// legal

Privacy Policy

Last updated: June 26, 2026

This Privacy Policy explains how tideline.sh ("tideline.sh", "we", "us", or "our") collects, uses, and shares information when you visit tideline.sh, use our analytics APIs, or interact with any other service we offer (collectively, the "Services"). By using the Services you acknowledge the practices described below.

1. Information We Collect

We collect the following categories of information:

  • Account data. Email address, display name, avatar, and authentication identifiers when you sign in. If you use Google Sign-In, Google may provide basic profile data such as your email address, display name, profile image, and stable Google account identifier. We do not request Gmail, Drive, Calendar, contacts, or Workspace content scopes. Passwords are stored only as salted hashes and are never readable by tideline.sh staff.
  • API and usage data. API key identifiers, request metadata such as endpoint, method, status code, timestamps, IP address, user agent, and aggregate request volume.
  • On-chain queries. Wallet addresses, trader identifiers, and query parameters you submit to the Services. These addresses are public on-chain and are not linked to your account unless you explicitly associate them.
  • Billing data. For paid plans, we store plan selection, invoices, and limited payment metadata. Card numbers are handled by our payment processor and never reach tideline.sh servers.
  • Device and log data. Browser type, operating system, referring URL, pages viewed, session cookies, locale preference, and diagnostic logs.
  • Communications. Messages you send to support, feedback, and any information you voluntarily provide.

2. How We Use Information

We use personal data to:

  • Provide, operate, secure, and improve the Services.
  • Authenticate you, issue API keys, and enforce rate limits and quotas.
  • Use Google Sign-In data only to create, secure, and maintain your tideline.sh account.
  • Generate analytics, dashboards, AI-assisted summaries, and trader scores.
  • Bill for paid plans and prevent fraudulent or abusive use.
  • Detect, investigate, and prevent security incidents and abuse.
  • Communicate service updates, security notices, and product news you opted into.
  • Comply with applicable law and enforce our Terms of Service.

3. Legal Bases (EEA / UK users)

If you are in the European Economic Area or United Kingdom, we process personal data under the following legal bases: performance of the contract with you to deliver the Services, our legitimate interests in securing and improving the Services, your consent where applicable, for example for non-essential analytics, and compliance with legal obligations.

4. Cookies and Similar Technologies

We use strictly necessary cookies to keep you signed in, remember your language preference, and secure your session. We may use limited first-party analytics cookies to understand aggregate product usage. We do not use cross-site advertising trackers. You can manage cookies through your browser settings, but disabling essential cookies may prevent the Services from working.

5. How We Share Information

We share information only with:

  • Service providers that host infrastructure, process payments, send transactional email, operate error monitoring, and provide authentication. They are bound by confidentiality and data-processing agreements.
  • Hyperliquid and other upstream data sources to the extent required to fetch public blockchain and protocol data on your behalf. Queries routed to Hyperliquid contain only the data required to serve the request.
  • Legal and safety disclosures when required by law, subpoena, or to protect the rights, safety, or property of tideline.sh, our users, or the public.
  • Business transfers such as a merger, acquisition, or asset sale, in which case we will notify you before your information becomes subject to a different privacy policy.

We do not sell personal data, and we do not share personal data for cross-context behavioural advertising.

We do not sell Google user data, use it for advertising, or transfer it except as needed to provide authentication, security, account support, or legal compliance.

6. Data Retention

We retain account data for as long as your account is active and for a limited period afterward to comply with legal, accounting, and fraud-prevention obligations. Request logs are retained for up to 90 days in hot storage and may be retained longer in aggregate, non-identifiable form. You can request deletion at any time as described below.

7. Security

We use industry-standard security measures including TLS for all traffic, encrypted storage for credentials and keys, least-privilege access controls, and audit logging. No system is completely secure; we cannot guarantee absolute security, but we will notify affected users of confirmed breaches as required by law.

8. Google API Data and Limited Use

tideline.sh uses Google Sign-In for authentication. Our use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including Limited Use requirements. We do not use Google user data to train generalized AI models, build advertising profiles, or determine credit, insurance, employment, or lending eligibility.

9. International Transfers

tideline.sh operates globally, which may involve transferring personal data to countries other than your own. Where required, we rely on recognised transfer mechanisms such as the European Commission's Standard Contractual Clauses to protect your data.

10. Your Rights

Depending on where you live, you may have the right to:

  • Access, correct, or delete the personal data we hold about you.
  • Object to or restrict certain processing.
  • Port your data to another service.
  • Withdraw consent at any time where processing is based on consent.
  • Lodge a complaint with your local data-protection authority.

You can exercise most rights directly from the dashboard or by contacting us at the address below. We will respond within the timeframe required by applicable law.

11. Children

The Services are not directed to children under the age of 18, and we do not knowingly collect personal data from them. If we learn that we have collected data from a child, we will delete it promptly.

12. Changes to this Policy

We may update this Privacy Policy from time to time. We will post the updated version on this page and update the "Last updated" date. For material changes we will take reasonable steps to notify you, such as through the dashboard or by email.

13. Contact

If you have questions about this Policy or want to exercise your rights, contact us at [email protected].