Summary
HL Glass is an independent, read-only iPhone viewer for public Hyperliquid market data and public wallet addresses.
HL Glass never asks for or collects a private key, seed phrase, wallet signature, trading credential, or payment information. It has no wallet connection, order entry, deposit, withdrawal, asset-transfer, advertising, or cross-app tracking capability.
You can use core market viewing without adding an address. You can inspect a public address without creating a developer account. Device pairing, server alerts, aggregate portfolio history, and multi-device pinned-market sync are optional and stay off until you explicitly enable them.
Information Stored Only on Your iPhone
For users who do not opt in to optional cloud features, HL Glass keeps app data on the iPhone. This can include:
- A public wallet address you entered and its local label
- Markets you pinned in HL Glass
- Bounded market and public-account caches
- Locally derived position, order, fill, funding, and activity records
- Data-freshness, appearance, privacy, and app-lock preferences
- Sanitized diagnostics that do not contain a full wallet address or account amount
The local activity history is pruned after 180 days. Other caches are bounded, replaced by newer snapshots, or cleared by app controls. Removing a local address removes its local account data. Deleting the app removes its app container, subject to iOS and any device backup behavior you control.
Direct Requests to Hyperliquid
HL Glass requests public market information and, when you enter one, public wallet-address information directly from Hyperliquid’s public information interfaces. Hyperliquid may receive the public address, requested market, Internet Protocol address, timestamps, and ordinary network metadata needed to answer those requests under its own practices.
The developer does not use those direct requests as an analytics pipeline and does not receive your private key because the app never asks for one.
Optional Device Pairing
If you enter a one-time pairing code, the HL Glass control service receives:
- A random installation identifier, stored as a one-way hash
- A server-assigned device identifier
- A device display name
- App version and build number
- iOS version
- Short-lived access credentials and a rotating refresh credential
These credentials are stored in the iOS Keychain on the device and as hashes on the server. Pairing is not wallet authentication and grants no wallet or trading authority. The access credential lasts up to 24 hours; the rotating refresh credential lasts up to 90 days. Expired or revoked session records are removed after the documented 30-day cleanup window.
Optional Server Alerts and Aggregate History
Only after you explicitly enable server alerts, the service may receive and store:
- The public wallet address and your label
- Standard, Unified, or Portfolio Margin mode
- Alert types, thresholds, schedules, cooldowns, and minimal comparison state
- Aggregate portfolio snapshots such as account value, notional, margin used, withdrawable value, position count, source, and capture time
- An Apple Push Notification service token and delivery metadata
The full public address and active push token are encrypted at rest. Administrator views mask them. Raw private keys, signatures, trading credentials, and raw account-payload history are never accepted.
Optional Multi-Device Pinned Markets
Only after you explicitly enable multi-device sync, the service stores the market identifiers you pinned, a version number, the device that last updated the set, and update times. It does not turn those identifiers into trading instructions.
Disabling sync deletes the server-side pinned-market identifiers while leaving your local pins on the iPhone.
Analytics, Advertising, and Tracking
HL Glass does not include third-party advertising SDKs, behavioral analytics SDKs, tracking pixels, or cross-app tracking. It does not sell or rent personal data and does not build an advertising profile.
The developer control service may maintain bounded operational counts, health checks, security audit events, and rate-limit windows needed to secure and operate optional cloud functions. These are not used for advertising.
Service Providers
HL Glass uses these categories of third-party services:
- Hyperliquid public interfaces for public market and public-address data
- Cloudflare infrastructure for the optional control service, database, queue processing, access control, and public website
- Apple services for iOS distribution, Keychain, device authentication, and optional push notifications
These providers may process ordinary network and service metadata in locations where they operate, subject to their own terms and privacy practices.
Data Retention and Deletion
Server-side information is retained only for its operational purpose:
| Information | Retention |
|---|---|
| Aggregate portfolio snapshots | 90 days |
| Alert events and comparison history | 180 days |
| Push delivery attempts | 30 days |
| Operational usage snapshots | 90 days |
| Data-source health checks | 30 days |
| Management audit events | 180 days |
| Security, administrator, device, and wallet audit events | 365 days |
| Expired or revoked sessions, invalid push tokens, pairing challenges, and rate-limit windows | Up to 30 days after expiry or revocation |
To exercise the controls available in the app:
- Go to Settings → Server Alerts and choose Close and delete cloud address. This immediately removes the current device’s alert rules and address link. If no other paired device uses that observed address, the encrypted full address is cleared immediately; the deleted database record and dependent aggregate snapshots are removed within 30 days.
- Go to Settings → Multi-device Pinned Markets and disable cloud sync. This deletes the server-side pinned-market identifiers and keeps local pins.
- Use Settings → Remove Local Address to remove the address and its account data from this iPhone.
If a device credential has expired or been revoked, HL Glass does not falsely report a successful cloud deletion. Re-pair and retry, or contact @blocktom for assistance. The private administrator console can export or irreversibly delete an opted-in observed-wallet record. Security audit records may retain a masked or one-way identifier for the documented security period; they do not retain the full public address after wallet deletion.
Children
HL Glass is a general-audience financial information viewer and is not directed to children. The developer does not knowingly collect personal data from children through HL Glass.
International Processing
Hyperliquid, Cloudflare, and Apple may process service and network data in countries or regions where they operate. If you do not enable optional cloud features, HL Glass does not send your local app profile to the developer’s control service.
Security
HL Glass minimizes collection, separates direct public-data access from optional cloud services, encrypts sensitive cloud fields at rest, stores app credentials in Keychain, masks administrative displays, rate-limits sensitive APIs, and maintains bounded security audits. No security method can guarantee absolute protection.
Changes to This Policy
This policy may change when HL Glass, its optional services, or legal and platform requirements change. The updated version and effective date will be posted here. Material changes to optional collection will be explained before the related feature is enabled.
Contact
For support, privacy questions, data export, or deletion assistance, use the HL Glass support page or contact @blocktom.