WatchCrypto WatchCrypto
Markets Terminal Privacy
Log In

Privacy Policy

Last Updated: June 18, 2026

This Privacy Policy describes how Theorem Capital LLC ("Company", "we", "us", or "our") collects, uses, and protects your information when you use WatchCrypto ("Service").

1. Information We Collect

1.1 Information You Provide

  • Account Information: Email address, password (encrypted)
  • Profile Information: Display name (optional)
  • Alert Settings: Price alert configurations, notification preferences
  • Exchange and Trading Credentials: third-party exchange API keys and/or Hyperliquid agent-wallet (signing) keys you choose to connect, stored encrypted at rest (AES-256-GCM). These are limited-purpose trading credentials used only to carry out actions you initiate (such as placing or cancelling orders); you can revoke or delete them at any time.

1.2 Information Collected Automatically

  • Usage Data: Pages visited, features used, time spent
  • Device Information: Browser type, operating system, screen resolution
  • Log Data: IP address, access times, referring URLs
  • Approximate Location: We derive your country and region from your IP address (using MaxMind GeoLite2 data and our content delivery network's country signal) for sanctions-compliance purposes. This is country/region level only and is not precise geolocation.
  • Cookies: Session cookies for authentication, preference cookies

2. How We Use Your Information

PurposeData Used
Provide and maintain the ServiceAccount info, usage data
Send price alerts and notificationsEmail, alert settings
Transmit and sign orders you initiate at third-party venuesEncrypted exchange/agent credentials
Comply with sanctions and export-control laws (geo-blocking and circumvention prevention)IP address, derived country/region
Improve our ServiceAggregated usage analytics
Communicate with youEmail address
Prevent fraud and abuseIP address, device info

3. Information Sharing

We do not sell your personal information. We may share information only in these circumstances:

  • With your consent: When you explicitly authorize sharing
  • Service providers: Third parties that help operate our Service (hosting, analytics)
  • Legal requirements: When required by law or to protect our rights
  • Business transfers: In connection with a merger, acquisition, or sale of assets

4. Geolocation and Sanctions Screening

WatchCrypto is operated from the United States and is subject to U.S. economic sanctions and export-control laws. To comply with those laws, we use IP-based geolocation to enforce sanctions-based access restrictions and to detect and prevent circumvention. We resolve your IP address to a country and region only (not a precise location), using MaxMind GeoLite2 data and our content delivery network's (Cloudflare) country signal, in order to block access from comprehensively or precautionarily sanctioned jurisdictions, which currently include Cuba, Iran, North Korea, Syria, and the Crimea, Sevastopol, Donetsk, and Luhansk regions of Ukraine.

When access is blocked, we write a sanctions-compliance record containing a timestamp, a truncated SHA-256 hash of the IP address (pseudonymous; the raw IP address is not retained in that log), the resolved country and subdivision, and the requested path, to a dedicated append-only audit log. These records are retained to meet U.S. recordkeeping requirements as described in the Data Retention section.

IP geolocation is imperfect and may occasionally misidentify your location, which means a legitimate, non-sanctioned user could be wrongly blocked. If you believe you have been blocked in error and you are not located in, ordinarily resident in, or a citizen or national of a sanctioned jurisdiction, contact [email protected] to request review. We will not lift a block where doing so would conflict with applicable sanctions or export-control law.

5. Data Security

We implement industry-standard security measures to protect your information:

  • All data transmitted via HTTPS/TLS encryption
  • Passwords are hashed using bcrypt
  • API keys are encrypted at rest using AES-256
  • IP addresses recorded in sanctions block logs are stored only as a truncated SHA-256 hash; raw IP addresses are not retained in those logs
  • Regular security audits and updates
  • Access controls and monitoring

However, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.

6. Data Retention

  • Account data: Retained while your account is active, and deleted within 30 days of account deletion.
  • General server and usage logs: Retained for 90 days.
  • Sanctions-compliance records: Block logs (hashed IP address, resolved country and subdivision, and requested path) are retained for 10 years to meet U.S. Office of Foreign Assets Control (OFAC) recordkeeping requirements (rule effective March 12, 2025), after which they are deleted or anonymized. This 10-year legal hold can lawfully override an erasure request to the extent retention is required by law.
  • Analytics data: Aggregated and anonymized.

7. Your Rights

You have the right to:

  • Access: Request a copy of your personal data
  • Correction: Update or correct inaccurate data
  • Deletion: Request deletion of your account and data
  • Export: Download your data in a portable format
  • Opt-out: Unsubscribe from marketing communications

To exercise these rights, contact us at [email protected]

8. Cookies

We use cookies for:

  • Essential cookies: Required for authentication and security
  • Preference cookies: Remember your settings (theme, layout)
  • Analytics cookies: Understand how users interact with our Service

You can control cookies through your browser settings. Disabling essential cookies may affect functionality.

9. Third-Party Services

We use the following third-party services:

  • Supabase: Authentication and database (privacy policy: supabase.com/privacy)
  • Google Analytics: Usage analytics (privacy policy: policies.google.com/privacy)
  • Cloudflare: Content delivery, security, and country-level geolocation signal (privacy policy: cloudflare.com/privacypolicy)
  • Cryptocurrency Exchanges: When you connect API keys, data is shared per their policies
  • MaxMind GeoLite2: We resolve your IP address to a country/region to restrict access from sanctioned jurisdictions. This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.

10. International Data Transfers

Your information is processed in the United States. For transfers from the European Economic Area, the United Kingdom, or Switzerland, we rely on the EU-U.S. Data Privacy Framework (and its UK Extension and the Swiss-U.S. Data Privacy Framework) where applicable; otherwise, we rely on the European Commission's Standard Contractual Clauses, together with supplementary measures as appropriate.

11. Children's Privacy

Our Service is not intended for users under 18 years of age. We do not knowingly collect information from children.

12. California Privacy Rights (CCPA/CPRA)

This section describes the rights of California residents under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA").

Categories of personal information we collect:

  • Identifiers: email address and IP address;
  • Internet or other electronic network activity: usage and device information;
  • Geolocation: country/region only. Because this is not precise geolocation, it is not "sensitive personal information" under the CPRA; and
  • Trading credentials: exchange API keys and/or Hyperliquid agent-wallet keys, stored encrypted.

Sources of personal information: you, and your device when you access the Service.

Business purposes for which we use it: providing the Service; sanctions and export-control compliance screening; and security and fraud prevention.

We do not sell personal information, and we do not share it for cross-context behavioral advertising. California residents may request access to or deletion of their personal information, subject to the 10-year sanctions-record legal hold described in the Data Retention section. To exercise these rights, contact [email protected].

13. European Privacy Rights (GDPR)

If you are in the European Economic Area, the United Kingdom, or Switzerland, the following legal bases apply to our processing of your personal data:

  • Performance of a contract (Art. 6(1)(b)): to provide the Service, including routing and signing orders you initiate;
  • Compliance with a legal obligation (Art. 6(1)(c)): for sanctions and export-control screening and the related recordkeeping;
  • Legitimate interests (Art. 6(1)(f)): for security, fraud and abuse prevention, and preventing circumvention of geographic restrictions; and
  • Consent (Art. 6(1)(a)): only where we specifically ask for it, such as for non-essential analytics cookies.

You have rights under the GDPR including access, rectification, erasure, restriction of processing, data portability, and objection. The right to erasure is subject to the 10-year sanctions-records legal hold described in the Data Retention section, to the extent retention is required by law. To exercise these rights, contact [email protected].

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the "Last Updated" date.

15. Contact Us

For questions about this Privacy Policy or our data practices:

Theorem Capital LLC
Email: [email protected]

By using WatchCrypto, you acknowledge that you have read and understood this Privacy Policy.

© 2026 Theorem Capital LLC
Terms Privacy Telegram