On this page

Privacy

Last updated: 6 October 2026

The short version: this site sets no cookies, runs no analytics and loads nothing from third parties. The addresses and rules you enter stay in your browser. Nothing you type into the backtest, the watch step or the rules is ever sent to us.

Who is responsible

orcastrate UG (haftungsbeschränkt), Plinganserstr. 55, 81369 München, Germany. Email: legal@zunderlabs.com. See the Impressum for the full legal details.

Hosting

The site is a set of static files served by Cloudflare Pages. To deliver them and to protect the service, Cloudflare processes technical connection data such as your IP address, the time of the request, the page requested and your browser’s user agent. The legal basis is our legitimate interest in delivering a secure website (Art. 6 (1) (f) GDPR).

Cloudflare, Inc. (USA) acts as our processor under its data processing agreement, which includes the EU standard contractual clauses. Cloudflare may process data in the USA; it is certified under the EU–US Data Privacy Framework, for which the European Commission adopted an adequacy decision on 10 July 2023 (Art. 45 GDPR). Cloudflare’s privacy policy: https://www.cloudflare.com/privacypolicy/

Cookies and tracking

This site sets no cookies and uses no analytics, advertising or tracking services. The fonts are served from this site, not from a third party.

What stays in your browser

The site keeps a few settings in your browser’s storage. None of it is sent to us. Once you enter your own Hyperliquid address (on /connect, in the deploy wizard or on /approve), it is remembered on this device by default; untick “remember this address on this device” to remove it. The “stored only in this browser · clear” control deletes all of it and stops remembering for the rest of the browser session; clearing this site’s data in your browser does too.

KeyWhereWhatWhen
zunder.v1local storageyour rules, the install platform you picked, and your own addresswhen you change a rule or pick a platform; the address when you enter it, unless you untick “remember on this device”
zunder.addresslocal storageyour Hyperliquid address, for the docs’ personalised exampleswhen you enter it, unless you untick “remember on this device”
zunder.wizard.v1local storagethe deploy wizard’s choices (target, mode, rules); your addresses and your server’s host, user and port unless you untick “remember”when you use the wizard
zunder.networklocal storagethe mode you picked in the deploy wizard (paper or testnet)when you use the wizard
starlight-themelocal storagethe docs’ light or dark themewhen you pick one
zunder.account.v1session storagethe address you entered, so the steps of /connect and the wizard use the same one; gone when you close the tabwhen you enter your own address (never a sample vault)
zunder.remember.offsession storagethat you unticked “remember” or pressed “clear”, so nothing is saved again; gone when you close the tabwhen you untick “remember” or press “clear”
zunder.fontssession storagethat the fonts are already loaded, so pages do not flash; gone when you close the tabon /connect

The docs also read zunder.rules, zunder.platform and zunder.guardUrl if an older version of the site stored them; nothing writes them any more.

  • Addresses. Your own Hyperliquid address, entered on the backtest or watch step, in the deploy wizard, or connected on /approve, stays in this tab’s session storage until you close the tab and is shared between the steps so you do not type it twice. By default it is also saved in local storage, so the site remembers it on this device. Untick “remember this address on this device” to remove it, or press “clear” to delete everything the site stored. A sample vault is never stored, and an address never goes into a link.
  • Share links. “Copy share link” for your rules puts them into the part of the link after #. Browsers do not send that part to the server. A shared backtest result (/share?d=…) carries only the numbers of the result, never an address.
  • Notifications. If you turn on “notify me when a rule breaks” in the watch step, your browser asks for permission and shows the notifications itself. Nothing passes through us.

Hyperliquid

The market view, the backtest and the watch step connect your browser directly to Hyperliquid’s public API (api.hyperliquid.xyz): to read public trades and the public accounts of the traders behind them, and, if you enter one, the public history of an address. Hyperliquid then receives your IP address and the requests your browser makes, under its own terms. We do not see them. Traders shown in the market view are anonymised in your browser (a short code from a hash with a random value that changes every visit); their addresses are never shown.

The fee approval page (/approve)

If you use /approve to approve Guard’s builder fee, or to withdraw that approval, your browser wallet shows you the message (Hyperliquid’s ApproveBuilderFee: the builder address, at most 0.02%, or 0% to withdraw, the network) and signs it. Your browser then sends the signed message, and your wallet’s address in Hyperliquid’s queries, directly to Hyperliquid (api.hyperliquid.xyz, or api.hyperliquid-testnet.xyz for testnet). Nothing passes through us, and we store nothing on our side; your browser remembers the connected address as described above, unless you untick “remember”. The approval is recorded on Hyperliquid’s public ledger, where anyone, including us, can see it.

Waitlist

If you join the waitlist, the form sends your email address to our waitlist service: a Cloudflare Worker run by us, with its data in Cloudflare D1, restricted to Cloudflare’s EU jurisdiction (stored and processed in the EU).

  • What we store: your email address, the page the form was on, the version of the consent wording, the times you signed up and confirmed, how many confirmation emails we sent, and a hash of your confirmation token. Nothing else: no IP address, no name, no tracking pixel.
  • Double opt-in: we email you a confirmation link from waitlist@zunderlabs.com, sent with Cloudflare Email Service. Only a confirmed address is on the list.
  • Unconfirmed requests are deleted 7 days after our last confirmation email to you. If no email could be sent, they are deleted 60 days after your request. Deleted entries can remain in the database’s point-in-time recovery (Cloudflare D1 Time Travel) for up to 30 days before they are gone for good.
  • Leaving: every email has a link that deletes your entry.
  • Notification to us: when someone signs up or confirms, we receive an internal email through Cloudflare Email Routing saying so and from which page, without your email address.
  • Abuse protection: to stop automated sign-ups, the number of requests per IP address is limited. Cloudflare counts them for a short time; we do not store the IP address.
  • Service logs: the service keeps Cloudflare Workers logs, which record each request’s metadata (such as the time, the address requested, the response and your IP address) for up to 7 days, to find faults and abuse.
  • Legal basis: your consent for the list (Art. 6 (1) (a) GDPR), which you can withdraw at any time; abuse protection and logs: our legitimate interest in a secure service (Art. 6 (1) (f) GDPR).

Contact form

The contact form sends your message, the topic you pick, your email address and, if you give it, your name to the same service. It forwards them to us by email through Cloudflare Email Routing, and we answer from hello@zunderlabs.com. The service’s request logs (above) apply here too. We use your message only to answer you and delete it when the conversation is over, unless the law requires us to keep it. The legal basis is our legitimate interest in answering your enquiry (Art. 6 (1) (f) GDPR), or steps before a contract you ask for (Art. 6 (1) (b) GDPR). The tick box on the form confirms you want an answer; it is not a consent that the processing depends on.

Licence orders

If you buy a licence at /licence (businesses only), the page sends your order to the same service (the Cloudflare Worker above, data in Cloudflare D1 in the EU).

  • What we store: the plan and term, the Hyperliquid accounts the licence is for, your company name, address and country, your VAT ID and the result of its check, your email address, the price, VAT and USDC amount, the exchange rate used, the Terms version you accepted, and a hash of your order token. When you pay: the payment’s amount, time, transaction reference and the sending address. When we deliver: a hash of the licence key (not the key). No IP address.
  • Checks with others: an EU VAT ID is checked with the European Commission’s VIES service, which receives the VAT ID (and ours as the requester). The USDC price comes from Kraken’s public price feed, and payments are found on Hyperliquid, Arbitrum and Base through their public interfaces; none of these receives your name, address or email. For a payment on Arbitrum or Base we check the sending address against USDC’s public blocklist.
  • Emails: the order details and the licence key are sent to your email address with Cloudflare Email Service. When an order is paid we receive an internal email with the order’s details (company, address, VAT ID and its check, accounts, payment) through Cloudflare Email Routing to our own mailbox, whose provider processes it on our behalf.
  • How long: a paid order is kept as a business record for as long as German commercial and tax law requires (currently up to ten years). An order that is never paid is deleted 30 days after its quote ran out. A payment that matched no order is deleted after 400 days. Deleted entries can remain in D1’s point-in-time recovery for up to 30 days.
  • Abuse protection: the requests per IP address are limited (Cloudflare counts them for a short time), and so are the orders per visitor and day (we keep a salted hash of the IP address for that day, never the address itself, and delete it after a week) and the open orders per email address.
  • Legal basis: the contract you ask for and its performance (Art. 6 (1) (b) GDPR); keeping business records: our legal obligation (Art. 6 (1) (c) GDPR, §§ 147 AO, 257 HGB); the VIES check and abuse protection: our legitimate interest in selling correctly and safely (Art. 6 (1) (f) GDPR).

Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR), and the right to withdraw consent at any time. You can also lodge a complaint with a data protection supervisory authority, for example the one in your state of residence or the one responsible for us: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany.