Legal · Version 2026-09-15

Privacy Policy

Effective September 15, 2026

1. Who we are and what this Policy covers

Carbon Copy Markets Inc., doing business as Hoplite (“Hoplite,” “we,” “us,” or “our”), is the controller of the Personal Data described in this Policy. Our registered address is 2810 North Church Street, Wilmington, DE 19802, United States. You can reach our privacy team at support@hoplite.sh. We have not appointed a statutory data protection officer; the support team handles all data protection questions and requests.

We have not appointed a representative in the United Kingdom or the European Union.

This Policy explains how we collect, use, disclose, and protect information that identifies or can reasonably be linked to a person (“Personal Data”) when you visit hoplite.sh or use our applications, APIs, coding agents, sandboxes, integrations, support channels, and related services (collectively, the “Service”).

When you use Hoplite through an organization, that organization decides what repositories, prompts, and workspace data to bring into the Service and is usually the controller of Personal Data inside that content; Hoplite processes it as the organization's processor under our Terms of Service. Contact the organization about its privacy practices for that data. This Policy does not cover third-party services you connect to Hoplite or websites that link to us.

2. Personal Data we collect and where it comes from

  • Account and identity data (from you or your sign-in provider): name, email address, profile image, authentication identifiers, passkeys, organization membership, role, and preferences.
  • Customer Content (from you, your organization, and connected services): source code, repository metadata, branches, commits, pull requests, issues, prompts, instructions, messages, files, model inputs and outputs, tool calls, terminal commands, environment configuration, and other content processed at your direction.
  • Integration data (from services you connect): GitHub installation and repository information, issue-tracker records, Slack or iMessage messages, OAuth tokens, and integration configuration.
  • Usage and technical data (collected automatically): IP address, browser and device information, dates and times, pages visited, feature usage, diagnostics, logs, crash data, performance metrics, agent events, security events, and approximate location derived from IP address.
  • Signup verification data (collected automatically when you create an account): device signals and a derived device identifier from Fingerprint, a bot-risk score from Google reCAPTCHA, IP-derived country, and VPN or proxy indicators. See section 8.
  • Billing data (from you and Stripe): plan, seat count, credit balance, transaction identifiers, billing status, billing address, and limited payment metadata. Stripe processes full payment-card details; Hoplite never stores complete card numbers.
  • Communications (from you): support requests, feedback, survey responses, and records of the emails we send you.

3. Why we use Personal Data and our lawful basis for each purpose

UK and EU data protection law requires us to have a lawful basis for each way we use Personal Data. The table below sets out each purpose and the basis we rely on.

Purposes and lawful bases
PurposePersonal Data usedLawful basis
Providing the Service: creating and administering accounts and workspaces, authenticating you, executing agent requests, provisioning sandboxes, connecting integrations, and returning outputs.Account data, Customer Content, integration data, usage data.Performance of our contract with you (Terms of Service). Where your organization is the customer, our legitimate interest in providing the Service it has purchased for you.
Providing the Free-plan Muse Spark 1.3 Contributor model route. Meta may use prompt and completion content sent to this route to train and improve its models; paid plans use standard Muse Spark 1.3 and are not sent to it. See sections 5 and 6.Prompt and completion text, which can include instructions, tool results, and repository content.Performance of our contract to provide the selected model route. Where your organization is the customer, our legitimate interest in providing the Service it has selected.
Billing: processing subscriptions, credits, payments, refunds, taxes, and invoices.Account data, billing data.Performance of our contract; legal obligation for tax and accounting records.
Sending service, security, billing, and legal notices, and verification or sign-in emails.Account data, communications.Performance of our contract; legal obligation where a notice is legally required.
Sending product announcements by email.Email address, name.Legitimate interest in keeping customers informed about the product they use; you can unsubscribe at any time.
Keeping the Service secure and reliable: monitoring errors, diagnosing failures, keeping logs, rate limiting, and investigating abuse.Usage and technical data, account identifiers, error reports.Legitimate interest in operating a secure and reliable service and protecting our users and systems.
Preventing fraudulent, duplicate, and automated signups, and blocking use from sanctioned or high-abuse regions.Signup verification data, IP address, email address.Legitimate interest in preventing fraud and abuse of a free-tier service; legal obligation to comply with sanctions law.
Understanding how the product is used so we can improve it (product analytics).Pseudonymous usage events and, after sign-in, your user and organization identifiers, email, and name.Consent, given through the analytics banner, for analytics cookies and the events they enable. Server-side product events that need no browser storage rely on our legitimate interest in improving the Service; you may object at any time.
Attributing signups and purchases to the referral link that brought you to us so we can pay referral partners.Referral click ID, user ID, email, name, purchase amount.Consent, given through the analytics banner, for the attribution cookie; legitimate interest in operating the referral program for the resulting lead and sale records.
Notifying our team internally when a business account is created.Name, email address, company derived from your email domain.Legitimate interest in following up with new business customers.
Complying with law, enforcing our agreements, and establishing or defending legal claims.Any category, as relevant.Legal obligation; legitimate interest in protecting our rights.
Creating aggregated or de-identified statistics that cannot reasonably identify you.Usage data.Legitimate interest in understanding and reporting on our business.

Where we rely on legitimate interests, we have balanced those interests against your rights and concluded that the processing is not overridden by them. You can ask us for a copy of that assessment or object to the processing at support@hoplite.sh.

4. Do you have to provide Personal Data?

Providing your name and email address is a contractual requirement: we cannot create or administer an account without them. Completing the signup verification check is also required to create an account, because it is how we keep the Service available to genuine users. Billing information is required only if you buy a paid plan or credits. Everything else, including product analytics and referral attribution, is optional, and declining it does not affect your use of the Service.

5. AI model processing

To perform agent requests, Hoplite sends prompts, instructions, code, files, repository context, tool results, outputs, and related metadata to the model provider selected or enabled for your workspace. The providers we use are listed in section 6. Hoplite does not use Customer Content to train or fine-tune machine-learning models.

Model providers process data under their business or API terms. Their retention practices vary by provider, model, account configuration, and law. Unless we expressly agree otherwise in writing, we do not represent that model-provider processing is subject to zero data retention. Free-plan workspaces use Meta's Muse Spark 1.3 Contributor route through OpenRouter for Muse Spark requests; Meta may use prompts and completions sent to that route to train and improve its models. Paid plans use the standard Muse Spark 1.3 route and are not sent to the Contributor route. See the Meta row in section 6. If your workspace connects its own model gateway or API key, requests go to that provider under your own agreement with them.

6. Who we share Personal Data with

We share Personal Data with the service providers listed below, who process it on our behalf and only on our instructions. We do not sell Personal Data or share it for cross-context behavioral advertising. The tables are grouped by the purpose each provider serves and name the country the data is processed in together with the safeguard we rely on for the transfer (see section 7).

Hosting, storage, and content delivery
ProviderWhat they do for usData they receiveLocation and transfer safeguard
Amazon Web Services (AWS)Runs the Hoplite web app, API, worker, and sync service (ECS), stores uploads and artifacts (S3), encrypts secrets (KMS), delivers the app through CloudFront, and records infrastructure logs and metrics (CloudWatch).All categories processed by the Service, including account data, Customer Content, usage and technical data, and server logs.United States (us-east-1); CloudFront edge locations worldwide. TO CONFIRM: UK Addendum to the EU SCCs / UK IDTA, or UK-US Data Bridge certification.
PlanetScaleManaged PostgreSQL database for all application data.Account data, workspace and billing records, Customer Content metadata, agent transcripts and events, integration tokens (encrypted).United States. TO CONFIRM: UK Addendum to the EU SCCs / UK IDTA, or UK-US Data Bridge certification.
Authentication and identity
ProviderWhat they do for usData they receiveLocation and transfer safeguard
Google (Sign in with Google) and GitHub (OAuth)Optional social sign-in. Hoplite receives your name, email, and profile image from the provider you choose.Name, email address, profile image, provider account identifier.United States. TO CONFIRM: UK Addendum to the EU SCCs / UK IDTA, or UK-US Data Bridge certification.
Payments and billing
ProviderWhat they do for usData they receiveLocation and transfer safeguard
Stripe, Inc.Subscription billing, credit purchases, invoicing, and tax calculation.Billing name, email, address, payment method details (held by Stripe; Hoplite never stores full card numbers), plan, and transaction history.United States. TO CONFIRM: UK Addendum to the EU SCCs / UK IDTA, or UK-US Data Bridge certification.
Email delivery
ProviderWhat they do for usData they receiveLocation and transfer safeguard
Resend, Inc.Sends verification, sign-in, invitation, billing, and service emails, and keeps a contact-list mirror of user emails for product announcements.Email address, name, and the content of the email.United States. TO CONFIRM: UK Addendum to the EU SCCs / UK IDTA, or UK-US Data Bridge certification.
Source control
ProviderWhat they do for usData they receiveLocation and transfer safeguard
GitHub, Inc.Repository access through the Hoplite GitHub App: reading code and creating branches, commits, pull requests, comments, and issues at your direction.Repository contents and metadata, pull request and issue content, GitHub account identifiers, and installation details.United States. TO CONFIRM: UK Addendum to the EU SCCs / UK IDTA, or UK-US Data Bridge certification.
Development sandboxes
ProviderWhat they do for usData they receiveLocation and transfer safeguard
Modal Labs, Inc.Runs the isolated development sandboxes in which agents clone repositories, execute commands, run previews, and drive a browser.Repository contents, environment configuration and secrets you provide, command output, and files produced during a run.United States. TO CONFIRM: UK Addendum to the EU SCCs / UK IDTA, or UK-US Data Bridge certification.
Daytona Platforms, Inc.Legacy sandbox provider retained for a compatibility path; new workspaces run on Modal.Same categories as Modal when this provider is used.United States. TO CONFIRM: UK Addendum to the EU SCCs / UK IDTA, or UK-US Data Bridge certification.
Workflow orchestration
ProviderWhat they do for usData they receiveLocation and transfer safeguard
Temporal Technologies, Inc. (Temporal Cloud)Durable execution of agent runs and scheduled maintenance workflows.Workflow inputs and results: organization, thread, run, and user identifiers, and run parameters. Customer Content is referenced by identifier rather than copied into workflow history, except where a small step result is stored inline.United States. TO CONFIRM: UK Addendum to the EU SCCs / UK IDTA, or UK-US Data Bridge certification.
AI model inference and agent tools
ProviderWhat they do for usData they receiveLocation and transfer safeguard
Anthropic, PBCLarge-language-model inference for agent runs when an Anthropic model is selected.Prompts, instructions, code, files, repository context, tool results, and model outputs for the run.United States. TO CONFIRM: UK Addendum to the EU SCCs / UK IDTA, or UK-US Data Bridge certification.
OpenAI, L.L.C.Large-language-model inference for agent runs when an OpenAI model is selected, including ChatGPT Codex subscription models you connect.Same categories as Anthropic.United States. TO CONFIRM: UK Addendum to the EU SCCs / UK IDTA, or UK-US Data Bridge certification.
OpenRouter, Inc. (routing to Google, DeepSeek, Moonshot AI, Z.ai, Meta, and other model hosts)Routes inference requests for models not served directly (for example Gemini, DeepSeek, Kimi, GLM) to the underlying model host.Same categories as Anthropic, forwarded to the selected model host.United States (OpenRouter and the underlying model hosts used by Hoplite). TO CONFIRM: UK Addendum to the EU SCCs / UK IDTA, or UK-US Data Bridge certification.
Meta Platforms, Inc. (via OpenRouter)Provides the Muse Spark 1.3 Contributor model route. Free-plan workspaces use this route as their Muse Spark route. Meta may use prompts and completions sent to the Contributor route to train and improve its models. Paid plans use the standard Muse Spark 1.3 route and are not sent to this Contributor route.Prompt and completion text, which can include instructions, tool results, and repository content.United States. TO CONFIRM: UK Addendum to the EU SCCs / UK IDTA, or UK-US Data Bridge certification.
Customer-configured model gateways (Vercel AI Gateway, Cloudflare AI Gateway, Neon AI Gateway, or an OpenAI-compatible endpoint you supply)When your workspace connects its own model gateway, inference requests go to that gateway instead of Hoplite's providers.Same categories as Anthropic, sent to the gateway you configure.Determined by the gateway you configure. Your own arrangement with the gateway provider.
Exa Labs, Inc.Web search for agents when the web-search tool is enabled.Search queries composed by the agent during a run.United States. TO CONFIRM: UK Addendum to the EU SCCs / UK IDTA, or UK-US Data Bridge certification.
Connected integrations you enable
ProviderWhat they do for usData they receiveLocation and transfer safeguard
Linear, Slack, Photon (iMessage), Sentry app, and GitCafeOptional integrations you connect. Hoplite exchanges the data needed to sync issues, receive and send messages, read error details, or access repositories on the connected service.Integration account identifiers, OAuth tokens (encrypted at rest), and the issue, message, phone-number, error, or repository content you direct us to exchange.United States. TO CONFIRM: UK Addendum to the EU SCCs / UK IDTA, or UK-US Data Bridge certification.
Signup fraud prevention
ProviderWhat they do for usData they receiveLocation and transfer safeguard
Fingerprint (FingerprintJS, Inc.)Device identification during account creation to detect repeat and automated signups.Browser and device signals collected by the Fingerprint agent, IP address, and the derived visitor ID, country and region, and VPN or proxy indicators. Hoplite stores only a keyed hash of the visitor ID alongside the account it created. Identification requests go to a subdomain of hoplite.sh where configured, otherwise to Fingerprint's own hosts.United States (us region). TO CONFIRM: UK Addendum to the EU SCCs / UK IDTA, or UK-US Data Bridge certification.
Google reCAPTCHA (Google LLC)Bot detection during account creation, used alongside Fingerprint or instead of it when the Fingerprint agent is blocked.Browser and interaction signals collected by Google's reCAPTCHA script, IP address, and a risk score returned to Hoplite.United States. TO CONFIRM: UK Addendum to the EU SCCs / UK IDTA, or UK-US Data Bridge certification.
Error monitoring and logging
ProviderWhat they do for usData they receiveLocation and transfer safeguard
AxiomApplication log, trace, and metric storage for reliability and security monitoring.Structured server logs and OpenTelemetry traces and metrics: user, organization, thread, and run identifiers, request paths, error messages, and performance data. Request bodies, secrets, and cookies are scrubbed before export.United States. TO CONFIRM: UK Addendum to the EU SCCs / UK IDTA, or UK-US Data Bridge certification.
Sentry (Functional Software, Inc.)Error and crash reporting for the browser app, API, and worker.Error messages, stack traces, browser and device information, release version, and the identifiers needed to reproduce a failure. Default personal-data capture is disabled (sendDefaultPii: false), request data is scrubbed before sending, and session replay is not used.United States. TO CONFIRM: UK Addendum to the EU SCCs / UK IDTA, or UK-US Data Bridge certification.
incident.ioReceives production alerts from AWS CloudWatch and pages the on-call engineer.Alarm names, metric values, and alert descriptions. Alerts do not include Customer Content or account identifiers.United States. TO CONFIRM: UK Addendum to the EU SCCs / UK IDTA, or UK-US Data Bridge certification.
Product analytics
ProviderWhat they do for usData they receiveLocation and transfer safeguard
PostHog, Inc.Product analytics (explicitly modeled events only; no autocapture, session recording, or surveys), feature flags, and prompt and model configuration for the agent runtime.Browser: pseudonymous device and session identifiers, page paths without query strings, feature-usage events, and, after sign-in, your user ID, email, name, and organization. Server: agent-run and billing events keyed by user and organization ID, and AI generation metadata (model, tokens, latency). The worker does not record prompt or output text unless an operator explicitly enables HOPLITE_AI_TELEMETRY_RECORD_IO=1; if that setting is enabled in production, prompts and outputs are recorded. Ingest is proxied through a first-party host (ph.hoplite.sh).United States (US Cloud). TO CONFIRM: UK Addendum to the EU SCCs / UK IDTA, or UK-US Data Bridge certification.
Referral attribution
ProviderWhat they do for usData they receiveLocation and transfer safeguard
Dub Technologies, Inc.Attributes signups and purchases to referral links so we can pay referral partners.Referral click ID from the dub_id query parameter (stored in a first-party cookie); on signup, your user ID, email, name, and avatar URL; on purchase, the amount and Stripe invoice ID.United States. TO CONFIRM: UK Addendum to the EU SCCs / UK IDTA, or UK-US Data Bridge certification.
Internal operations notifications
ProviderWhat they do for usData they receiveLocation and transfer safeguard
Slack (internal channel) and Context.devWhen an account completes email verification, Hoplite posts the new user's name and email to an internal Slack channel and looks up the email's company domain through Context.dev to enrich that notification. Personal-email-domain signups are not posted.Name, email address, and the company name and logo derived from the email domain.United States. TO CONFIRM: UK Addendum to the EU SCCs / UK IDTA, or UK-US Data Bridge certification.

We also disclose Personal Data to: your organization and workspace collaborators according to their roles; services you direct us to connect; courts, regulators, and law enforcement where required by law or to protect rights and safety; and a successor in a merger, acquisition, financing, reorganization, or sale of assets, subject to appropriate confidentiality protections.

7. International transfers

Hoplite is based in the United States and most of the providers in section 6 process data there. When we transfer Personal Data from the United Kingdom or the European Economic Area to the United States or another country without an adequacy decision, we rely on one of the following safeguards, as indicated per provider in section 6: the UK International Data Transfer Addendum to the EU Standard Contractual Clauses (or the UK IDTA), the EU Standard Contractual Clauses for EEA transfers, or the provider's certification under the UK Extension to the EU-US Data Privacy Framework (the “UK-US Data Bridge”) where it holds one. [TO CONFIRM WITH COUNSEL: the mechanism in force for each provider, and Carbon Copy Markets Inc.'s own mechanism for receiving UK and EEA data as controller.]

You can request a copy of the relevant safeguards at support@hoplite.sh.

8. Automated decisions during signup

When you create an account, an automated check decides whether the signup can proceed. It uses a device identifier from Fingerprint, a bot-risk score from Google reCAPTCHA, the country and region derived from your IP address or device, VPN and proxy indicators, and the number of accounts previously created from the same device. The check refuses account creation when the signup appears automated, when the device has already created the maximum number of accounts, when the email domain is a disposable-email provider, or when the connection comes from a region we do not serve. Regions we do not serve are comprehensively sanctioned jurisdictions, jurisdictions our payment or model providers cannot serve, and regions with sustained signup fraud volume.

This is an automated decision that prevents you from using the Service. Because it may significantly affect you, you have the right to ask for a human review: email support@hoplite.sh with the email address you tried to sign up with, and a member of our team will review the decision, explain it where sanctions law permits, and create the account manually if the refusal was wrong. Beyond signup, Hoplite does not make decisions about you that have legal or similarly significant effects solely by automated means.

9. Cookies and browser storage

We use cookies and browser storage for two reasons: strictly necessary items that keep you signed in, protect sign-in, remember your choices, and verify signups; and analytics and attribution items. Where the law where you are requires consent (including the EEA, the United Kingdom, Switzerland, Brazil, Quebec, and South Korea), we set analytics and attribution items only after you choose Accept in the cookie banner, and Reject is offered with equal prominence. In the United States and other regions that require notice rather than consent, we set them when you visit and you can turn them off at any time with the “Your privacy choices” link next to “Privacy policy” in the page footer (our “Do Not Sell or Share My Personal Information” control), which offers the same Accept and Reject choice; we also treat a Global Privacy Control signal from your browser as that opt-out. We use your country (never stored) only to decide which of these applies. You can change your choice at any time through those controls or by clearing your browser storage; withdrawing consent or opting out stops further analytics and attribution storage but does not affect processing that already happened.

Cookies and browser storage on hoplite.sh
NameSet byPurposeLifetimeBasis
__Secure-better-auth.session_tokenHopliteKeeps you signed in.7 days, refreshed on useStrictly necessary
__Secure-better-auth.state and related sign-in cookiesHopliteProtects the sign-in and OAuth flow against cross-site request forgery.Minutes; removed when sign-in completesStrictly necessary
hoplite:themeHopliteRemembers your light or dark theme choice.Until clearedStrictly necessary
hoplite_consentHopliteRemembers whether you accepted or rejected analytics cookies.182 daysStrictly necessary
hoplite_dub_id (or __Host-hoplite_dub_id on secondary marketing domains)Hoplite for DubStores the referral click ID from a dub_id link so a later signup can be attributed to the referrer.90 daysConsent (analytics banner)
dub_idDubDub's own first-party attribution cookie written by its script.90 daysConsent (analytics banner)
ph_<project token>_posthogPostHogPseudonymous device and session identifier so product analytics events from one browser are grouped together.365 daysConsent (analytics banner)
ph_<project token>_posthog (localStorage)PostHogFeature-flag state and analytics super-properties.Until clearedConsent (analytics banner)
_iidt (only when the signup fraud check runs)FingerprintDevice identifier used during account creation to detect repeat or automated signups. Set only on the signup page.Up to 1 year (7 days in Safari)Strictly necessary
Sentry (no storage)SentryError reporting. Sentry's browser SDK as configured writes no cookies or local storage.Not applicableStrictly necessary

Browser settings also let you block or delete cookies, but blocking strictly necessary cookies prevents sign-in from working.

10. How long we keep Personal Data

Retention periods
DataRetention period
Account and profile dataFor the life of your account, then deleted within [30 — TO CONFIRM] days of account deletion, except where retained under another row.
Customer Content you upload or create in Hoplite (messages, prompts, outputs, attachments)For the life of the thread or workspace that contains it, until you or your organization deletes it, then deleted within [30 — TO CONFIRM] days.
Agent run diagnostics (internal run events and recovery steps that are not shown in the transcript)Eligible for deletion once at least 14 days have passed since the run finished; a cleanup job removes eligible rows after that grace period. User-visible transcript messages, tool calls, approval records, and billing records are kept per the other rows.
Sandbox workspaces and their contentsFor the life of the thread; provider storage is released when the thread is archived or deleted, [TO CONFIRM] days after the last activity.
Billing and tax records7 years after the transaction, as required by tax and accounting law.
Signup verification records (hashed device identifier, method, outcome)For the life of the account, so repeat-signup limits keep working; [TO CONFIRM] days for refused signups.
Application logs, traces, and metrics30 days in CloudWatch; [TO CONFIRM] days in Axiom; infrastructure audit trails 365 days.
Error reports in Sentry[90 — TO CONFIRM] days, per our Sentry plan's retention.
Product analytics events in PostHog[TO CONFIRM] months, per our PostHog plan's retention; identified profiles are deleted on request.
Referral attribution records in DubFor the life of the referral program record — [TO CONFIRM].
Emails sent through Resend[TO CONFIRM] days of delivery logs held by Resend.
Support communications[3 — TO CONFIRM] years after the request is closed.

Deletion from live systems and from backups happens on different schedules, and copies may persist in backups until those are overwritten, normally within [35 — TO CONFIRM] days. We may keep data longer where the law requires it, to resolve disputes, or to enforce our agreements.

11. Your rights

If you are in the United Kingdom or the European Economic Area, you have the following rights over your Personal Data:

  • Access: to obtain confirmation that we process your Personal Data and a copy of it.
  • Rectification: to have inaccurate Personal Data corrected and incomplete data completed.
  • Erasure: to have Personal Data deleted where there is no longer a good reason for us to keep it.
  • Restriction: to have us pause processing while a dispute about accuracy or lawfulness is resolved.
  • Portability: to receive the Personal Data you gave us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
  • Objection: to object to processing based on legitimate interests, including product analytics and product announcements, and to any direct marketing.
  • Withdrawal of consent: where we rely on consent (analytics and attribution cookies), to withdraw it at any time. Withdrawal does not affect processing that took place before you withdrew.
  • Not to be subject to a solely automated decision with legal or similarly significant effects: see section 8 for the human-review route.

To exercise any right, email support@hoplite.sh. We may ask you to verify your identity. We respond within one month, extendable by two further months for complex requests, and we will tell you if we need the extra time. We do not charge for requests unless they are manifestly unfounded or excessive. We will not treat you differently for exercising your rights.

You also have the right to lodge a complaint with a supervisory authority. In the United Kingdom, that is the Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF; ico.org.uk; 0303 123 1113. In the European Economic Area, you can complain to the data protection authority of the country where you live, work, or where you believe the infringement occurred. We would appreciate the chance to address your concern first, so please consider contacting us before you complain.

If you live elsewhere, including in a U.S. state with a privacy law, you may have similar rights, including to appeal a denied request. Use the same contact address. Authorized agents may submit requests where local law permits.

12. Security

We protect Personal Data with access controls, encryption in transit, encryption at rest for secrets and integration tokens, credential protections, logging, and isolated sandboxes for agent execution. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. You are responsible for securing your account, connected services, secrets, repositories, and local systems.

13. Children

The Service is not directed to children, and you must be at least 18 years old to use it. We do not knowingly collect Personal Data from children. If you believe a child has provided Personal Data, contact us so we can investigate and delete it.

14. Changes to this Policy

We may update this Policy as the Service and our practices change. We post each version with its effective date and keep earlier versions available on request. If a change materially affects how we use Personal Data, we will notify you by email or in the Service before it takes effect. Continuing to use the Service after that notice means the new version applies; you are not required to re-accept it to keep using an existing account.

15. Contact us

For privacy questions or requests, email support@hoplite.sh, or write to Carbon Copy Markets Inc., 2810 North Church Street, Wilmington, DE 19802, United States.