Coldfront
Draft. Items in [BRACKETS] are filled in before launch.

Privacy Policy

Last updated: [EFFECTIVE DATE]

This policy explains what information the Coldfront browser extension (the "Extension") and the website at cold-front.xyz (the "Site") handle. The controller is [COMPANY LEGAL NAME], [POSTAL ADDRESS] ("we", "us"). Contact: [email protected].

1. The short version

  • The Extension sends nothing to us. We have no servers the Extension talks to, no accounts and no analytics in the Extension.
  • Your API wallet key and your passphrase never leave your device.
  • The Extension talks only to Hyperliquid, to check your API wallet's approval and your account's referral code.
  • The Site uses cookie-free, privacy-first analytics.

2. The Extension

2.1 Stored on your device only

WhatWhereWhy
The API wallet private key, encrypted (PBKDF2-SHA256 with 600,000 iterations, AES-GCM)Chrome extension local storageSo you can unlock and trade
Your main account address, the API wallet address and nameChrome extension local storageTo show them and to check the API key belongs to them
An optional passkey credential ID (Touch ID and similar)Chrome extension local storageTo unlock without typing the passphrase
Your settings (auto-lock, idle lock and similar)Chrome extension local storageTo apply them
A list of main accounts already confirmed as using referral code COLDFRONTChrome extension local storageSo later unlocks need no lookup
The decrypted API key, while unlockedChrome's session storage, cleared when you lock or close the browserTo hand it to the Hyperliquid app

Your passphrase is used to decrypt the API key on your device and is never stored or sent anywhere. Removing the Extension deletes all of this.

When you remove the Extension, Chrome opens a page on the Site (cold-front.xyz/bye) that reminds you to revoke the API wallet and asks, optionally, why you left. The Extension attaches no data to that page. Your answer is a link to another page, counted by the Site's analytics like any page view.

2.2 Sent to Hyperliquid

The Extension sends requests to Hyperliquid's public information service (api.hyperliquid.xyz):

  • your main account address, to check that your API wallet is approved and when it expires;
  • your main account address, to check which referral code the account joined with.

These requests go directly from your browser to Hyperliquid. Hyperliquid receives your IP address and the address you ask about, like any request to it. Hyperliquid's own privacy policy covers what it does with them.

While the Extension is unlocked, it gives your API wallet key to the Hyperliquid app in your Hyperliquid tabs. The app uses it to sign your orders, which it sends to Hyperliquid.

2.3 What we never collect

We do not collect your keys, passphrase, balances, positions, orders, trading history, browsing history, or any content of pages you visit.

2.4 Chrome Web Store "Limited Use" statement

Coldfront's use of information received from Chrome APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. The Extension uses authentication information (the encrypted API wallet key) only to provide its single purpose: letting the official Hyperliquid app trade your account while the Extension is unlocked. It is not transferred to us or to anyone else except the Hyperliquid app as described above, not used for advertising, and not sold.

3. The Site

3.1 Analytics. We use Cloudflare Web Analytics, which does not use cookies, does not store your IP address and does not track you across sites. It counts page views, referring sites, countries and device types in aggregate.

3.2 Hosting logs. Our host, [Cloudflare], processes IP addresses and request details to deliver and protect the Site. [Cloudflare keeps these under its own policy.]

3.3 Email. If you join our list or email us, we keep your email address and messages to reply and to send the updates you asked for. Every email has an unsubscribe link. We use [EMAIL PROVIDER] to send email.

3.4 Partner links. Links with a partner tag (for example ?p=name) tell us which partner sent a visit, in aggregate.

3.5 No cookies are set by the Site itself. [If this changes, a cookie notice will be added.]

4. Legal bases (EEA and UK)

  • Replying to you and sending updates you asked for: your consent, or our legitimate interest in answering you.
  • Site analytics and security logs: our legitimate interest in running and protecting the Site, using data that does not identify you.

5. Sharing

We do not sell or rent personal information. We share it only with the service providers named above, to run the Site and send email, and when the law requires it.

6. Keeping data

Email addresses: until you unsubscribe or ask us to delete them. Support emails: [24 months]. Analytics: aggregate only.

7. Your rights

Depending on where you live, you can ask to see, correct, delete or export the personal information we hold about you, object to its use, or withdraw consent. Email [email protected]. You can also complain to your data protection authority. Because the Extension's data stays on your device, you control it directly: delete the vault in Settings, or remove the Extension.

8. Children

The Services are not for anyone under 18.

9. International transfers

Our providers may process data outside your country. Where required, they use standard contractual clauses or similar safeguards.

10. Changes

We will post changes here with a new "Last updated" date.