Gatu - Privacy Policy
Last Updated: July 21, 2026
This Privacy Policy ("Policy") explains how Gatu Corp. ("Gatu," "we," "us," or "our") handles personal data in connection with the interface available at https://app.gatu.ai and related Gatu websites and support services (collectively, the "Services"). Capitalized terms not defined here have the meaning given in our Terms of Use.
1. Scope and Roles
Gatu provides non-custodial interface software. Public blockchain networks, Hyperliquid, wallet and authentication providers, RPC providers, bridges, block explorers, and other third-party services process data under their own terms and privacy policies. Gatu does not control public blockchain records and generally cannot delete or alter information recorded onchain.
2. Personal Data We May Handle
Depending on how you use the Services, we may handle:
- Account and contact information: an email address, social-login identifier, support correspondence, or other information you choose to provide. Authentication providers may process this information before making limited account information available to the Interface.
- Wallet and transaction information: public wallet addresses, smart-wallet or Agent-wallet addresses, signatures, transaction hashes, orders, positions, balances, and other public or protocol-provided activity associated with an address.
- Device and usage information: IP address, approximate country or region, request date and time, requested path, browser and operating-system information, language, referral information, and technical diagnostics generated when the Services are accessed.
- Preferences stored on your device: language, theme, chart settings, favorites, account-mode preferences, and other local settings. Locally generated Agent credentials may also be stored on your device to support authorized trading. Gatu does not receive your seed phrase or wallet private key through ordinary use of the Interface.
3. How and Why We Use Data
We may use personal data to:
- provide, maintain, secure, and troubleshoot the Services;
- connect the Interface to wallets, authentication providers, Hyperliquid, blockchain networks, and supported third-party services;
- display account and transaction information requested by you;
- detect abuse, fraud, security incidents, sanctions exposure, or attempts to evade access restrictions;
- respond to support, legal, or regulatory requests;
- understand aggregate service reliability and performance; and
- comply with applicable law and enforce the Terms.
Where applicable, we rely on performance of a contract, legitimate interests in operating and securing the Services, consent, or compliance with legal obligations. Mandatory rights available under applicable data-protection law are not limited by this Policy.
4. Cookies, Local Storage, and Analytics
The Services may use cookies and browser storage for authentication, security, preferences, and feature operation. Clearing browser storage may remove settings or locally stored Agent credentials and may require you to reconnect or reauthorize a wallet.
As of the Last Updated date, the Interface does not integrate a product-analytics SDK. Infrastructure access logs and third-party providers may still process the technical data necessary to deliver, secure, and diagnose the Services. If Gatu later introduces a materially different analytics or tracking service, this Policy should be updated before that service is enabled.
5. When Data Is Shared
We may share data with service providers only as reasonably necessary for the purposes above, including:
- wallet, authentication, and account-abstraction providers;
- Hyperliquid and supported blockchain, RPC, bridge, and explorer providers;
- IP-based geolocation, hosting, content-delivery, security, and infrastructure providers;
- professional advisers, auditors, and insurers;
- law-enforcement, courts, regulators, or other authorities when legally required; and
- a successor or counterparty in a merger, financing, reorganization, or sale of relevant assets.
We may also disclose data to protect users, enforce the Terms, investigate security incidents, or prevent unlawful activity. We do not sell personal data in exchange for money.
6. Public Blockchain Data
Transactions and wallet activity submitted to public networks or decentralized protocols may be permanently public. A third party may associate a public address with other information about you. Do not submit information to a public blockchain that you do not want publicly available.
7. International Transfers
Providers may process data in countries other than your own. Where required, we seek to use appropriate transfer mechanisms, such as adequacy decisions, standard contractual clauses, or the United Kingdom international data transfer addendum. Public blockchain data may be replicated globally and may not be subject to conventional transfer controls.
8. Retention
We retain personal data only for as long as reasonably necessary for the purposes described here, including security, support, legal, accounting, and dispute-resolution requirements. Retention by public blockchains and independent third-party providers is governed by their systems and policies. Data stored only in your browser remains under your control until it is cleared or expires.
9. Security
We use reasonable technical and organizational measures intended to protect data, but no internet, wallet, browser-storage, or blockchain system is completely secure. You are responsible for securing your devices, wallets, credentials, recovery methods, and signing authorizations.
10. Children
The Services are not intended for anyone below the age of legal majority where they live. We do not knowingly collect personal data from children. Contact us if you believe a child has provided personal data through the Services.
11. Your Rights
Depending on your location, you may have rights to access, correct, delete, restrict, or object to processing of personal data, receive a portable copy, withdraw consent, or complain to a supervisory authority. These rights may be limited where data is public onchain, must be retained by law, or is controlled by an independent provider. We may need to verify your request before acting on it.
12. Third-Party Links and Services
The Services may link to or embed third-party services. Their privacy practices are governed by their own policies. Review those policies before using the relevant service.
13. Relationship to the Terms
This Policy forms part of the Terms. To the extent permitted by mandatory applicable law, the governing-law and dispute-resolution provisions in Section 13.3 of the Terms apply to this Policy. If this Policy conflicts with the Terms on a non-privacy contractual matter, the Terms control. Mandatory data-protection rights remain unaffected.
14. Changes to This Policy
We may update this Policy as the Services, providers, or legal requirements change. The Last Updated date identifies the latest revision. Material changes take effect when posted unless a later date is stated.
15. Contact
Questions or privacy requests may be sent to support@gatu.ai.