← Home

Pit Privacy Policy

Effective date: July 27, 2026 · Last updated: July 31, 2026

Pit ("Pit," "we," "us") is operated by The Pit App LLC. This Privacy Policy describes how we collect, use, and share information when you use the Pit mobile app (the "App").

1. What this version of the App does

This version of Pit is a social and market-data app. You can create an account, follow other users, post and read content, send direct messages, browse live cryptocurrency market data, and keep a watchlist.

Buying, selling, position management, deposits, and withdrawals are not offered in this version of the App. We describe below what we still collect, because several things happen that are not obvious from what you can see on screen — most importantly, an embedded cryptocurrency wallet is created for your account, and we read public blockchain data associated with it.

2. Information we collect

2.1 Account and identity information

When you create an account we use Privy, our authentication and embedded-wallet provider, to sign you in by email one-time code, or through Apple, Google, or Discord. We receive from Privy an opaque account identifier and your email address, which we store against your account. We do not collect your government ID and we do not perform identity verification.

2.2 Wallet addresses

When you sign in, Privy creates an embedded cryptocurrency wallet on two networks (an Ethereum Virtual Machine wallet and a Solana wallet) and associates them with your account. This happens even though this version of the App does not offer trading, and even though the App does not display your wallet address to you.

The private key material for those wallets is held by Privy's infrastructure, not by us — we never have access to your private keys. We do store your public wallet addresses, and you should understand two consequences:

2.3 Public blockchain and market information

We read public blockchain data associated with your wallet address from the Hyperliquid network, directly from your device, throughout your session. This includes any positions, balances, trade history, funding, and order history that address holds. This data is public and on-chain by nature of the protocol; we read it, we do not create it.

We read this data in this version of the App even though the portfolio screens are not available, for two purposes: so that the portfolio and performance features work immediately if and when they are enabled for your account, and so that trade calls posted from an address can later be evaluated against public records (see section 7). This data is read by your device from a public source; we do not store a copy of your on-chain history beyond what is needed for those purposes, and we do not use it for advertising or profiling. If you would rather this did not happen, do not sign in to the App — the wallet and the reads are created by signing in.

2.4 User-generated content

Posts, replies, quotes, trade calls, profile information (display name, handle, bio, avatar), likes, reposts, bookmarks, follows, blocks, reports, and direct messages are stored and may be visible to other users or the public, depending on the content type and your settings. Images you attach are uploaded to our object storage.

Trade calls in this version of the App are self-reported. When you post one, you type the market, direction, entry price, leverage, and profit or loss figures yourself. We do not verify those figures against blockchain records before publishing them. See "Trade calls are user statements, not verified records" below.

2.5 Device and diagnostic information

We use Sentry to collect crash reports, error reports, and performance diagnostics (app crashes, screen load times, request latency, app sessions). These are associated with your account through an opaque identifier.

We apply automated filters that attempt to remove sensitive values before events leave your device, but these are best-effort: crash reports captured by the underlying platform SDK can include the full addresses of API requests your device made, and navigation records can include a username or a token address that appears in an in-app link. We do not intentionally transmit your email address, private keys, or balances to this service.

We also use Firebase for push notification delivery, remote configuration, and crash reporting as a fallback. Firebase generates an installation identifier for your device the first time the App launches, before you sign in.

2.6 Product analytics

Product-usage analytics is switched off in the App as currently shipped. The capability exists and can be enabled by us remotely, without a new App release. If it is enabled, events describe which screens and market types you interacted with; they do not carry amounts, your email address, or your wallet address. On iOS you will see the system App Tracking Transparency prompt before any analytics identifier is used.

2.7 Approximate location

We use your device's IP address to determine your approximate country, to establish whether certain features are available in your region under applicable regulation. This check runs when the App starts, including before you sign in. We do not collect GPS or precise location, and the App never requests location permission.

2.8 Photos

If you set a profile picture or attach an image to a post or message, the App accesses your photo library with your permission. If you save an image you received, the App writes it to your photo library with your permission. We do not otherwise read your photo library.

2.9 Push notifications

The App requests notification permission when it first launches, before you sign in. If you allow it, we collect a device push token to deliver notifications about your account activity.

3. How we use your information

To operate and secure your account; to display market data; to power social features (feed, profiles, search, leaderboards, direct messages); to send notifications; to detect and prevent fraud, abuse, and market manipulation; to comply with legal obligations; and to diagnose and fix technical problems.

We do not use your information for third-party cross-app or cross-website advertising tracking, and we do not sell your personal information.

4. Third parties

RecipientWhat it handlesNotes
Privy Authentication, embedded-wallet key management Governed by Privy's privacy policy
Hyperliquid (api.hyperliquid.xyz) Public market data, and public on-chain data for your wallet address Receives your wallet address and your IP address. Public protocol data — see "Public blockchain and market information"
Cloudflare (geolocation worker) IP address → country and availability verdict Runs at App start, before sign-in — see "Approximate location"
Sentry Crash, error, performance, and session diagnostics See "Device and diagnostic information." Best-effort filtering, not guaranteed removal
Firebase (Google) Push delivery, remote configuration, crash reporting fallback, installation identifier Advertising-identifier collection is explicitly disabled
Cloud object storage Stores images you upload (avatars, post and message attachments) Held under contract, on our instructions only. Deleted when you delete the post or your account — see "Data retention and deletion"
Market data proxy Trending-token market data Receives your wallet addresses only if multi-chain features are enabled for your account; not enabled by default
Transactional email provider Transactional email — currently only the account-deletion completion notice Receives only your email address, solely to send that notice. No marketing email is sent

Not used in this version: we do not integrate a fiat payment or card processor in this build, and no payment or identity-verification data is collected by the App or shared with any payment provider. This version also makes no requests to Arbitrum blockchain infrastructure, because the only feature that did so — automatic detection of incoming transfers — is disabled.

5. Data retention and deletion

You can permanently delete your account from Settings → Legal & Privacy → Delete Account. You can also request deletion without the App at https://thepitapp.xyz/account-deletion. When you delete your account:

  1. Your account is deactivated immediately — hidden from feeds, search, and suggestions — and your push notification token is purged.
  2. Deletion becomes permanent after a 7-day grace period; the exact date is shown to you when you request it. During the grace period you can cancel by signing back in and choosing Restore account.
  3. After the grace period we permanently delete your likes, reposts, bookmarks, follows, notifications, points and badge history, leaderboard and season history, and your stance records. The text and media of your posts are erased and any remaining record is disassociated from you (shown as "Deleted account"). Trade calls you posted are retained in that same anonymized form, because other users may have acted on them. Direct messages you sent remain visible to their recipients — as in most messaging services — with your identity removed. Blocks other users placed on you are retained so that deleting and re-creating an account cannot be used to evade a block. A minimal record of the deletion itself (a hashed identifier and a timestamp) is retained as a compliance record.
  4. We stop associating your wallet address with your account, and we send a confirmation email if we have an address on file.

Important limitation: blockchain data tied to your wallet address is public, on-chain, and not controlled by Pit. Deleting your Pit account removes the link between your identity and that address within our systems; it does not and cannot remove the underlying public blockchain record, and it does not delete the wallet itself.

5.1 How long we keep things

We keep personal information only for as long as we need it for the purposes described in this policy, and then delete or anonymize it:

6. Your choices and rights

To exercise any right described below, email support@thepitapp.xyz from the address on your account, or use the in-App deletion flow. We respond within the time required by applicable law (one month under the GDPR, extendable by two further months for complex requests; 45 days under US state privacy laws, extendable once by a further 45 days). We do not charge for these requests and we will not discriminate against you — degrade the service, change pricing, or restrict features — for making one. We may need to verify that the request comes from you, which we do by confirming control of the account email; if we cannot verify you, we will tell you why rather than release data to the wrong person.

6.1 If you are in the EEA, the UK, or Switzerland

We process your personal data on these legal bases: performance of a contract (operating your account and the social features you ask for), legitimate interests (security, fraud and abuse prevention, detecting market manipulation, diagnostics and keeping the App working), consent (photo library access, push notifications, and product analytics if we ever enable it — you may withdraw consent at any time in your device settings, without affecting processing already carried out), and legal obligation where a law requires us to retain or disclose something.

You have the right to:

Our controller for this processing is The Pit App LLC, at the address in section 12.

6.2 If you are in California or another US state with a privacy law

Depending on your state (for example California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, or Montana) you have the right to know what personal information we collect and why, to access and obtain a copy of it, to correct it, to delete it, and to appeal a decision we make about your request. To appeal, reply to our response or email support@thepitapp.xyz with "Privacy appeal" in the subject line; if we deny the appeal you may complain to your state Attorney General.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising — under the CCPA/CPRA and equivalent state laws, as those terms are defined there. We therefore do not offer a "Do Not Sell or Share My Personal Information" mechanism, because there is nothing to opt out of. We do not use or disclose sensitive personal information for purposes beyond those permitted without a right to limit. We do not knowingly sell or share the personal information of anyone under 16.

The categories we collect, our purposes, the categories of third party we disclose to for business purposes, and our retention periods are set out in sections 2, 3, 4, and 5 of this policy respectively. You may use an authorized agent to submit a request on your behalf if the agent provides written proof of authorization.

6.3 Everyone else

Wherever you live, you can ask us for a copy of your data, ask us to correct it, or delete your account, using the same contact route. We apply these rights as a matter of policy, not only where a law compels them.

7. Trade calls are user statements, not verified records

Trade calls posted in this version of the App are typed in by the person who posted them. We do not check them against blockchain records before publishing, and we do not represent them as accurate. Treat any performance figure you see in the App as a claim made by another user.

Separately, you should know that posting a trade call causes us to begin monitoring the public blockchain activity of the wallet address associated with your account, so that the claim can be evaluated against public records later. If you do not want that, do not post trade calls.

Nothing in the App is financial, investment, or trading advice.

8. Children's privacy

The App is not directed to, and is not intended for use by, anyone under 18. Our Terms of Service require you to be at least 18 to hold an account. We do not knowingly collect personal information from anyone under 18, and we do not collect personal information from children as defined by COPPA.

We do not operate an in-App age-verification step; account creation relies on your confirmation that you meet the age requirement, and on the age rating applied by the app stores. If you believe someone under 18 has created an account, or that a child's information has reached us, email support@thepitapp.xyz — if we learn that an account holder is under 18 we will terminate the account and delete the associated personal information.

9. International data transfers

Pit is operated from the United States. If you use the App from outside the United States, your information is transferred to, stored in, and processed in the United States and in other countries where our service providers listed in section 4 operate. Data-protection law in those countries may differ from the law where you live.

Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and, for the UK, the ICO's International Data Transfer Addendum) in our contracts with those providers, together with the technical and organizational measures described in this policy — transport encryption in transit, access control, and filtering of sensitive values before diagnostics leave your device. Where a provider is covered by an adequacy decision or a certification such as the EU-US Data Privacy Framework, we rely on that instead.

You can request further information about the safeguards we use for a specific transfer by emailing support@thepitapp.xyz.

10. How we protect your information

We use encryption in transit for all network requests, access controls limiting who on our side can reach production data, and automated filtering that attempts to strip sensitive values from diagnostic events before they are sent. Private key material for your embedded wallet is held by Privy, not by us. No system is perfectly secure, and we cannot guarantee absolute security; if a breach affects your personal information we will notify you and the relevant authorities where the law requires it.

11. Changes to this policy

We may update this policy from time to time. When we do, we change the "Last updated" date at the top. If a change materially affects how we use information we already hold about you, we will notify you in the App or by email to the address on file before it takes effect, and where the law requires your consent we will ask for it rather than assume it. Continuing to use the App after a change takes effect means you accept the updated policy.

12. Contact us

The Pit App LLC
16192 Coastal Hwy, Lewes, Delaware 19958
Email: support@thepitapp.xyz
Web: thepitapp.xyz

In this version of the App the in-app Help & Support entry point is not shown, so this address is the primary way to reach us.