Legal

Privacy Policy

Effective date: July 16, 2026

This Privacy Policy explains how Project Hyperion AI ("Hyperion," "we," "us," or "our") collects, uses, discloses, and protects information when you use Project Hyperion and related services at projecthyperionai.com (the "Service").

By using the Service, you acknowledge this Policy. For our contractual terms, see the Terms of Service.

1. Who we are

Hyperion provides educational market intelligence and decision-support tools across financial instruments. We do not place trades or act as your broker or investment adviser. Contact for privacy requests: privacy@projecthyperionai.com.

2. Information we collect

Account and identity

  • Name, email address, and password (stored hashed) when you sign up
  • Profile information from Google OAuth if you choose that sign-in method
  • Plan status (Free / Unlimited), subscription identifiers, and quota usage

Usage and product data

  • Contract analyses, scanner activity, watchlist items, positions context you provide, journal entries, and related preferences
  • Technical logs such as IP address, browser type, device information, approximate location derived from IP, timestamps, and error diagnostics
  • Communications you send us (support, password reset requests)

Payment information

Paid subscriptions are processed by PayPal. We receive subscription status and related billing metadata; we do not store your full payment card or bank credentials on our servers. PayPal's privacy policy governs their processing.

Cookies and similar technologies

We use cookies and similar technologies for authentication/session management, security, preferences (such as theme), and basic analytics needed to operate the Service. You can control cookies through your browser; disabling essential cookies may break sign-in.

3. How we use information

  • Provide, secure, and improve the Service
  • Authenticate users and enforce Free / Unlimited plan limits
  • Process subscriptions, cancellations, and related billing events
  • Send transactional email (password reset, security, subscription notices)
  • Operate Eclipse learning: store and analyze scans/analyses (including source tags such as hyperion_web) to grade outcomes and improve models and recommendations over time
  • Detect abuse, prevent fraud, and comply with law
  • Communicate product updates where permitted

4. Legal bases (EEA/UK where applicable)

Where GDPR or UK GDPR applies, we process personal data based on:

  • Contract — to provide the Service you request
  • Legitimate interests — security, product improvement (including Eclipse learning), and fraud prevention, balanced against your rights
  • Consent — where required (for example, certain cookies or marketing)
  • Legal obligation — when we must retain or disclose information by law

5. How we share information

We do not sell your personal information. We may share information with:

  • Service providers that help us operate (hosting, database, authentication, email, payments, error monitoring) under contractual confidentiality and processing terms
  • Payment processors (PayPal) for subscriptions
  • Professional advisers and authorities when required by law, legal process, or to protect rights, safety, and security
  • Business transfers in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate safeguards

Typical infrastructure categories include cloud hosting (for example Vercel), databases (for example Turso), application hosting for the Eclipse engine (for example Railway), email delivery (for example Resend), and OAuth providers (for example Google). Exact vendors may change; we select providers that meet our security needs.

6. Retention

We retain account and usage data for as long as your account is active and as needed to provide the Service, improve Eclipse, resolve disputes, enforce agreements, and meet legal, tax, and accounting requirements. You may request deletion of your account; we will delete or anonymize personal data unless we must retain it (for example, billing records or security logs).

7. Security

We use administrative, technical, and organizational measures designed to protect personal data (including encrypted transport, hashed passwords, and access controls). No method of transmission or storage is 100% secure; we cannot guarantee absolute security.

8. International transfers

We may process and store information in the United States and other countries where we or our providers operate. Where required, we use appropriate safeguards for cross-border transfers (such as standard contractual clauses).

9. Your rights

Depending on your location, you may have rights to access, correct, delete, or export your personal data; to object to or restrict certain processing; and to withdraw consent where processing is consent-based. California residents may have additional rights under the CCPA/CPRA, including the right to know, delete, and correct personal information, and to non-discrimination for exercising rights. We do not sell personal information or share it for cross-context behavioral advertising as those terms are commonly defined.

To exercise rights, email privacy@projecthyperionai.com. We may verify your identity before fulfilling a request. You may also have the right to lodge a complaint with a supervisory authority.

10. Children

The Service is not intended for individuals under 18. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will take appropriate steps to delete it.

11. Marketing communications

We send transactional messages related to your account. If we send optional product updates, you can unsubscribe where those messages include an opt-out, or by contacting us. Transactional messages required to operate the Service may still be sent.

12. Changes to this Policy

We may update this Privacy Policy from time to time. We will post the updated Policy and revise the effective date. Material changes may also be communicated by email or in-product notice.

13. Contact

Privacy questions or requests: privacy@projecthyperionai.com.

Legal: legal@projecthyperionai.com.

This Policy is drafted to align with common industry practices (including GDPR/CCPA-style disclosures for SaaS). It is not legal advice. Have qualified counsel review it for your entity, jurisdictions, and vendors before production reliance.

Terms of Service →