Hunter Killer
← Back

Privacy Policy

Status: PUBLISHED — reviewed by an AI legal-review panel July 11, 2026; licensed-counsel review completed per owner sign-off 2026-07-25 (the August 7, 2026 amendments are engineering compliance revisions that post-date that counsel review and have not yet been reviewed by counsel; counsel re-review is tracked on the Operator's worklist) · Version: 1.2 · Effective date: 2026-06-19 · Last updated: August 7, 2026

About this Policy. This is a good-faith, standard-form privacy policy that has been reviewed by an AI legal-review panel and by licensed counsel engaged by Operator (counsel review completed per owner sign-off 2026-07-25; the amendments dated August 7, 2026 post-date that review). It is not itself legal advice. Nothing in this document asserts, and it must not be read as asserting, any license, registration, authorization, or regulatory status that Operator does not in fact hold.

Service: Hunter Killer (the "Service") · operated by Irishman Management LLC ("Operator", "we", "us")


1 · Summary

This Privacy Policy explains what personal data Hunter Killer collects, why we collect it, how we use and protect it, who we share it with, and the rights you have over it.

In plain terms:

Hunter Killer is a crypto liquidation-intelligence and manual-trade-discipline analytics tool. It is decision-support software; it is not a broker, dealer, investment adviser, or fiduciary, it does not custody your funds, and it does not pool capital or trade on your behalf autonomously. When the Service relays an order at your instruction, it executes on your own connected exchange account using your own API keys — we never take custody of your assets. See the Terms of Service and Risk Disclosure for the full description of what the Service is and is not.

2 · Who we are (data controller / business)

The entity responsible for your personal data ("controller" under the EU/UK General Data Protection Regulation ("GDPR"); "business" under CCPA/CPRA) is:

Irishman Management LLC
1931 Cordova Rd., Fort Lauderdale, FL 33316, United States
Privacy contact: privacy@hunterkiller.io
General support: support@hunterkiller.io

We have not appointed a Data Protection Officer ("DPO"). Our processing does not currently meet the mandatory-appointment thresholds in GDPR Article 37 (we are not a public authority, and our core activities do not consist of large-scale, regular and systematic monitoring of data subjects or large-scale processing of special-category data). You may direct all privacy questions to privacy@hunterkiller.io. If our processing changes such that a DPO becomes required, we will appoint one and update this Policy.

EU/UK representative (GDPR Article 27). Because the Operator is established outside the EU/EEA and the UK but offers the Service to data subjects located there, we are required to designate a representative in the EU and the UK. As of the effective date of this Policy we are in the process of designating such representatives; until that designation is published here, EU/EEA and UK data subjects may contact us directly at privacy@hunterkiller.io for any matter falling within Article 27, and we will respond and forward as required. We will update this section with the representatives' names and addresses once designated.

3 · What we collect

| Category | Data | Why | Retention | |---|---|---|---| | Account | Email address, password hash (bcrypt), signup timestamp, and the IP address and browser user agent recorded at signup and at security-relevant account events (e.g., password-reset requests) — kept with your account as evidence of your acceptance of the Terms, Risk Disclosure, and jurisdiction attestation and for fraud/abuse defense | Authentication, account recovery, attestation records, fraud/abuse prevention | Until account deletion + 30-day grace | | Social sign-in (optional) | If you choose "Continue with Google" or "Continue with X", we receive from that provider your provider account identifier, your email address and its verification status (Google; X does not supply an email), and your display name or handle, which we store to create or link your account. We never receive your contacts, posts, or provider password. | Authentication and account linking | Until account deletion + 30-day grace | | Waitlist (no account needed) | Email address you submit via a "Notify me" form, a salted hash of your IP address, and the page where you signed up | Confirming your signup and notifying you when a beta spot or general access opens | Until access-notification emails conclude or you opt out — you may opt out at any time by emailing privacy@hunterkiller.io or following the opt-out instructions in any waitlist email | | Exchange API keys | Exchange API keys + secrets (encrypted at rest with per-tenant, HKDF-derived AES-256-GCM keys) | Required for the dashboard to read your balances/positions and, where you instruct it, to relay orders to your own exchange account | Until you delete the key or the account | | Trade journal | Closed positions (symbol, side, entry/exit prices, P&L, your notes/tags/ratings) | Performance review, calendar, equity curve, trade-discipline tooling | Indefinite while account active; purged on account deletion | | Trade-cost analytics | Per-fill execution records derived from your connected account (symbol, side, size, price, maker/taker, fees) used for round-trip cost analysis | Execution-cost / trade-discipline analytics for you | Indefinite while account active; purged on account deletion | | Equity snapshots | Daily account-level USD totals | Equity-curve charts | Indefinite while account active; purged on account deletion | | Settings | Notification preferences (email, optional Telegram chat ID, severity threshold), alert categories | Routing notifications and configuring your experience | Until you change them or delete the account | | Push notifications (optional) | If you enable browser push alerts: the push-subscription endpoint URL and the encryption keys your browser generates for it, plus the browser user agent | Delivering the browser push alerts you enable | Until you disable push notifications, unsubscribe, or delete the account | | Referral / campaign attribution | If you arrive via a referral or affiliate link or a tracked campaign: the referral or affiliate code and campaign (UTM) parameters you carried, recorded at signup | Crediting your referrer under the referral/affiliate program and measuring our own outreach | With your account; aggregate campaign statistics are de-identified | | Session | Login session identifier and expiry; the IP address and user agent at login and at security-relevant events are recorded in the authentication/security event log (next row) | Security (rate-limiting, account-takeover defense, fraud/abuse prevention) | Session records: 30 days after the session ends | | Authentication / security events | Login attempts, rate-limit and lockout events, source IP and user agent | Account-takeover defense, abuse and fraud prevention | 12 months, then deleted or anonymized (events tied to account administration or operator actions may be retained up to 24 months with the operator audit logs) | | Support tickets | Subject, message, optional reply email, page context, IP, user agent | Triaging and responding to your support requests | 90 days after resolution | | Billing (via Stripe) | Name, billing contact, subscription or one-off purchase records, transaction history; card data is collected and stored by Stripe, not by us | Processing payments, managing subscriptions and one-off purchases, tax/accounting | Subscription and purchase records retained for the period required by tax and accounting law (see §10) | | Operator audit logs (platform-internal) | Cross-tenant access records; operational integrity events (e.g., engineer/calibration runs, ticket alerts) | Operational integrity, security, and accountability | 24 months from creation, then deleted or anonymized (see §10) | | Discipline Coach report (free or one-off paid) | A read-only exchange API key and secret you paste to generate a report. Used in memory for read-only history calls to the exchange you select, for a single generation of your report, then discarded. Never written to disk, database, or logs; never used to place, cancel, or fund any order. (Applies to the free and one-off paid report; continuous monitoring stores the key encrypted — see the row below.) | Generating your discipline report | Not retained — the key is dropped from memory the instant your report is built | | Discipline Coach continuous monitor (opt-in, requires an account) | If you enable continuous monitoring, the read-only exchange API key you provide is stored encrypted at rest (per-tenant AES-256-GCM, as in the "Exchange API keys" row) so we can re-read your open positions on a schedule and alert you to discipline-rule breaches. It is used read-only and never to place, cancel, or fund an order. | Powering scheduled discipline alerts | Deactivated immediately when you disable monitoring — the key stops being read from the very next scheduled check and the cached discipline profile derived from it is deleted at the same moment. The encrypted key record itself is permanently erased when your account is purged after deletion, or sooner on request to privacy@hunterkiller.io | | Anonymized benchmark contribution (opt-in only) | Only if you check the optional "contribute" box where offered: aggregate-only derived statistics — e.g., win rate, hold-time asymmetry, a symbol's long/short side, and the sign (not amount) of P&L. Never your identity, your API key, or any individual trade. | Improving the coach's benchmarks and the aggregate retail-positioning view, shown only in k-anonymized form | De-identified aggregates retained; opt-in positioning contributions expire from the published aggregates within 24 hours, and the retained contribution record is itself fully de-identified (a daily-rotating, non-reversible token and a position side only) |

We do not collect:

4 · Legal bases for processing (GDPR Article 6)

For users in the EU/EEA and UK, we rely on the following legal bases under GDPR Article 6(1):

| Processing purpose | Legal basis | |---|---| | Creating and authenticating your account; rendering dashboards; storing your journal; relaying orders you instruct to your connected exchange; routing the notifications you configure | Contract — Art. 6(1)(b): necessary to perform the agreement (the Terms of Service) we have with you | | Processing payments and managing subscriptions via Stripe | Contract — Art. 6(1)(b) | | Securing the Service: rate-limiting and temporary lockouts, abuse/fraud prevention, operator alerting on attack bursts, maintaining authentication and audit logs | Legitimate interests — Art. 6(1)(f): our and our users' interest in a secure, abuse-free platform | | Improving and calibrating our analytics models using k-anonymized aggregates (minimum 3 distinct tenants per bucket; never per-tenant attribution across tenants) | Legitimate interests — Art. 6(1)(f): improving Service quality, balanced against your interests by aggregation and k-anonymization | | Recording referral/affiliate attribution and first-party, pseudonymous measurement of our own sign-up funnel | Legitimate interests — Art. 6(1)(f): operating our referral programs and understanding our own outreach, using pseudonymous identifiers and aggregate reporting | | Delivering browser push notifications you enable | Contract — Art. 6(1)(b): you enable and configure them | | Producing the Discipline Coach's opt-in anonymized benchmark and aggregate retail-positioning figures | Consent — Art. 6(1)(a): contributed only if you check the "contribute" box; declining does not affect your report, and each figure is shown only in k-anonymized form (minimum 5 distinct contributors) | | Sending you optional Telegram alerts; sending non-essential / marketing communications | Consent — Art. 6(1)(a): you opt in, and you may withdraw consent at any time | | Sending waitlist notifications you requested | Consent — Art. 6(1)(a): you submit your email for this purpose and may opt out at any time | | Retaining billing/tax records; responding to lawful subpoenas, court orders, and regulatory requests | Legal obligation — Art. 6(1)(c) |

Where we rely on legitimate interests, you have the right to object (see §9). Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

Withdrawing consent to contribute. You may stop contributing at any time by unchecking the "contribute" box or emailing privacy@hunterkiller.io; this stops all future contributions. Because a contribution is irreversibly de-identified and aggregated at the moment it is recorded (it carries no identifier that could link it back to you), figures already merged into an aggregate cannot be located, isolated, or removed, and withdrawal therefore does not unwind past aggregate contributions. This does not affect the lawfulness of processing carried out before withdrawal (GDPR Art. 7(3)). Opt-in retail-positioning contributions additionally expire from the published aggregates automatically within 24 hours. If you delete your account, we stop any future contribution; existing de-identified aggregates, which are no longer personal data, are retained.

Note: transactional, service-essential emails (e.g., signup verification, password reset, billing receipts, security and account notices) are sent on the contract basis and are not optional while you maintain an account; they are not marketing.

5 · How we use your data

We do not use your data for behavioral advertising, and we do not use your trade journal, equity data, execution-cost analytics, or API-key data for any purpose other than operating the Service for you and producing the k-anonymized aggregates described above. The Discipline Coach's read-only key is used once for your report and never stored; Coach benchmark/positioning aggregates are produced only from opt-in contributions and only in k-anonymized form.

6 · Federated-design isolation (per-tenant by construction)

Every dashboard endpoint that returns customer-contributed data scopes by tenant_id derived from your authenticated session. Cross-tenant data access is prevented by construction:

When Operator personnel access or act on a specific tenant's account or data for support, security, or operational reasons, those actions are recorded in platform audit logs, and direct cross-tenant reads of another tenant's data are recorded in an append-only cross-tenant access log with timestamp, justification, and the operator user ID.

7 · Encryption and storage

8 · Sub-processors and third parties

We share the minimum personal data necessary with the following sub-processors, each engaged under terms that require them to protect your data and process it only on our instructions or for the stated purpose. We do not sell or share your personal information with any party for advertising or for their own marketing.

| Sub-processor | Purpose | Data shared | |---|---|---| | Stripe, Inc. | Payment processing, subscription billing, fraud screening | Name, billing contact, subscription/transaction data; card data is collected and stored by Stripe (we do not store card numbers) | | Resend (Resend, Inc.) | Transactional and account emails (verification, password reset, billing receipts, alerts) | Your email address and message content | | Telegram (optional) | Alert delivery, only if you configure a Telegram chat ID | Your chat ID and the alert content you opted to receive | | Browser push services (optional) — the push service operated by your browser vendor (for example Google FCM, Mozilla autopush, or Apple Push Notification service) | Delivery of browser push notifications you enable | The push-subscription endpoint and the alert payload, routed by your browser under its own push infrastructure | | Cryptocurrency exchanges you connect (including Bybit, Binance, OKX, Bitget, KuCoin, Gate.io, HTX, MEXC, Crypto.com, Coinbase, Kraken, Gemini, Deribit, Hyperliquid, and others we add) | Reading your account or execution data and, where you instruct it, relaying your orders to your own exchange account. For the Discipline Coach, when you paste a read-only key we transmit that key to the exchange you select solely to make read-only history calls on your behalf; the key is used in memory and not stored. | Your read-only API requests (and, for the Coach, your read-only key in transit) routed to that exchange under your own credentials | | Cloudflare, Inc. | Edge network / reverse proxy, TLS termination, DNS, and DDoS / bot protection in front of the Service, including the Cloudflare Turnstile human-verification check on our sign-up and waitlist forms | Network traffic metadata, including your IP address, request headers, and user agent, processed in transit | | Hetzner Online GmbH | Cloud hosting / compute infrastructure | All Service data is hosted on Hetzner infrastructure | | Backblaze, Inc. (Backblaze B2) | Encrypted offsite backups | Encrypted backup archives of Service data | | UptimeRobot (itrinity, s.r.o.) | Independent uptime monitoring of our public endpoints and a hosted public status page | No customer personal data — it probes public URLs and records response status/latency only; if you visit the hosted status page, UptimeRobot processes your visit under its own privacy policy |

The cryptocurrency exchanges you connect are independent controllers of the data you hold with them; their own privacy policies govern your relationship with them, and we are not responsible for their practices. Telegram likewise applies its own privacy policy to your chat, and your browser vendor's push service applies its own policies to push delivery.

Content delivery and embedded third-party content. Some pages load static resources from third-party content-delivery networks — web fonts from Google Fonts on certain public pages and in the dashboard, and a charting library from the unpkg CDN — and certain dashboard features you can choose to open embed third-party content, namely TradingView chart widgets and YouTube video thumbnails/players. When your browser loads these resources it connects directly to those providers, which necessarily receive your IP address and standard request headers, and embedded TradingView or YouTube content may set their own cookies under their own privacy policies. We do not send these providers your account data, they receive no data from us other than what your browser sends when you load the resource, and in the dashboard such content is user-initiated. These providers act as independent controllers of the data they receive via your browser.

Identity providers (optional social sign-in). If you sign in with Google (Google LLC) or X (X Corp.), that provider authenticates you and sends us your provider account identifier, email address and verification status (where supplied), and display name. Each provider is an independent controller of the data it holds about you and your use of it is governed by its own privacy policy; we do not send providers your trading data.

Deidentified and aggregate data; our data services. We operate business-to-business analytics products and a read-only data API that provide aggregated, deidentified market intelligence — for example, calibrated liquidation "magnet" levels, distal reach-rates, cross-asset contagion metrics, and (only from opt-in contributions) k-anonymized retail-positioning/"crowding" views. This data is aggregated and deidentified, contains no identifiers, and cannot reasonably be linked to you or your account. It is therefore not "personal information" under the CCPA/CPRA (Cal. Civ. Code § 1798.140) or comparable laws. Consistent with § 1798.140(m), we: (i) have taken reasonable measures to ensure the data cannot be associated with you; (ii) publicly commit to maintain and use such data only in deidentified, aggregate form; (iii) will not attempt to reidentify it; and (iv) contractually obligate any recipient to the same. Because this data is not personal information and is never disclosed for cross-context behavioral advertising, providing it is not a "sale" or "share" of your personal information. Individual trade data, identity, and API keys are never included in it.

Data processing addendum. Where you use the Service as a business and applicable law requires a data processing agreement covering personal data you process through the Service, we offer a data processing addendum incorporating the processor terms of GDPR Article 28 and the transfer safeguards described in §12. Request one at privacy@hunterkiller.io.

We do not use any third-party advertising, marketing-analytics, user-profiling, or third-party error-monitoring service. We do not share data with:

We may disclose data without your consent only where required by law (e.g., a valid subpoena, court order, or regulatory demand) or to protect the rights, safety, or property of users, the public, or the Operator, and in connection with a merger, acquisition, or sale of assets, in which case we will notify you and any successor will be bound by terms at least as protective as this Policy.

9 · Your privacy rights

We honor data-subject and consumer rights regardless of where you live, to the extent applicable law requires. Subject to verification and legal limits, you may:

9.1 EU/EEA and UK (GDPR) residents

In addition to the above, you have the right to lodge a complaint with your local supervisory authority (in the EU, the data protection authority of your country of residence; in the UK, the Information Commissioner's Office). We ask that you first contact privacy@hunterkiller.io so we can try to resolve your concern directly. You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects; the Service does not make such decisions about you.

9.2 California (CCPA/CPRA) residents

We collect the categories of personal information described in §3 (identifiers such as email and IP address; commercial information such as subscription records; internet/network activity such as session and authentication logs; and the financial/trade-journal information you provide) for the business purposes described in §5.

To exercise any of these rights, contact privacy@hunterkiller.io or use the in-product tools. We will verify your request against your account credentials. You may use an authorized agent, who must provide proof of authorization. We will respond within the timeframes required by applicable law.

9.3 Other U.S. states and jurisdictions

Residents of other U.S. states with comprehensive privacy laws, and of other jurisdictions with applicable data-protection laws — including Canada (PIPEDA), Brazil (LGPD), Switzerland (revised FADP), South Africa (POPIA), Singapore (PDPA), Japan (APPI), South Korea (PIPA), Hong Kong (PDPO), India (DPDP Act), and mainland China (PIPL) — may have comparable rights (such as access, correction, deletion, portability, and objection or withdrawal of consent) under their local laws. We will honor verified requests to the extent applicable law requires; contact privacy@hunterkiller.io. Where local law requires a local representative or registration we have not yet appointed or completed, you may always reach us directly at privacy@hunterkiller.io and we will respond as required.

10 · Data retention

| Data | Retention | |---|---| | Active account data (journal, equity snapshots, execution-cost analytics, settings, keys) | Until you delete | | Soft-deleted account data | 30 days, then permanently purged | | Session logs | 30 days after the session ends | | Authentication / security event logs | 12 months, then deleted or anonymized | | Support tickets | 90 days after resolution | | Push subscription records | Until you disable push notifications, unsubscribe, or delete the account | | Billing / tax records | Retained for the period required by applicable U.S. tax, accounting, and corporate-records law (generally at least 7 years), and thereafter only for as long as needed to resolve disputes, defend against chargebacks, or meet legal obligations, then deleted or anonymized | | Aggregate (k-anonymized) platform analytics | Indefinite — not personal data (no individual is identifiable) | | Operator audit / cross-tenant access logs | 24 months from creation, then deleted or anonymized | | Offsite backups (Backblaze B2, server-side encryption at rest) | Rotated on a 90-day cycle; deleted or expired data ages out of backups within 90 days |

When a retention period ends, we delete or irreversibly anonymize the data. We may retain limited information beyond these periods only where necessary to comply with a legal obligation, resolve disputes, or enforce our agreements, and only for as long as that need exists.

11 · Cookies and similar technologies

The Service itself sets only essential cookies required to operate it. Specifically:

Local storage. Your browser's local storage holds: your interface preferences (e.g., active tab, layout choices); if you arrive via a referral or affiliate link or a tracked campaign, the referral or affiliate code (hk_ref, hk_aff_ref) and campaign parameters (hk_utm), kept so we can credit your referrer and understand which outreach brought you to us; a random, pseudonymous visitor token (hk.vid) used for first-party measurement of our own sign-up funnel; and, when we run a first-party page experiment, your experiment assignment (hk.ab.*). These items are first-party only, are not shared with any advertising network, and are not used to track you across other websites.

First-party measurement. We measure our own sign-up and pricing funnel (for example, page views, sign-up steps, and conversions) using the pseudonymous visitor token described above plus anonymous event beacons, and we review the results in aggregate. We do not use third-party analytics platforms, advertising cookies, third-party tracking pixels, cross-site trackers, or any third-party error-monitoring service, and we do not build advertising profiles of individual users. Because our cookies are strictly necessary and our local-storage items are first-party, non-tracking functional storage, no consent banner is currently required for non-essential tracking; if we ever add non-essential tracking technologies, we will provide the appropriate consent controls first.

Embedded third-party content. Certain features load third-party content directly into your browser — web fonts (Google Fonts) on some pages, a charting library from a public CDN, and, in the dashboard, TradingView chart widgets and YouTube video thumbnails/players you choose to open. Your browser connects to those providers directly, and they may set their own cookies under their own privacy policies (see §8). We do not control and are not responsible for those providers' practices.

12 · International data transfers

The Operator is based in the United States. The Service's primary hosting infrastructure is operated by Hetzner Online GmbH in its Singapore data-center region, and network traffic is routed through Cloudflare, Inc.'s global edge network. As a result, your personal data is processed in the United States, Singapore, and other jurisdictions in which our sub-processors operate, and will be transferred across borders.

Where we transfer personal data of EU/EEA or UK residents to a country that has not received an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (SCCs) (and the UK International Data Transfer Addendum where applicable), together with supplementary technical and organizational measures (including the encryption described in §7). You may request a copy of the relevant safeguards by emailing privacy@hunterkiller.io.

When you use the Discipline Coach or connect an exchange, your read-only API requests — and, for the Coach, the read-only key you paste — are transmitted to the exchange you select, which may be located outside your country (including outside the EU/EEA, UK, and the United States). That exchange is an independent controller of the data it holds about you and processes your request under its own terms; we act only as a conduit for the read-only call you request.

13 · Security

We apply industry-standard safeguards, including:

No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. You are responsible for safeguarding your account credentials and for using API keys with the minimum permissions you need.

14 · Breach notification

If we become aware of a personal-data breach that is likely to affect you, we will notify affected users without undue delay. For EU/EEA and UK residents, we will notify the competent supervisory authority within 72 hours of becoming aware where the breach is likely to result in a risk to your rights and freedoms, consistent with GDPR Articles 33–34, and we will notify affected users where the breach is likely to result in a high risk to them. For U.S. residents, we will provide notice without undue delay and as required by applicable state breach-notification laws.

15 · Children's privacy

The Service is intended for adults and is not directed to anyone under 18. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us personal data, contact privacy@hunterkiller.io and we will delete it.

16 · Changes to this Policy

We may update this Policy from time to time. Material changes will be announced via:

Your continued use of the Service after a change takes effect constitutes acceptance of the updated Policy.

17 · Contact


Last updated: August 7, 2026 — deep worldwide compliance assessment + red-team revision (Version 1.2; engineering compliance review, post-dates the 2026-07-25 counsel review): §3 corrected (removed the unused customer 2FA-secret data category; session row now reflects that login IP/user-agent live in the authentication/security log; added push-notification and referral/campaign-attribution rows; positioning contributions described as expiring from published aggregates within 24 hours); §4 legal bases aligned (rate-limiting/lockout wording; added push-delivery and referral/funnel-measurement bases); §5 crowding bullet qualified to where the opt-in is offered; §6 operator-access logging aligned to the actual audit/cross-tenant logging implementation; §7 corrected (customer-facing 2FA is not yet offered — operator 2FA configuration held under restricted file permissions; backups described accurately as TLS in transit + Backblaze B2 server-side encryption at rest); §8 added browser push services and an embedded third-party content disclosure (Google Fonts, unpkg CDN, TradingView, YouTube); §9 access right corrected to the actual self-serve exports plus full-copy-by-email; §9.3 expanded to Swiss FADP, POPIA, PDPA, APPI, PIPA, PDPO, DPDP, and PIPL; §10 added push-subscription row and corrected the billing-retention and backup rows; §11 cookie/local-storage inventory completed (hk_sw_main, hk_aff_ref, hk_utm, hk.vid, hk.ab.) and first-party funnel measurement disclosed; §13 2FA claim corrected. Prior (July 25, 2026): licensed-counsel review completed per owner sign-off; status lines updated (Version 1.1). Prior (July 11, 2026): status reconciled from DRAFT to PUBLISHED (reviewed by an AI legal-review panel; independent licensed-counsel review recommended for jurisdiction-specific sections), Version 1.0.*

July 4, 2026 — panel revision: §3 discloses signup IP/user-agent retention, optional Google/X social sign-in data, and waitlist collection; §3 Discipline Coach continuous-monitor retention corrected to deactivate-immediately/erase-on-purge; §4 waitlist legal basis added; §8 adds Turnstile detail, UptimeRobot, identity-provider disclosure, and the data processing addendum offer; §9 deletion right describes the purge schedule and backup age-out; §9.2 adds Global Privacy Control statement; §10 adds backup-rotation row; §11 cookie inventory corrected to the actual cookies (hk_auth, hk_2fa, OAuth round-trip, Cloudflare, hk_ref).

Operated by Irishman Management LLC · 1931 Cordova Rd., Fort Lauderdale, FL 33316