Telegram messages you linked. Reason: our contract with you.
  • Keeping it secure and working: logs, sign-in and key-use records, limits on how often a form can be sent, and spotting abuse. Reason: our legitimate interest in a safe service that works.
  • Answering you: the messages you send us. Reason: you asked, and our legitimate interest in replying.
  • Sending the news you signed up for: the sign-up list. Reason: your consent, which you can withdraw at any time.
  • Learning which parts of our site work: which button you started from and which pop-up version you saw. We look at counts, not at you. Reason: our legitimate interest in improving the site.
  • Showing traders' public records: the traders page and copy scores, built only from what Hyperliquid already publishes. Reason: our legitimate interest in showing customers who they can copy.
  • Meeting the law: tax and accounting records, and answering lawful demands. Reason: legal obligation.

We don't sell your data, rent it out, or use it for advertising. The only automatic decisions made about your account are the ones you set up: what to copy, at what size, and when to freeze.

Who else sees it

  • Hyperliquid receives every order we place for you, signed with the agent key. The approvals you sign during setup go from your browser straight to Hyperliquid. We also read Hyperliquid's public data about your account to show you your balance and positions.
  • Vultr runs our servers in Tokyo, so everything we hold sits on its machines.
  • Google's Gmail delivers contact-form messages to us and carries our replies.
  • Telegram carries our bot's messages to you, if you link it.
  • Cloudflare answers one question when you sign up from a less common email provider: your browser asks its public DNS service whether that domain can receive mail. Only the part after the @ is sent, never the whole address.
  • Courts, regulators and police, when the law requires us to hand something over, and anyone we must tell to stop fraud or harm.
  • A buyer, if the business changes hands. They must keep the promises in this policy for data collected under it.

Your wallet app is not ours. It has its own privacy policy, and what it does with your data is between you and its maker.

Public by design

Your trading is public. Anyone can look up a Hyperliquid address and see its positions, orders and history, including every trade we copy for you. If someone links your wallet address to you, they can see your trading. We cannot change that, and closing your MirrorTrade account removes nothing from Hyperliquid.

Traders we list. The traders page shows public Hyperliquid accounts from the venue's own leaderboard, with figures worked out from their public trades. If one of them is yours and you want it off our list, tell us through the contact page.

X-ray. The X-ray page checks a wallet in your browser, directly against Hyperliquid, and does not send the address to us. It does put the address in the page's link, so if you reload or share that link, the address reaches our server log like any other page address.

Cookies and browser storage

This site sets no cookies. The app sets one. Both keep a few small values in your browser's storage. None of them follows you to other websites.

Name, and whereWhat it's for
hl_session · cookie · appKeeps you signed in. Ends after 12 hours, or when you sign out.
wagmi.* · storage · appThe wallet software's note of which wallet you connected, so you don't reconnect on every page.
mt.arrival · this tab only · appThe launch code and button you arrived with, until setup applies them.
mt.dashboard.advanced · storage · appWhether you opened the dashboard's advanced view.
ctamodalVersion, ctamodalShown · storage · this siteWhich of two versions of our sign-up pop-up you get, and whether it appeared. Desktop only.
ctamodalSeen · this tab only · this siteThat you closed the pop-up, so it stays closed.

You can clear any of these in your browser's settings. Clearing hl_session signs you out.

How long we keep it

WhatHow long
The message you sign to sign inMinutes
A sign-in12 hours, then it ends. The record of it stays with your account.
Your account, copying record, and sign-in and key-use recordsWhile the account is open, then 6 years after you close it, for fees, tax and disputes.
The agent keyUntil you close the account. Revoking it on Hyperliquid makes it useless at once.
Your Telegram chat IDUntil you ask us to unlink it, or close the account.
Messages you send us6 years, as the record of what you asked and what we told you.
Your email on the sign-up listUntil you unsubscribe or ask us to remove it.
Your IP address, to limit how often a form is sentOne hour, in memory only.
Server logs30 days
Copying engine logs7 days. Our trading servers' system log also keeps a copy, for longer until we cut it to 30 days.
Database backups30 days

Logs and backups age out on their own schedule, so something we delete can stay in them until they do.

Keeping it safe

The site and the app are served only over HTTPS. Agent keys are encrypted with AES-256-GCM, each under a key of its own. The master key that unlocks those is kept outside the database, so a copy of the database or a backup cannot be used to trade. Every unlock is logged with its reason. Forms store no IP address. Only the people who run MirrorTrade can reach our servers.

No system is perfectly secure. If a breach puts your data at risk, we will tell you, and the authorities where the law requires it, without undue delay.

Your rights

Depending on where you live, you may have the right to:

  • see what we hold about you, and get a copy in a format you can reuse;
  • have it corrected;
  • have it deleted;
  • object to how we use it, or have us restrict it;
  • withdraw consent you gave, such as to the sign-up list, without affecting anything done before.

To use any of them, write to us through the contact page and choose Support. We answer within one month. If you're asking about an account, we may ask you to sign a short message with its wallet, so we know it's yours. That never needs your seed phrase or private key, and no one from MirrorTrade will ever ask you for either.

Some things we cannot delete: anything on Hyperliquid, and records the law makes us keep. If that applies to your request, we'll say so.

You can also complain to the data-protection authority where you live. We'd like the chance to put it right first.

Where your data is

Our servers are in Tokyo, Japan. The European Union and the United Kingdom both recognise Japan as protecting personal data to their own standard.

Google, Telegram and Cloudflare may handle the data they receive in other countries. Where data-protection law requires a safeguard for sending your data abroad, we use one the law recognises, such as standard contractual clauses.

Children

MirrorTrade is not for anyone under 18 (terms section 3). We don't knowingly collect their data, and if we find we have, we delete it.

Changes

When we change this policy, we post the new version on this page and change the date at the top. A change to how we use data we already hold is posted here before it takes effect.

Contact

Questions and requests about your data go to our contact page. Choose Support, and a person will read it.

There is no registered office to send formal notices to. Send them through the same contact page and we will confirm receipt in writing.