TERMS OF SERVICE — HypaValley

Last Updated: 07/18/2026 · Version 2026-07-18

LIVE TRADING RISK WARNING: LIVE TRADING IS AT YOUR OWN RISK. YOU ARE SOLELY RESPONSIBLE FOR YOUR STRATEGIES, SETTINGS, AND ORDERS. HYPAVALLEY DOES NOT ACCEPT ANY LIABILITY FOR LOSSES, DAMAGES, OR CLAIMS ARISING FROM APP ERRORS, SOFTWARE BUGS, SYSTEM OUTAGES, DATA ISSUES, OR MISCONFIGURATION.

Welcome to HypaValley (“HypaValley,” “we,” “our,” or “us”). These Terms of Service (“Terms”) govern your access to and use of the HypaValley website, applications, APIs, tools, and related services (collectively, the “Service”). You must affirmatively accept the current version of these Terms before using account features. If you do not agree, do not use the Service.

Definitions

  • Content includes text, software, code, features, designs, graphics, interfaces, and documentation provided by HypaValley.
  • User Content includes strategies, blocks, configurations, JSON specifications, scripts, code, prompts, notes, labels, uploads, and any other materials you submit or generate through the Service.
  • Broker means a third-party brokerage or trading venue you connect (e.g., Alpaca Markets).
  • Live Trading means submitting orders intended for execution in a real-money brokerage account.

Overview of the Service

HypaValley provides tools that may allow users to:

  • Build algorithmic trading strategies using a visual builder and/or other interfaces
  • Generate and store normalized strategy specifications (including JSON or similar representations)
  • Generate code (including Python or other languages) from strategy specifications
  • Run simulations, backtests, and paper-trading scenarios
  • Connect a brokerage account via an authorization flow (e.g., OAuth) to enable Live Trading
  • View portfolios, positions, orders, executions, logs, charts, alerts, and other analytics derived from user inputs and/or Broker-provided data

HypaValley is not a broker-dealer, investment adviser, commodity trading advisor, financial institution, exchange, or escrow service. HypaValley does not execute trades itself; Live Trading occurs through your connected Broker, subject to that Broker’s terms, policies, and approvals.

Eligibility; Children

  • Minimum Age. You must be at least 18 years old and the age of majority in your jurisdiction to create an account or use the Service.
  • Broker Eligibility. Live Trading also requires that you meet your Broker’s eligibility, identity-verification, and account-approval requirements.
  • No Use by Minors. If you are under 18 or otherwise below the age of majority where you live, do not use the Service or provide personal information.

Account Registration and Security

  • Account Accuracy. You agree to provide accurate information and keep it up to date.
  • Credentials. You are responsible for maintaining the confidentiality of your login credentials and for all activity under your account.
  • Electronic Communications. By using the Service, you consent to receive electronic communications from us (e.g., transactional emails, security notices, confirmations). Marketing emails (if offered) will include opt-out mechanisms.

No Financial Advice; No Fiduciary Duty

The Service is provided for technical, educational, and informational purposes only. HypaValley does not provide financial, investment, legal, tax, or accounting advice, and nothing on the Service is a recommendation, endorsement, or solicitation to buy or sell any security or financial product. You are solely responsible for determining whether any strategy, trade, or transaction is appropriate for you.

Trading Risks; No Performance Guarantees

Trading involves substantial risk, including the potential loss of all invested funds. Algorithmic trading can amplify losses. You acknowledge and agree that:

  • Backtests, simulations, and paper trading results are hypothetical and may not reflect actual market conditions.
  • Live execution outcomes may differ due to latency, slippage, spreads, partial fills, market impact, order type behavior, trading halts, short sale restrictions, liquidity constraints, outages, or Broker-specific rules.
  • The Service may experience delays, errors, data gaps, downtime, or other technical issues.
  • HypaValley does not guarantee performance, profitability, fill quality, best execution, availability, or accuracy.
  • You assume all risk for Live Trading, including losses arising from misconfiguration, unintended orders, software bugs, data issues, or Service errors.

Live Trading is at your own risk. You are solely responsible for reviewing, testing, and monitoring your strategies, settings, and orders. HypaValley is not responsible for trading losses, unintended orders, or damages caused by app errors or outages.

NO GUARANTEES; NO RESPONSIBILITY FOR ERRORS. YOU ACKNOWLEDGE THAT SYSTEM ERRORS, SOFTWARE BUGS, UNEXPECTED BEHAVIOR, OR THIRD-PARTY SERVICE ISSUES MAY OCCUR AND MAY RESULT IN LOSSES. YOU ACCEPT ALL SUCH RISKS AND RELEASE HYPAVALLEY FROM LIABILITY FOR ANY RESULTING DAMAGES.

Broker Connectivity and Third-Party Services

  • Authorization. If you connect a Broker account, you authorize the Service to access permitted account data and submit order instructions only within the scope you approve through the Broker’s authorization mechanism (e.g., OAuth).
  • Broker Terms Govern. Your Broker’s terms, disclosures, and policies apply to your brokerage account and all trading activity. HypaValley is not responsible for Broker decisions, compliance determinations, account approvals/closures, margin calls, fees, routing, execution, settlement, or Broker outages.
  • No Broker Affiliation. References to third parties do not imply partnership or endorsement unless explicitly stated.

Delegated authorization. HypaValley uses broker-provided delegated authorization (e.g., OAuth) where supported. We do not accept or store broker API keys/secrets or broker passwords. Available authorization methods may change over time and may vary by broker.

Strategy Generation, Code Generation, and Automation Acknowledgements

  • User Control. You are responsible for reviewing your strategies, parameters, code, and settings (including symbols, quantities, order types, time-in-force, risk limits, schedules, and safeguards) before enabling paper trading or Live Trading.
  • Generated Output May Be Incorrect. Any generated code, strategy specification, analytics, or explanations may contain errors or omissions and may not be suitable for Live Trading without independent validation.
  • No Duty to Monitor. HypaValley does not monitor your strategies for suitability, compliance, or correctness and has no obligation to warn you of potential losses or errors.
  • Use at Your Own Risk. You assume all responsibility and liability for the strategies you deploy and the trades they place.

Educational Templates and Community Content

  • Templates Are Examples. Named, starter, prompt-generated, and community strategies are educational, configurable examples—not personalized recommendations, investment advice, or claims that a strategy is suitable or profitable.
  • Review and Configure. Symbols, indicators, thresholds, order sizes, schedules, and risk controls in a template may not fit your objectives or market conditions. You must independently review and change every parameter as needed.
  • Test Before Live Use. Run simulations and paper tests, review logs and orders, and monitor behavior before considering Live Trading. Testing does not guarantee live results.
  • Community Posts. Community content reflects its authors’ views and is not verified or endorsed by HypaValley. HypaValley does not provide copy trading, mirror trading, shared trade signals, or automatic import or execution of community content. Users independently create, configure, and direct any strategy they choose to run.

User Responsibilities and Acceptable Use

You agree to use the Service lawfully and not to:

  • Interfere with or disrupt the Service (including by attempting to overload, probe, scan, or test vulnerabilities).
  • Reverse engineer, decompile, or attempt to access non-public APIs, source code, or systems (except to the extent such restriction is prohibited by law).
  • Circumvent rate limits, access controls, paywalls, or security features.
  • Use the Service to violate Broker rules, market data licensing terms, or applicable laws (including securities laws).
  • Upload malicious code, malware, or harmful content.
  • Infringe intellectual property rights or misappropriate trade secrets.
  • Resell access to the Service or provide it to third parties as a service bureau without our written permission.

We may investigate and take action in our discretion, including suspension/termination, if we believe you violated these Terms.

Market Data and Third-Party Data

Market data displayed in the Service may be provided by your Broker and/or third-party providers. Data may be delayed, incomplete, or inaccurate. You may not redistribute, resell, or otherwise use market data except as permitted by your Broker/provider agreements.

Fees, Free Trials, Billing, Auto-Renewal, and Refunds

  • Paid Plans; Stripe Payments. Certain features require payment (including subscriptions and premium tiers such as “Pro” and “Founders Club”). Pro and Founders Club may be offered on monthly and yearly terms as disclosed at checkout. Payments are processed by Stripe (our payment processor). By purchasing a paid plan, you authorize us (and Stripe) to charge your selected payment method for applicable fees, taxes, and other charges described at checkout. HypaValley does not store full payment card numbers; Stripe may store and process your payment information pursuant to its terms and privacy policy.
  • Free Trial Requires Payment Method. If you enroll in a free trial, you must provide a valid payment method. Unless you cancel before the trial ends, your trial will automatically convert to a paid subscription at the end of the trial period and your payment method will be charged the applicable subscription fee plus any taxes. If you cancel during the trial, you will not be charged and access ends at the trial end.
  • Auto-Renewal; User Controls. Subscriptions may renew automatically at the end of each billing period if auto-renew is enabled. You can enable/disable auto-renew in your account settings (if available) or otherwise through the cancellation controls we provide. If auto-renew is enabled, you authorize recurring charges each billing period until you cancel or disable auto-renew. If auto-renew is disabled, your subscription will remain active until the end of the current paid period and will not renew.
  • Cancellation Effective Date; Access Through Period End. If you cancel a subscription or disable auto-renew, your cancellation will take effect at the end of your then-current billing period (or subscription month, as applicable). You will generally retain access to paid features until that time. Canceling stops future renewals; it does not retroactively refund charges already paid for the current period, except as expressly stated in Refunds or as required by law. If you cancel during a free trial, access ends at the trial end.
  • Price Changes. We may change prices, plan features, or billing terms from time to time. We will provide notice where required by law. Any changes will apply prospectively for your next billing cycle (or as otherwise disclosed).
  • Refund Policy.
    • Monthly Plans — Five-Day Refund Window. An eligible current monthly Pro or Founders Club payment may be refunded in full if you request the refund within five calendar days after the successful payment and first disable auto-renew. Gifted plans and payments already refunded are not eligible. An approved refund is returned to the original payment method, cancels the subscription, and immediately downgrades the account to Freemium. Outside this window, monthly fees are non-refundable except where required by law. We may deny or limit refunds for fraud, abuse, chargebacks, payment-processor restrictions, or other legal reasons.
    • Yearly Plans — Prorated Refunds (Annual Prepay; Monthly Proration; Limited). Pro and Founders Club yearly plans are annual prepaid subscriptions. If you cancel a yearly plan, cancellation is effective at the end of your then-current subscription month, and you will retain access to paid features until that time. We may provide a prorated refund subject to: monthly (not daily) proration; unused full months only after the cancellation effective date; current month not refundable; “subscription month” is each monthly period from your start date; refunds go to the original payment method; exclusions include taxes/fees/chargebacks/outstanding usage; we may deny refunds for fraud/abuse/violations; legal requirements always apply. Proration is calculated at fixed monthly rates of $2.99 (Pro) and $9.99 (Founders Club). Refunds are limited to the amount paid and may be $0 once the fixed monthly rate has fully exhausted the annual price.
  • Failed Payments; Suspension. If a payment fails or your payment method is invalid/expired, we may retry the charge, request updated payment information, and/or suspend or downgrade your access until payment is received.
  • Chargebacks. Initiating a chargeback without first contacting us to resolve a billing dispute may result in suspension or termination.

Intellectual Property

  • Our IP. HypaValley and its licensors own all rights in the Service and Content.
  • License to You. Subject to these Terms, we grant you a limited, revocable, non-exclusive, non-transferable license to use the Service for your personal or internal business use.
  • Feedback. If you provide feedback, you grant HypaValley the right to use it without restriction or compensation.

User Content; License; Responsibility

  • Ownership. You retain ownership of your User Content.
  • License to HypaValley. You grant HypaValley a non-exclusive, worldwide, royalty-free license to host, store, reproduce, process, display (to you), execute (on your behalf), translate, and generate derivative representations (e.g., strategy-to-code conversion) of your User Content as necessary to provide, maintain, and improve the Service.
  • Anonymized/Aggregated Use. We may use anonymized and/or aggregated data derived from usage and User Content to improve the Service, provided it does not identify you.
  • Your Responsibility. You represent that you have the necessary rights to submit User Content and that it does not violate law or third-party rights.

Copyright Complaints

If you believe content on the Service infringes your copyright, contact support@hypavalley.com with sufficient details to identify the work and the allegedly infringing material.

Termination; Suspension; Account Closure and Data Deletion

  • Stopping Use; Closing Paid Plans. You may stop using the Service at any time. If you have a paid subscription, you are responsible for canceling or disabling auto-renew to avoid future charges.
  • Deletion Requests. HypaValley does not currently offer self-service account deletion. You may submit a verified deletion request to support@hypavalley.com. We will process valid requests as required by applicable law.
  • Retention and Exceptions. We may retain information that is reasonably necessary for security, fraud prevention, billing and dispute records, legal compliance, or establishing and defending legal claims. Data remaining in backups is isolated from ordinary use and expires through the applicable backup lifecycle. We will explain material limitations when responding to a request.
  • Broker Disconnect; Token Revocation. If you disconnect a Broker integration or your authorization expires, we will stop using the authorization and may delete or invalidate stored tokens consistent with our security practices.
  • Termination or Suspension by Us. We may suspend or terminate access at any time, with or without notice, if we believe you violated these Terms, created risk for HypaValley or others, or if required for legal, compliance, or security reasons.
  • Effect of Termination. Upon termination, your right to use the Service ends. Sections that by their nature should survive termination will survive, including intellectual property, disclaimers, limitation of liability, and indemnification.

Disclaimers

THE SERVICE IS PROVIDED “AS IS” AND “AS AVAILABLE.” TO THE MAXIMUM EXTENT PERMITTED BY LAW, HYPAVALLEY DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, ACCURACY, AND AVAILABILITY. YOU USE THE SERVICE AND LIVE TRADING FEATURES AT YOUR SOLE RISK. WE DO NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, OR SECURE.

Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW: (a) HYPAVALLEY WILL NOT BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR LOSS OF PROFITS, REVENUE, DATA, OR GOODWILL, INCLUDING TRADING LOSSES OR DAMAGES ARISING FROM ORDERS, EXECUTION, OR SERVICE ERRORS; AND (b) HYPAVALLEY’S TOTAL LIABILITY FOR ANY CLAIM WILL NOT EXCEED THE AMOUNTS YOU PAID TO HYPAVALLEY FOR THE SERVICE IN THE 12 MONTHS BEFORE THE EVENT GIVING RISE TO THE CLAIM (OR, IF YOU PAID NOTHING, $100).

Indemnification

You agree to defend, indemnify, and hold harmless HypaValley and its officers, directors, employees, and agents from any claims, liabilities, damages, losses, and expenses (including reasonable attorneys’ fees) arising from your use of the Service, your User Content, or your violation of these Terms or applicable law.

Governing Law; Venue

These Terms are governed by the laws of the State of California, without regard to conflict-of-law principles. Any dispute arising from these Terms or the Service will be brought in the state or federal courts located in Santa Clara County, California, and you consent to their jurisdiction and venue.

Changes to the Terms

We may update these Terms from time to time. Changes are effective when posted. When we designate an update as requiring renewed acceptance, account features will remain unavailable until you affirmatively accept the new version.

Contact

Questions or support: support@hypavalley.com


PRIVACY POLICY — HypaValley

Last Updated: 07/18/2026

This Privacy Policy explains how HypaValley (“HypaValley,” “we,” “our,” or “us”) collects, uses, shares, and protects information when you use the Service.

Information We Collect

1.1 Account Information

  • Email address
  • Login credentials (stored in hashed form)
  • Optional profile information and preferences
  • Terms version, acceptance timestamp, and adult-eligibility confirmation

1.2 Strategy and Trading-Related Information

  • Strategy definitions (e.g., blocks/configs), normalized specifications (e.g., JSON), generated code
  • Backtest/paper results and logs
  • If you enable Live Trading: Broker-sourced data such as account status, positions, orders, and executions as permitted by your authorization

1.3 Usage, Device, and Log Data

IP address, device/browser type, pages visited, timestamps, feature interactions, error logs, and performance metrics.

1.4 Broker Authorization Data (e.g., OAuth)

Authorization tokens/credentials needed to maintain Broker connectivity (as applicable). We do not collect or store your SSN, government ID, bank account numbers, or Broker login password.

How We Use Information

We use information to provide and operate the Service; authenticate users and maintain account security; run backtests/paper trading and, if enabled, submit order instructions to your Broker; provide support; troubleshoot issues; improve reliability; communicate transactional messages; enforce our Terms; and comply with legal obligations. We do not sell your personal information.

How We Share Information

  • Broker Integrations. If you connect a brokerage account, we share and receive information with/from your Broker as necessary to provide the authorized features. Your Broker’s policies govern how the Broker handles your brokerage data.
  • Payment Processing (Stripe). Payments are processed by Stripe. Stripe may collect and process your payment information (such as card details and billing address) under its own terms and privacy policy. HypaValley typically receives limited payment metadata from Stripe (e.g., payment status and subscription state) to manage subscriptions and support.
  • Service Providers. We may share information with vendors that help us operate the Service (hosting, analytics, customer support, monitoring). They may access information only to perform services for us and must protect it.
  • Legal and Safety. We may disclose information if required by law or if we believe disclosure is necessary to protect rights, safety, or security, investigate fraud, or enforce our Terms.
  • Business Transfers. If we undergo a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to applicable law.

Cookies and Analytics

HypaValley currently uses cookies and similar storage that are necessary to authenticate users, protect forms, maintain sessions, remember service preferences, and operate requested features. We may also use limited first-party operational logs to understand reliability and feature usage. We do not currently load third-party advertising tracking on the Service. If that practice changes, we will update this disclosure and implement any consent or opt-out controls required by applicable law before enabling it.

Data Retention

  • General Retention. We retain information as long as necessary to provide the Service and for legitimate business purposes such as security, fraud prevention, dispute resolution, and legal compliance.
  • Deletion Requests. We do not currently offer self-service deletion. You may submit a verified request to support@hypavalley.com, and we will process valid requests as required by applicable law, subject to permitted retention exceptions.
  • Backups. Deleted information may remain temporarily in backups until those backups expire or are overwritten under the applicable lifecycle. Backup copies are not used for ordinary business operations.
  • Broker Authorization Tokens. If you revoke access or disconnect your Broker integration, we will stop using the authorization and may delete or invalidate stored tokens consistent with our security practices.

Security

We implement commercially reasonable administrative, technical, and organizational safeguards to protect information. No system is completely secure; you are responsible for using strong passwords and protecting your devices.

Children’s Privacy

The Service is not intended for anyone under 18 or below the age of majority in their jurisdiction. We do not knowingly permit minors to create accounts. If you believe a minor has provided personal information, contact us so we can investigate and take appropriate action.

Your Choices and Rights

Depending on your jurisdiction, you may have rights to access, correct, delete, or obtain a copy of your personal information, and to opt out of certain processing. To submit a request, contact support@hypavalley.com. California residents may have additional rights under CCPA/CPRA. HypaValley does not sell personal information and does not share it for cross-context behavioral advertising.

International Users

If you access the Service from outside the United States, you understand your information may be processed in the United States where data protection laws may differ.

Changes

We may update this Privacy Policy from time to time. Changes are effective when posted.

Contact

Privacy questions: support@hypavalley.com


SECURITY & DATA HANDLING STATEMENT — HypaValley

Last Updated: 07/18/2026

HypaValley is committed to protecting user data and maintaining secure broker integrations. This Security & Data Handling Statement summarizes how HypaValley processes, stores, and protects information.

1. System Architecture

HypaValley operates a backend service that:

  • Receives strategy instructions
  • Executes API calls to your connected Broker
  • Processes webhook updates from Broker integrations
  • Stores user strategies and logs
  • Stores broker authorization tokens securely (where applicable)

All sensitive operations occur server-side, never in the browser.

2. OAuth Token Handling

Alpaca connections are required to use broker-provided OAuth. HypaValley does not request or store users’ Alpaca usernames, passwords, API keys, or API secrets.

  • Tokens are stored encrypted in secure database fields and restricted to backend trading services.
  • Tokens are transmitted only to the applicable Broker API as needed to provide an authorized feature and are not disclosed to unrelated third parties.

Token revocation: Users may revoke access through their Broker dashboard or disconnect the integration in HypaValley settings. Disconnecting removes the stored broker authorization credentials from HypaValley.

3. Data Storage

Stored: user email, hashed password when email/password login is used, external sign-in account identifier when Google login is used, strategies (blocks/JSON/Python), trading logs, paper results, encrypted OAuth tokens, execution event logs.

Not intentionally collected or stored: SSN, government ID, bank account numbers, Broker usernames or passwords, Broker API keys or secrets, or other sensitive financial identity documents.

4. Encryption & Data Protection

Public website and API traffic is protected with HTTPS/TLS at the production proxy, with HTTP Strict Transport Security (HSTS) enabled and session cookies marked Secure and HttpOnly. Connections to supported Broker and payment-provider APIs use HTTPS. Internal strategy-runner traffic is restricted to an isolated server/container network and authenticated with scoped internal tokens. Broker authorization tokens are encrypted at rest using AES-256-GCM, and the encryption key is held in environment configuration outside source code and backed up separately from database backups. Sensitive application endpoints require authentication and authorization, with CSRF protection applied to state-changing browser requests.

5. Market Data Handling

HypaValley does not sell or independently redistribute market data. Market data is retrieved from the user’s Broker and/or authorized market-data providers to operate requested features and may be temporarily cached or processed to calculate strategy results. Derived results, strategy logs, and execution records may be retained as described in the Privacy Policy.

6. Access Controls & Authentication

Production infrastructure is protected by AWS network controls, and administrative server access is restricted using key-based SSH. Application access uses authenticated, server-side sessions with authorization checks, and administrative functions are limited to a small set of designated accounts (least privilege). Production secrets are stored outside source code. Privileged actions — such as enabling or disabling live trading and connecting or disconnecting a Broker — are recorded in a dedicated audit log.

7. Logging, Monitoring & Change Management

HypaValley records application, execution, and order events, and maintains a dedicated audit log of privileged actions. A reconciliation process periodically compares internal records against Broker data to detect discrepancies. Code changes are managed through version control and must pass an automated continuous-integration gate (linting and an offline test suite) before release. Operating-system and dependency updates are applied as part of routine maintenance.

8. Data Backups & Recovery

HypaValley’s production database is protected by automated, encrypted backups retained under an operational backup schedule and stored separately from the primary application environment, with access restricted through cloud-provider access controls. Recovery procedures are documented, and recoverability has been validated by restoring a backup to a separate environment and verifying the recovered data. The token-encryption key is backed up separately from database backups so that a single compromise cannot yield both the encrypted data and the key.

9. Incident Response

HypaValley maintains a written incident-response runbook covering roles, severity levels, containment, evidence preservation, and notification. When a security issue is identified, HypaValley may restrict access, revoke or rotate affected credentials, preserve relevant logs, investigate the event, remediate the cause, and notify affected users, Brokers, or authorities when required by applicable law or agreement. These procedures are reviewed and refined over time.

10. Compliance & Regulations

HypaValley seeks to operate in accordance with applicable privacy laws, contractual commitments, and Broker requirements. This statement is reviewed at least annually and after material changes. It does not claim a third-party security certification or independent compliance audit. HypaValley is not a broker-dealer and does not custody user funds or securities.

11. Contact

For security concerns or data questions, email support@hypavalley.com.