← Back to DXAP

Privacy Policy

Effective September 12, 2026

DX Research Group, LLC, a Texas limited liability company (“DXRG,” “we,” “us,” or “our”), respects your privacy. This Privacy Policy explains how we collect, use, disclose, retain, and protect information when you access or use:

  1. DX: Terminal Pro, including https://terminal.markets and related pages, applications, interfaces, smart contracts, and Mini Apps;
  2. the DX Agent Protocol, also referred to as DXAP, including its alpha platform, Agents, APIs, SDKs, dashboards, tools, documentation, trading integrations, and legacy paper-trading records;
  3. any other website, application, API, agent, model, research program, service, sales activity, marketing activity, community program, or event that links to this Privacy Policy.

We refer to all of the foregoing collectively as the “Services.”

This Privacy Policy explains our information practices and your choices. Our Terms of Service govern use of the Services. Acknowledging this Policy or accepting the Terms does not by itself provide consent to optional processing. Where applicable law requires consent, we request a distinguishable choice separately from agreement to the Terms.

DXAP ALPHA DATA NOTICE: DXAP is an experimental trading platform. We may collect and analyze information about how you configure and use Agents, including prompts, strategies, model inputs and outputs, tool calls, execution traces, legacy paper-trading activity, live trading instructions, orders, positions, performance, errors, and security events. We may use this information to operate the Services, evaluate and improve Agents, train or develop models, create datasets and benchmarks, conduct and publish research, and develop commercial products, as described below. These operational and research records are distinct from account-linked product analytics and optional session recording described in Section 8. Availability and collection depend on the Service, enabled features, your choices, and applicable law. Optional browser analytics or recording choices do not replace the separate purposes and legal bases for operational or research processing.

If you have questions or wish to exercise a privacy right, contact us at hello@dxrg.ai.

1. Scope and Roles

This Privacy Policy applies to personal information processed by DXRG in connection with the Services. “Personal information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an individual or household, and includes equivalent concepts such as “personal data” under applicable law.

For purposes of European, United Kingdom, and similar data-protection laws, DXRG generally acts as the controller of personal information described in this Privacy Policy. In limited circumstances, such as when an organization uses an enterprise version of a Service under a separate data-processing agreement, DXRG may act as a processor or service provider on that organization’s instructions.

This Privacy Policy does not govern information processed independently by public blockchains, Hyperliquid, other trading venues, wallet providers, model providers, analytics providers, social networks, or other third parties. Their own notices and terms apply.

Providers acting on DXRG's behalf process information under the applicable agreement and instructions. Independently determined provider uses are addressed separately in Sections 3.3 and 5. A third party's terms or notice do not remove DXRG's responsibilities for its selection of providers or disclosure of personal information.

2. Information We Collect

The information we collect depends on which Services you use, the features you enable, and how you interact with us.

2.1 Information You Provide Directly

Account and Profile Information

We may collect your name, username, display name, email address, password or authentication information, organization, role, profile image, social handle, referral information, preferences, and other account or profile details.

We also record the legal notices presented, the versions acknowledged, acceptance and choice timestamps, the account identifier, and privacy choices. Browser-reported records are distinguished from independently maintained permission or authentication records.

Wallet and Blockchain Information

We may collect wallet addresses, public keys, wallet type, network, signatures used to authenticate or authorize transactions, token or NFT holdings relevant to access, and transaction information associated with a wallet.

We do not intend to collect wallet seed phrases. Do not provide a seed phrase or unrestricted private key through any Service, prompt, support request, or form.

Trading-Venue and Integration Information

If you connect DXAP to Hyperliquid or another third-party venue, we may process information necessary to establish and operate the integration, such as:

  • account, subaccount, vault, or agent-wallet identifiers;
  • public addresses and delegated account relationships;
  • API keys, access tokens, session keys, OAuth tokens, or other authorization credentials;
  • permissions and scopes associated with a credential;
  • balances, collateral, margin, positions, leverage, orders, fills, cancellations, funding payments, fees, liquidations, and account history;
  • risk limits, Agent limits, configuration settings, and trading preferences; and
  • information returned by the venue’s APIs.

Depending on the integration, credentials may be processed by DXRG or by a service provider acting on our behalf. You should grant only the minimum permissions needed and disable withdrawals or transfers whenever the venue permits.

Agent Inputs, Configurations, and User-Generated Content

We may collect prompts, natural-language strategies, system instructions you are permitted to configure, parameters, goals, constraints, model selections, files, datasets, code, messages, comments, questions, feedback, Agent names and avatars, and other content you submit or connect to the Services.

Do not submit confidential information, trade secrets, personal information about others, regulated data, or third-party content unless you have authority and a lawful basis to do so.

Paper-Trading and Simulation Information

We collect information about paper-trading Agents, including simulated balances, positions, orders, fills, profit and loss, portfolio changes, actions, strategies, scores, rankings, evaluations, and experiment participation.

Live Trading and Transaction Information

Where you enable live execution, we may collect or generate order instructions, order acknowledgments, fills, position data, account changes, transaction identifiers, blockchain records, fees, funding, and other activity associated with an Agent or connected account.

Communications and Support Information

We collect information you provide when you contact support, report a bug, participate in a community channel, respond to a survey, request access, join a waitlist, participate in an interview or research study, or otherwise communicate with us. This may include recordings or transcripts if we notify you and obtain any consent required by law.

If you choose to give us a Discord handle or another support contact, we may associate it with your DXAP account after verifying account ownership or confirming the association with you. We use this association to follow up on your support request. We do not infer that association from a public handle or automatically import Discord conversations into product analytics.

Payment and Billing Information

If you purchase a subscription, API access, or another paid Service, we may collect billing name, billing address, tax information, transaction records, and limited payment information. Payment card details may be collected directly by our payment processor rather than DXRG.

Identity, Eligibility, and Compliance Information

Where necessary, we or a compliance provider may collect date of birth, country of residence, government-issued identification information, sanctions-screening results, entity documents, beneficial-ownership information, or other information used to verify identity, eligibility, legal compliance, or fraud risk.

Marketing Preferences

We collect your preferences for email, product announcements, research updates, event invitations, and other communications.

2.2 Information Collected Automatically

Device and Connection Information

We may collect IP address, browser type, browser language, operating system, device type, device identifiers, application version, internet service provider, time zone, and approximate location derived from IP address.

Usage and Interaction Information

We may collect pages or screens viewed, links clicked, buttons used, searches, session dates and times, referring pages, navigation paths, feature usage, authentication events, wallet-connection events, and interactions with content, Agents, APIs, and other users.

Where optional session recording is offered and enabled, we may also collect interaction and displayed-content information to reconstruct selected use of the interface. Section 8 explains account linkage, covered information, safeguards, and choices. Session replay is distinct from audio or video recordings of support calls or research interviews.

Agent Telemetry and Execution Data

We may automatically collect detailed telemetry about Agent operation, including:

  • model and version information;
  • prompts and context provided to a model;
  • model outputs and responses;
  • tool and API calls and their results;
  • Agent actions, attempted actions, state changes, and decisions;
  • execution traces, intermediate artifacts, and workflow events;
  • latency, token usage, compute usage, retries, timeouts, and errors;
  • paper and live trading instructions and results;
  • safety-filter, risk-control, and policy events;
  • evaluation scores, human feedback, and automated assessments; and
  • crash, diagnostic, security, and performance logs.

API and Developer Information

We may collect API requests and responses, endpoint usage, timestamps, IP addresses, authentication identifiers, rate-limit events, errors, integration metadata, webhook activity, and information about applications built using our APIs or SDKs.

Cookies and Similar Technologies

We and our providers may use browser storage, software development kits, pixels, web beacons, and similar technologies for authentication, preferences, security, measurement, and communications. We do not use analytics cookies. Cookies needed for authentication or other requested functionality are separate from product analytics. Section 8 describes the applicable technologies, purposes, and choices.

Location Information

We may collect approximate location from IP address. We may collect precise device location only if you authorize access through your device or application settings.

2.3 Information We Receive from Third Parties

We may receive information from:

  • Hyperliquid and other trading venues, including account, permission, market, order, fill, position, balance, fee, and transaction data;
  • public blockchains and blockchain analytics providers, including wallet activity, token holdings, smart-contract interactions, and risk indicators;
  • wallet, authentication, and identity providers, including wallet addresses, authentication confirmations, profile information, and compliance results;
  • AI model and infrastructure providers, including model responses, usage metadata, errors, safety events, and service-performance information;
  • market-data, oracle, and analytics providers, including pricing, order-book, volume, asset, and market information;
  • payment processors, including payment status, billing identifiers, and fraud indicators;
  • social networks and community platforms, if you connect an account, use a Mini App, or interact with our official channels;
  • marketing, referral, and event partners, including registration information and campaign attribution;
  • security, fraud-prevention, and compliance providers; and
  • publicly available sources, including websites, public profiles, sanctions lists, and public regulatory or legal records.

2.4 Information That Is Public or Public by Design

Certain information may be public through the Services, a public blockchain, or a third-party venue, including public wallet addresses, Agent names, Agent avatars, public profiles, portfolio or performance information, rankings, scores, transactions, smart-contract events, and trading activity.

Public information can be viewed, copied, indexed, analyzed, and redistributed by others. We cannot control how third parties use information that is publicly available.

2.5 Sensitive Personal Information

Depending on your use, we may process information considered sensitive under some laws, such as account credentials, trading-account access information, government identifiers, precise geolocation, or financial account information.

We use sensitive personal information only for purposes reasonably necessary to provide, secure, and administer the Services; comply with law; prevent fraud; or for other purposes permitted by applicable law. We do not use sensitive personal information to infer characteristics about you except where permitted or with required consent.

Usable authentication secrets, including private credentials, access tokens, and session keys, are limited to authorized integrations, protection of the Services, compliance with law, and legal claims. We do not use those secrets as model-training content or publish, sell, or distribute them. Redacted diagnostics and security-event information that do not expose a usable secret may be used for lawful evaluation, research, and improvement. Optional analytics or recording consent does not authorize processing prohibited by sensitive-data law or use of another person's information without the required authority or legal basis.

3. How We Use Information

We may use personal information for the following purposes or as otherwise disclosed when information is collected.

3.1 Provide, Operate, and Administer the Services

We use information to:

  • create, authenticate, and manage accounts;
  • connect wallets, Agents, APIs, and third-party integrations;
  • operate paper-trading simulations;
  • transmit authorized live trading instructions to third-party venues;
  • retrieve and display balances, positions, orders, fills, and performance;
  • maintain Agent state, configurations, history, and permissions;
  • process payments and provide paid features;
  • provide support and respond to requests; and
  • deliver notices, updates, security alerts, and administrative messages.

3.2 Operate, Evaluate, and Improve Agents

We use Agent Inputs, Agent Outputs, Agent Activity, telemetry, evaluations, and related data to:

  • operate and troubleshoot Agents;
  • evaluate instruction following, reasoning, tool use, safety, reliability, and trading behavior;
  • compare models, prompts, architectures, strategies, tools, and configurations;
  • improve Agent design, risk controls, interfaces, and performance;
  • identify unexpected, unsafe, manipulative, or abusive behavior; and
  • develop new Agents, features, models, datasets, benchmarks, and Services.

3.3 Artificial Intelligence and Machine-Learning Training

Unless prohibited by applicable law or a separate written agreement, we may use User Inputs, Agent Outputs, Agent Activity, support interactions, feedback, and related information to develop, train, fine-tune, test, validate, benchmark, or improve artificial intelligence and machine-learning systems operated by DXRG or its service providers.

We may engage model, infrastructure, evaluation, and other providers to process information for DXRG, including to operate Agents and to develop, fine-tune, evaluate, or improve systems for DXRG. When a provider acts on our behalf, its processing is subject to our applicable agreement and instructions. A provider's use of information for its own independently determined purposes, including improvement of its general-purpose models, is a distinct use. Where we permit such use, we describe the relevant provider or recipient category, information, purposes, and applicable choices before that use occurs and obtain any consent required by law. Provider terms do not remove DXRG's responsibilities for the information it discloses.

A choice about optional browser analytics or session recording does not itself authorize unrelated model training, research publication, or marketing. Operational information lawfully collected to provide Agents may also be used for the separately described evaluation, research, and model-development purposes under an applicable legal basis. Authentication secrets are subject to Section 2.5, and retained datasets and trained artifacts are subject to Section 9.

3.4 Research, Publications, and Commercial Development

We may use information to study autonomous Agents, agentic markets, market dynamics, human-agent interaction, trading behavior, digital assets, safety, security, and other research topics.

We may create and publish research papers, reports, articles, demonstrations, case studies, leaderboards, benchmarks, datasets, or commercial products using:

  • aggregated or de-identified information;
  • public blockchain and public venue information;
  • public Agent profiles and performance information;
  • pseudonymous identifiers such as wallet addresses or Agent identifiers where appropriate; and
  • excerpts, examples, or findings derived from Agent Inputs, Agent Outputs, and Agent Activity, subject to applicable law.

We make commercially reasonable efforts to avoid directly identifying individuals in public research unless the information is already public, the identification is necessary and lawful, or we have permission. However, pseudonymous blockchain or Agent data may sometimes be linked to an individual by third parties.

We distinguish information you make public through a feature from private source information. Designating an Agent profile or a transaction as public does not itself make associated private prompts, account information, or credentials public. Publication of excerpts, datasets, demonstrations, and commercial materials remains subject to applicable rights and the commitments in this Policy. We assess whether combinations of wallet, Agent, account, and activity information can identify a person; public availability or removal of a name does not itself establish anonymity or unrestricted reuse rights.

3.5 Analytics and Product Development

We use information to understand usage, measure interest, analyze adoption, evaluate experiments, plan capacity, develop features, personalize experiences, and improve the quality, usability, and performance of the Services.

For signed-in use, we may associate product events and diagnostic information with your account across sessions and with service records, including wallet relationships, Agent use, setup state, funding, and trading activity. We may group accounts by confirmed setup or usage state to understand adoption, retention, feature use, and relevant support needs. Where enabled, session recordings may also be account-linked. Section 8 distinguishes current analytics collection from additional browser analytics or recording features and describes provider disclosures and choices. These account-linked records are identifiable or pseudonymous, not anonymous merely because they use internal identifiers.

3.6 Security, Integrity, Fraud Prevention, and Enforcement

We use information to:

  • secure accounts, wallets, credentials, Agents, APIs, and infrastructure;
  • detect unauthorized access, malware, prompt injection, model abuse, API abuse, fraud, market manipulation, sanctions evasion, and other prohibited conduct;
  • investigate incidents, complaints, and violations;
  • enforce our Terms and other policies;
  • protect users, DXRG, third parties, and the public; and
  • maintain logs and evidence related to security or legal matters.

3.7 Legal and Regulatory Compliance

We use information to comply with laws, regulations, legal process, court orders, governmental requests, tax obligations, sanctions requirements, and other legal duties; establish, exercise, or defend legal claims; and respond to lawful requests from authorities or third parties.

3.8 Communications and Marketing

We may use contact and usage information to send product announcements, research updates, newsletters, invitations, surveys, promotions, or other marketing, subject to your preferences and applicable law. You may unsubscribe from marketing emails using the link in the message, but you may continue to receive transactional, security, and administrative communications.

3.9 Public Features, Rankings, and Community

We may use and display public profile, Agent, wallet, performance, portfolio, ranking, score, and activity information to operate leaderboards, competitions, public profiles, research displays, and community features.

3.10 De-Identification and Aggregation

We may create aggregated, anonymized, or de-identified information and use or disclose it for research, analytics, product development, publication, commercialization, security, and other lawful purposes. Where required by law, we will not attempt to re-identify information that has been de-identified, except to test the effectiveness of de-identification or as otherwise permitted.

An internal identifier, a wallet address, or removal of a name does not by itself make information de-identified. Where we rely on information being de-identified, we take measures designed to prevent reasonable association with an individual, maintain it in that form, and impose recipient restrictions required by law. Information that remains reasonably linkable to an individual is handled as personal information.

3.11 Business Operations and Transactions

We use information for accounting, audits, corporate governance, insurance, financing, due diligence, and business transactions such as a merger, acquisition, reorganization, sale of assets, or transfer of business.

4. Legal Bases for Processing

Where applicable law requires a legal basis, we identify the basis for each processing activity before undertaking it. Accepting the Terms or granting an intellectual-property license does not make every described use necessary to perform a contract. General product improvement, research, and model development are assessed separately from processing genuinely needed to provide a requested Service.

  • Contractual necessity: processing necessary to provide the Services you request, authenticate you, operate Agents, maintain integrations, process transactions, and perform our agreement with you.
  • Legitimate interests: processing necessary for our legitimate interests or those of a third party, including improving and securing the Services, conducting research, developing products, preventing abuse, communicating with users, and operating our business, where those interests are not overridden by your rights.
  • Consent: processing based on consent, including optional browser analytics, device storage or access, session recording, certain marketing, precise location, or other activities where consent is required. You may withdraw consent at any time without affecting processing that was lawful before withdrawal.
  • Legal obligation: processing necessary to comply with law, regulation, legal process, sanctions, accounting, tax, or other legal requirements.
  • Vital interests: processing necessary to protect a person's vital interests where that basis is available under applicable law.

For processing based on legitimate interests, we assess the purpose, necessity, reasonable expectations, impact on individuals, and safeguards. Establishing or defending legal claims is a processing purpose, not a standalone legal basis. Where relevant, we also apply the additional conditions required for sensitive or other specially protected information.

The following table explains how these purposes are distinguished. A listed basis applies only where its legal conditions are met; we do not treat the alternatives as interchangeable permission for every use.

Purpose Typical Information Typical Legal Basis
Operate requested accounts and integrations Account, wallet, authentication, transaction, and support information Contractual necessity for the requested functionality
Operate paper and live Agents and model inference User Inputs, configurations, credentials, venue data, Agent Activity, Agent Outputs Contractual necessity for the requested Agent or integration
Security and fraud prevention Device, usage, credential, wallet, transaction, Agent, and risk information Legitimate interests in protecting the Services; legal obligation for required compliance
Research and development Agent telemetry, inputs, outputs, performance, usage, public blockchain data Legitimate interests; consent where required
AI training and model improvement beyond requested inference User Inputs, Agent Outputs, Agent Activity, feedback, evaluations Assessed legitimate interests in development and evaluation; consent where required
Product analysis from lawfully collected service records Account and Agent lifecycle, setup, funding, activity, and support states Assessed legitimate interests in understanding and improving the Services, subject to applicable choices and purpose limits
Optional browser analytics and session recording Browser/session identifiers, interactions, and permitted recording content Consent where required by device-access or data-protection law; otherwise an independently assessed lawful basis
Qualifying aggregate measurement Short-lived measurement inputs and aggregate statistics The applicable statistical-measurement exception only where all its conditions are met, together with a valid personal-data basis where needed; not a basis for retained person-level histories or replay
Marketing Contact, preference, and interaction information Consent where required; legitimate interests where permitted
Legal compliance and claims Identity, account, wallet, transaction, communications, and compliance information Legal obligation for required compliance; legitimate interests in establishing, exercising, or defending claims where permitted

5. How We Disclose Information

We may disclose personal information to the following categories of recipients.

5.1 Vendors and Service Providers

We may disclose information to companies and individuals that provide services to us, including cloud hosting, databases, cybersecurity, authentication, identity verification, sanctions screening, customer support, analytics, session recording, payments, email, communications, model inference, AI development, data labeling, evaluation, market data, blockchain infrastructure, and professional services.

Providers acting on our behalf are subject to contractual restrictions appropriate to their role and applicable law. A provider may have a different role for a distinct activity. Independent provider processing, including independent model development, is addressed as a separate use under Section 3.3 and the relevant disclosure; a provider's own terms do not replace our obligations. PostHog provides product analytics and, where enabled, recording functionality; Vercel provides public audience and performance measurement as described in Section 8.

5.2 AI Model and Infrastructure Providers

We may send prompts, context, files, market information, Agent instructions, Agent Outputs, and related metadata to third-party model, inference, data, or infrastructure providers to operate, evaluate, secure, or improve the Services.

5.3 Hyperliquid and Other Trading Venues

When you connect or authorize an integration, we disclose information and instructions necessary to authenticate, retrieve account information, transmit orders, manage positions, and otherwise operate the integration. The venue independently processes information under its own terms and privacy practices.

5.4 Wallets, Blockchains, and Smart Contracts

When you sign or submit a blockchain transaction, information such as wallet address, transaction data, asset amount, contract interaction, and other transaction details may be publicly recorded on a blockchain. Blockchain information may be permanent and visible worldwide.

5.5 Affiliates

We may disclose information to entities that control, are controlled by, or are under common control with DXRG for the purposes described in this Privacy Policy.

5.6 Research and Commercial Partners

We may disclose aggregated, de-identified, public, or pseudonymous information to research institutions, collaborators, publishers, evaluators, customers, and commercial partners. We may disclose identifiable information where you direct us, consent, the information is already public, or disclosure is otherwise lawful.

5.7 Other Users and the Public

Information you make public, information associated with public wallet activity, and information displayed through public Agent profiles, leaderboards, competitions, or research features may be disclosed to other users and the public.

5.8 Business Transfers

We may disclose or transfer information in connection with an actual or proposed merger, acquisition, financing, reorganization, bankruptcy, receivership, sale of assets, or other business transaction. The recipient may continue to process information as described in this Privacy Policy unless you are notified otherwise.

5.9 Legal, Safety, and Enforcement Disclosures

We may disclose information to courts, regulators, law-enforcement agencies, governmental authorities, venue operators, security researchers, counterparties, or other third parties when we believe disclosure is necessary or appropriate to:

  • comply with law, legal process, or a valid request;
  • enforce agreements and policies;
  • investigate fraud, manipulation, abuse, security incidents, or unlawful activity;
  • protect rights, property, safety, markets, systems, users, or the public;
  • prevent financial loss or other harm; or
  • establish, exercise, or defend legal claims.

5.10 At Your Direction or With Your Consent

We may disclose information when you ask us to, enable an integration, authorize an Agent, participate in a public feature, or otherwise consent.

6. Ownership Terms and Privacy Rights

Our Terms of Service allocate ownership and intellectual-property rights in Agents, Agent Activity, Agent Outputs, User Inputs, and related materials. Those contractual provisions do not eliminate or reduce privacy rights that cannot be waived under applicable law.

Personal information is not treated as outside the scope of privacy law merely because DXRG owns or has a license to associated content, data, Agent Activity, or Agent Outputs. We will respond to valid privacy requests as required by applicable law, subject to exceptions and limitations described below.

7. Public Blockchains, Public Venue Data, and Immutability

Public blockchains are designed to create transparent and difficult-to-alter records. Information written to a public blockchain may be permanently available and replicated by unrelated parties. DXRG cannot edit, delete, or control information stored on a public blockchain.

Similarly, Hyperliquid and other venues may make order, trade, wallet, account, or market information publicly available or independently retain it. Requests to delete information from DXRG systems do not delete information held by a blockchain, venue, wallet provider, search engine, archive, or other third party.

You should avoid associating a public wallet with information you do not want publicly linked.

8. Browser Technologies, Analytics, and Session Recording

8.1 Technologies and Current Collection

We do not use analytics cookies. Authentication cookies and storage needed for security, preferences, and functionality you request are separate. Browser storage is not necessarily anonymous or exempt from privacy requirements merely because it is not a cookie. Blocking necessary cookies or storage may prevent requested functionality from working.

At this version's publication, public audience measurement uses PostHog's cookieless mode, which derives a short-lived identifier from IP address and browser characteristics with a rotating salt. That browser instance does not identify your DXAP account or persist an analytics identifier in your browser. The identifier is not described as anonymous solely because it is hashed. Vercel also provides cookieless audience and performance measurement.

The signed-in app supports account-linked product events and masked session recording as described in this Policy. Signup includes one acknowledgement of the Terms and this Privacy Policy; there is no separate analytics section or cookie popup. The app enables the disclosed collection following that acknowledgement, subject to prior objections, browser privacy signals, separately obtained permissions where required, and applicable law. We record the acknowledgement as such, not as a separate optional-consent action. Permissions documented outside the app remain distinct from a new in-app acceptance action.

The following subsections describe the enabled scope and safeguards. This notice does not retroactively change the treatment of previously collected information or replace any required affirmative choice. Before a material expansion, we provide the applicable feature information and controls and any notice required under Section 16.

8.2 Account-Linked Product Analytics

Depending on the Service, enabled features, your choices, and applicable law, additional product analytics may include pages and screens viewed, navigation, clicks and other feature interactions, Agent lifecycle and chat-use events, timestamps, durations, browser and device characteristics, session identifiers, browser identifiers, and diagnostic categories. To understand conversion, funding, retention, and Agent use, we may also analyze account and Agent identifiers, wallet relationships, referral attribution, deposit amounts and counts, account values, and trading-activity summaries.

For permitted signed-in analytics, PostHog receives your internal account identifier, session/browser identifiers, app and setup events, Agent and execution-account identifiers, panels opened, chat submission/response outcomes, timing and diagnostic categories, and selected financial state observed through the app: available USDC, account cash/equity, and open-position counts. Deposit-widget success is identified as a provider-reported browser callback, not proof of a complete funding ledger. Chat events do not include message bodies. This pipeline does not export raw wallet addresses, referral-code values, prompts, strategies, credentials, raw error bodies, or private support transcripts. The wallet-to-account mapping remains in DXRG service records. Permitted events and recordings may be account-linked across sessions; these records are identifiable or pseudonymous.

The app uses localStorage for permitted PostHog identity/session state and browser privacy records, rather than analytics cookies. SDK session state may also use sessionStorage for tab/session coordination. Session storage normally lasts for the browser-tab session; persistent state lasts until a reset, deletion, changed choice, or applicable version/retention limit. On logout or account change, app analytics identity is reset. Browser choices are scoped to the account on that browser. Optional storage, access, and collection requiring consent begin only after that consent. A first-party domain, internal ID, or cookie-free design is not treated as an automatic exemption.

8.3 Session Recording

Where recording is enabled, PostHog may reconstruct layout, navigation, clicks, scrolling, and other selected interactions in the Terminal, Summary, Agent builder, and Chat views. Recordings are associated with your internal account/session identifiers and may be reviewed by authorized DXRG personnel and service providers for usability, troubleshooting, and support. Raw session recordings are currently configured for 30-day retention. Product events and necessary legal/security records follow the separate criteria in Section 9. Profile, Settings, public pages, deposit widgets, and embedded wallet/third-party frames are excluded from the selected recording scope. Normal page text and inputs are masked; selected fixed interface labels remain readable. Network request/response bodies, headers, console logs, and canvas capture are not included. This recording does not authorize a provider's independently determined model-training use.

Recording is not permission to capture every field. We exclude usable credentials, seed phrases, unrestricted private keys, authentication tokens, and government identifiers from product analytics and replay. We apply masking or redaction before transmission to the content excluded from the applicable recording scope, including private chat, strategy, support, or financial content not expressly included in that scope. Recording a chat-use event does not itself authorize recording the chat text. Browser permission or an analytics choice does not grant permission for an unrelated model-training or publication use.

We obtain separate affirmative permission before recording where applicable law requires it. Optional recording may be declined without losing access to the core Services. Where recording is offered, the information accompanying it identifies a persistently accessible control to stop future collection as easily as it was enabled. Earlier lawful recordings and privacy requests are handled under Sections 9 and 12.

8.4 Privacy Controls and Signals

We honor Global Privacy Control and recognized Do Not Track values of "1" or "yes" by suppressing browser product analytics and session recording and discarding unsent usage events. Authentication, requested trading functionality, security, necessary support, and minimal legal-choice records are separate. This broader browser-analytics commitment supplements any duty to apply a qualifying signal to covered sale, sharing, or targeted advertising and associated account information.

To document your legal acceptance and privacy preferences, the frontend retains a browser record and sends a minimal client-reported receipt to PostHog, including the internal account identifier, notice versions, action/time, recorded authorization source, and enabled or disabled collection states. This receipt is separate from behavioral analytics and does not include a session/browser identifier, wallet address, signature, or page content. It may be recorded even when usage analytics or replay is off. A browser receipt does not replace independently maintained permission records or imply that the wallet challenge proves acceptance of a particular notice version.

Where separate consent is required, we obtain and document it rather than treating acceptance of the Terms as that consent. A reference to this Policy does not remove an applicable consent requirement. Where a statistical-measurement exception requires an objection mechanism, we provide a simple free means to object and restrict that measurement to the exception's purposes. Retained individual histories and session recordings are not treated as exempt aggregate statistics.

When signed in, use the browser privacy controls at the end of this Policy to stop or change collection for the current account on that browser, or download your browser record. These controls are outside signup and do not add an onboarding step. Changes propagate to other open tabs on the same origin; other browsers and separately documented permissions are managed separately. Contact hello@dxrg.ai for account-wide requests, questions about earlier records, or assistance. Removing browser storage removes that local record and does not by itself erase information already lawfully received by DXRG or its providers.

9. Data Retention

We retain personal information for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Services, maintain Agent and trading history, conduct research, improve models, secure systems, comply with law, resolve disputes, enforce agreements, and support business operations.

We determine retention by category and purpose rather than applying an intellectual-property license as a retention period:

Category Retention criteria
Account and integration records Duration of the requested account or integration, followed by any period needed for applicable legal, security, dispute, or recordkeeping obligations
Product events and account analytics The period reasonably needed for the stated conversion, adoption, retention, or feature analysis, considering sensitivity and whether identifiable history remains necessary
Session recordings The stated troubleshooting, support, or usability-review period disclosed for the enabled recording feature; not automatically the longer research-data period
Support and communications Resolution of the request and a justified follow-up, service-improvement, legal, or security period
Agent telemetry, evaluations, and research datasets The relevant Agent history, documented development or research purpose, validation and reproducibility needs, applicable rights, and lawful retention limits
Legal, security, and financial records Applicable statutory periods, claim or investigation needs, and proportionate security requirements
Backups and restricted copies The applicable backup rotation or lawful hold; copies awaiting deletion are restricted from ordinary active use

We review continued need and delete or de-identify information when it is no longer needed for a permitted purpose. We respond to valid deletion, restriction, and objection requests as required by applicable law. We retain information after such a request only where an applicable legal exception or other lawful basis permits the particular continued processing, and explain any refusal or limitation as required by law. An intellectual-property license, technical inconvenience, or a general reference to research integrity is not itself an exception to an applicable deletion duty.

Account closure or withdrawal of consent does not transfer ownership of DXRG's models, datasets, benchmarks, or research, or automatically require deletion of every product previously developed through lawful processing. Where we rely on consent, withdrawal stops future processing based on that consent and does not invalidate earlier lawful processing. We assess whether a retained dataset, model, or other artifact still contains or exposes personal information and take the deletion, restriction, or other measures required by law. We do not treat model weights or derived artifacts as categorically exempt from privacy rights or binding remedies. We may continue using information and artifacts that we are lawfully entitled to retain and use, including appropriately anonymized or de-identified information.

Revoking a trading credential or closing an account does not automatically delete information already collected, information retained by a third-party venue, or public blockchain records.

10. Data Security

We use administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure. Measures may include access controls, logging, encryption in transit, credential management, environment separation, monitoring, and incident-response procedures, as appropriate to the information and system.

No security measure is perfect. Experimental software, autonomous Agents, third-party models, APIs, wallets, blockchains, and trading venues create additional risks. We cannot guarantee that information, credentials, or assets will remain secure.

You are responsible for securing your devices, wallets, private keys, passwords, API keys, and trading permissions. Use least-privilege credentials, enable available security features, monitor connected accounts, and promptly revoke credentials if compromise is suspected.

11. International Data Transfers

DXRG is based in the United States, and we and our providers may process information in the United States and other countries. These countries may have data-protection laws different from those in your location.

Where required for transfers from the European Economic Area, United Kingdom, Switzerland, or another jurisdiction with transfer restrictions, we use recognized safeguards such as adequacy decisions, standard contractual clauses, the United Kingdom International Data Transfer Addendum, contractual protections, or another lawful transfer mechanism.

You may contact us for more information about applicable transfer safeguards.

12. Your Privacy Rights and Choices

Your rights depend on where you live and are subject to legal exceptions. You may have the right to:

  • Access personal information we hold about you and obtain information about its processing;
  • Correct inaccurate personal information;
  • Delete personal information;
  • Port certain personal information in a usable format;
  • Restrict certain processing;
  • Object to processing based on legitimate interests;
  • Withdraw consent where processing is based on consent;
  • Opt out of certain sales, sharing, targeted advertising, profiling, or other processing where applicable;
  • Limit use of sensitive personal information where applicable;
  • Appeal our denial of a privacy request where required; and
  • Complain to a data-protection authority or state regulator.

To exercise a right, email hello@dxrg.ai and describe your request. We may need to verify your identity and authority before responding. Verification may require confirmation through your email, account, wallet signature, or other information reasonably related to the request. We will use verification information only for verification, security, fraud prevention, and legal compliance.

To appeal a denied request where an appeal right applies, reply to the decision or email hello@dxrg.ai with "Privacy appeal" and enough information to identify the request. We will review and respond within the applicable legal period and explain any available regulator complaint route. Do not send a seed phrase, private key, or access token with a privacy request.

An authorized agent may submit a request where permitted by law. We may require proof of authorization and direct identity verification from the individual.

We will not unlawfully discriminate against you for exercising a privacy right. However, if information is necessary to provide a Service, deleting or restricting it may prevent continued use.

12.1 EEA, United Kingdom, and Switzerland

If you are in the European Economic Area, United Kingdom, or Switzerland, you may exercise the rights described above and lodge a complaint with your local supervisory authority. You may also object to direct marketing at any time.

Where we rely on legitimate interests, you may request information about the balancing assessment relevant to your circumstances. Where processing is based on consent, withdrawal does not affect the lawfulness of processing before withdrawal.

12.2 United States State Privacy Rights

Residents of California, Colorado, Connecticut, Delaware, Iowa, Indiana, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and other states with applicable privacy laws may have some or all of the rights described above, subject to the scope and effective date of the relevant law.

We do not sell personal information for monetary consideration. Some state laws define "sale," "sharing," or "targeted advertising" more broadly than a payment of money. Before engaging in covered activity, we provide the required information and opt-out mechanisms, including recognition of qualifying preference signals where required. Requests may also be sent to hello@dxrg.ai. The broader browser-analytics suppression described in Section 8 remains applicable independently of those statutory definitions.

12.3 Marketing Communications

You may opt out of marketing emails using the unsubscribe link in the email or by contacting us. Opting out of marketing does not stop transactional, security, legal, or Service-related communications.

12.4 Account Closure and Content Deletion

You may delete certain content through available account controls. To request account closure, contact us. Account closure and privacy requests are distinct from ownership and intellectual-property rights. The ownership and license terms do not override privacy rights or duties that cannot lawfully be waived. Section 9 explains lawful retention, research datasets, trained artifacts, and backups; Section 7 explains records independently held by public blockchains and venues.

13. California Privacy Notice

This Section supplements the rest of this Privacy Policy for California residents and is intended to address the California Consumer Privacy Act, as amended (“CCPA”).

13.1 Categories of Personal Information

The following table describes categories of personal information we may have collected in the preceding 12 months, examples, purposes, and categories of recipients. Whether we collected a category from you depends on your use of the Services.

CCPA Category Examples Purposes Categories of Recipients
Identifiers Name, email, username, IP address, wallet address, account ID, device ID Account operation, authentication, communications, security, analytics Service providers, affiliates, integrations, legal recipients
Customer records information Contact details, organization, billing details, account credentials Service delivery, billing, support, compliance Service providers, payment processors, affiliates
Commercial information Purchases, subscriptions, transactions, paper and live trading activity, positions, fees Operate Services, analytics, research, support, compliance Service providers, venues, affiliates, research partners as permitted
Internet or electronic activity Browsing, clicks, sessions, API usage, Agent interactions, logs Authentication, analytics, security, product improvement Hosting, analytics, security, model, and infrastructure providers
Geolocation Approximate IP-based location; precise location if authorized Security, localization, compliance, requested features Service and security providers
Audio, electronic, visual, or similar information Profile images, recordings or transcripts of support or research sessions Support, research, quality assurance Service providers, research collaborators as permitted
Professional or employment information Organization, role, business contact information Account administration, enterprise Services, communications Service providers, affiliates, business partners as directed
Inferences Preferences, risk signals, suspected interests, Agent or usage evaluations Personalization, security, analytics, research, product improvement Service providers, affiliates
Sensitive personal information Account credentials, trading-account access information, government identifiers, precise geolocation Authentication, integration operation, security, compliance Service providers, venues at your direction, legal recipients
User content Prompts, strategies, files, messages, Agent configurations, feedback Service operation, AI development, research, security, support Model providers, service providers, research partners as permitted

Sources include you, your devices, Agents, public blockchains, Hyperliquid and other venues, wallets, model providers, service providers, affiliates, partners, and public sources.

Optional session recording under Section 8 adds electronic interaction and visual information to the relevant categories, including the selected navigation, clicks, scrolling, and masked displayed content described there. Its introduction does not mean recordings existed throughout the preceding 12 months. Category-specific retention criteria are in Section 9.

13.2 Sale, Sharing, and Sensitive Information

We do not sell personal information for money. We do not use or disclose sensitive personal information for the purpose of inferring characteristics about a consumer except as permitted by the CCPA or with required consent.

Before engaging in an activity that constitutes sale or sharing for cross-context behavioral advertising under the CCPA, we provide the required notice and working opt-out methods. We honor qualifying opt-out preference signals, including Global Privacy Control, where required, and apply them to associated accounts as required. Disclosure to an analytics provider is assessed according to the actual relationship and use; neither the label "analytics" nor the absence of monetary payment determines the result.

13.3 California Requests

California residents may request access to categories and specific pieces of personal information, correction, deletion, and information about collection, use, and disclosure. They may also opt out of covered sale or sharing and limit certain uses of sensitive personal information where applicable.

To submit a request, email hello@dxrg.ai. We may verify the request as described in Section 12.

13.4 California “Shine the Light”

California residents may request information about certain disclosures of personal information to third parties for their own direct-marketing purposes, where applicable. Submit requests to hello@dxrg.ai with “California Shine the Light” in the subject line.

14. Children and Minors

The Services are not directed to children or anyone under 18, and we do not knowingly allow a person under 18 to create an account, operate an Agent, or use trading functionality.

If you believe a person under 18 has provided personal information, contact us at hello@dxrg.ai. We will take appropriate steps consistent with applicable law.

15. Third-Party Websites, Services, and Integrations

The Services may link to or integrate with third-party websites, wallets, model providers, blockchains, exchanges, trading venues, applications, or services. DXRG does not control their privacy or security practices. This Privacy Policy does not apply to information a third party processes independently.

Review the privacy policies and terms of each third party before connecting an account, granting permissions, submitting information, or conducting a transaction.

This does not limit our responsibilities for providers acting on our behalf or for disclosures we make, as described in Sections 1, 3.3, and 5.

16. Changes to This Privacy Policy

We may update this Privacy Policy and will identify the version and effective date. We will provide appropriate notice of material changes through the Services or another suitable direct means, including before a materially different collection or use where required by law. Where consent is required, we obtain it before beginning the relevant processing.

A policy update or continued use does not by itself enable optional tracking or recording that requires an affirmative choice, retroactively authorize materially different uses of previously collected information, or override commitments or law applicable when information was collected. We preserve applicable choices and provide any new choice required for an expansion. Changes apply from the stated effective date, subject to these requirements.

17. Contact Us

For questions, requests, or complaints about this Privacy Policy or our privacy practices, contact:

DX Research Group, LLC
Email: hello@dxrg.ai

If you are in a jurisdiction that requires a local representative or data-protection contact, you may request the applicable details by email.


© 2026 DX Research Group, LLC. All rights reserved.