Privacy Policy
Effective Date: June 20, 2026 · Version 1.0
1. Introduction
HyperAudit LLC (“HyperAudit,” “we,” “us”) operates the smart contract audit platform at hyperaudit.io. This Privacy Policy explains what data we collect, how we use it, how we protect it, and your rights regarding that data.
2. Data We Collect
2.1 Account Information
- Email address
- Name (if provided)
- Password (hashed, never stored in plaintext)
- Wallet address (if paying via crypto)
2.2 Payment Information
- Transaction hash (for crypto payments on BSC)
- Stripe payment identifiers (card details are processed and stored by Stripe; we never see or store full card numbers)
2.3 Smart Contract Code
- Source code files you upload for audit
- Compilation artifacts if provided
- Contract metadata (file names, sizes, language)
2.4 Usage Data
- IP address
- Browser type and version
- Pages visited and actions taken
- Timestamps of interactions
- Device information
2.5 Consent Records
- Timestamp of Terms/Privacy Policy acceptance
- IP address at time of acceptance
- Version of documents accepted
3. How We Use Your Data
- Service Delivery: Processing your smart contract code through our AI analysis engine and delivering audit reports.
- Payment Processing: Verifying payments and associating them with audit orders.
- Communication: Sending audit status updates, report delivery notifications, and essential service messages.
- Service Improvement: Analyzing aggregate usage patterns to improve audit accuracy and platform performance. We do not use your specific code to train AI models accessible to other customers.
- Legal Compliance: Maintaining records required by law, responding to legal process, and enforcing our Terms.
4. Code Storage and Security
Your smart contract code is treated as confidential. We implement the following safeguards:
- Code is stored in encrypted database storage (Supabase with row-level security)
- Access is restricted to authenticated users viewing only their own submissions
- Code is transmitted over TLS 1.2+ encryption
- Internal access to customer code is limited to automated processing systems
- We do not share, sell, or publish your code
5. Data Retention
Smart contract code and audit reports are retained for 12 months from the date of audit completion. After 12 months, code files are permanently deleted. You may download your reports at any time during this period.
Account information is retained for as long as your account is active, plus 12 months after account closure for legal compliance purposes.
Payment records are retained for 7 years as required by U.S. tax and financial regulations.
Consent records (timestamps, IP, version agreed to) are retained indefinitely as legal evidence of agreement.
6. Third-Party Services
We use the following third-party services to operate the platform:
- Supabase (database and authentication) — stores account data, audit records, and code files. Data processed in the US.
- Vercel (hosting) — serves the web application. No customer code is stored by Vercel.
- Anthropic (AI analysis) — smart contract code is sent to Anthropic’s Claude API for analysis. Anthropic does not retain inputs for model training under our commercial agreement. Data processed in the US.
- Stripe (payment processing) — processes card payments. Stripe’s privacy policy governs card data. We never receive or store full card numbers.
- BNB Smart Chain (BSC) — crypto payment verification. Wallet addresses and transaction hashes are publicly visible on the BSC blockchain by nature of blockchain technology.
7. Your Rights
You have the right to:
- Access: Request a copy of all personal data we hold about you.
- Correction: Request correction of inaccurate data.
- Deletion: Request deletion of your account and associated data, subject to legal retention requirements.
- Export: Download your audit reports and account data in a machine-readable format.
- Objection: Object to processing of your data for purposes beyond service delivery.
To exercise any of these rights, contact us at privacy@hyperaudit.io. We will respond within 30 days.
8. International Data Transfers
Our services are operated from the United States. If you access the Service from outside the US, your data will be transferred to and processed in the US. By using the Service, you consent to this transfer. We rely on standard contractual clauses and service provider agreements to protect data transferred internationally.
9. Cookies and Tracking
We use essential cookies for authentication and session management. We do not use third-party advertising trackers. Analytics, if implemented, use privacy-respecting tools that do not sell data to third parties.
10. Children’s Privacy
The Service is not intended for individuals under 18 years of age. We do not knowingly collect data from minors. If we become aware that we have collected data from a person under 18, we will delete it promptly. If you believe a minor has provided data to us, contact privacy@hyperaudit.io.
11. Data Breach Notification
In the event of a data breach affecting your personal data or uploaded code, we will notify affected users via email within 72 hours of becoming aware of the breach, as well as any applicable regulatory authorities as required by law.
12. Changes to This Policy
We may update this Privacy Policy at any time. Changes take effect when posted with a new version number and effective date. We will notify users of material changes via email. Your continued use of the Service after changes constitutes acceptance. Previous versions remain referenced by consent records created under them.
13. Contact
For privacy inquiries:
HyperAudit LLC
Wyoming, USA
Email: privacy@hyperaudit.io