Skip to content
MosaicBack to Mosaic

Legal

Privacy Policy

How Mosaic collects, uses, stores, and protects information.

Last updated: 9 August 2026

Jump to section
01Introduction02Information we collect03How we use information04Data storage and security05How we disclose information06Cookies and similar technologies07Data retention08Your rights and choices09Marketing communications10International transfers11Children's privacy12Changes to this policy13Contact us

Contents

01Introduction02Information we collect03How we use information04Data storage and security05How we disclose information06Cookies and similar technologies07Data retention08Your rights and choices09Marketing communications10International transfers11Children's privacy12Changes to this policy13Contact us

1. Introduction

Mosaic is currently a pre-launch project operated by its founder and has not yet been incorporated as a separate legal entity. In this Privacy Policy, “Mosaic,” “we,” “us,” and “our” refer to the Mosaic project and its current operator. This Privacy Policy explains how we collect, use, store, disclose, and protect information when you:

  • Visit the Mosaic website;
  • Register for early access;
  • Use features currently available on the website; or
  • Communicate with us.

Connected-account and live-execution features are not currently available to users. The connected-account sections below explain how information may be handled when those features become available.

The Mosaic website, research materials, early-access registration, paper-execution information, and other features currently made available by Mosaic are collectively referred to as the “Services.” Your use of the Services is also subject to our Terms of Use.

2. Information We Collect

Information you provide

We collect information that you provide directly to us, including:

  • Your email address;
  • The Mosaic products or features you are interested in;
  • Information submitted through early access forms or free-text fields;
  • Feedback, support requests, and other communications; and
  • Any other information you choose to provide.

Connected-account information

When connected-account functionality becomes available, and you choose to connect a wallet, exchange account, subaccount, or other supported trading account, we may collect or process:

  • Wallet addresses;
  • Exchange account identifiers;
  • API keys, authentication tokens, or similar connection credentials;
  • Account balances and available margin;
  • Portfolio positions;
  • Orders, fills, cancellations, and trading history;
  • Execution, reconciliation, and account-status information; and
  • Other data made available through the connected exchange, protocol, wallet, or trading venue.

Connected-account execution will be non-custodial. You will retain custody of your assets. Mosaic will never have withdrawal or transfer access to connected user wallets or exchange accounts. You should never provide Mosaic with a wallet seed phrase or private key.

Information collected automatically

When you access or use the Services, we automatically collect certain technical and usage information, including:

  • IP address;
  • User-Agent and related technical information;
  • Pages and product features viewed or used;
  • Error reports, performance data, and diagnostic logs; and
  • Approximate location and related operational details derived from your IP address.

When you join the waitlist, we may use your IP address with IPLocate to derive approximate location and related network details. Our server logs may also use GeoLite2 data created by MaxMind for internal operational logging, including country, region, continent, and city metadata. Those GeoLite2 values are not sent to our API, returned to clients, or sent to PostHog. GeoLite2 data is available from MaxMind.

3. How We Use Information

We use information to:

  • Process and manage early access registrations;
  • Notify you when relevant Mosaic products or features become available;
  • Provide, operate, maintain, and improve the Services;
  • Monitor performance, availability, capacity, and reliability;
  • Diagnose and resolve technical or operational issues;
  • Detect and prevent fraud, unauthorised access, abuse, and security incidents;
  • Respond to questions, feedback, and support requests;
  • Send product announcements, research notes, access invitations, and service communications;
  • Analyse how users interact with the Services;
  • Enforce our terms and other agreements; and
  • Comply with applicable legal and regulatory obligations.

When connected-account functionality becomes available, and you authorise it, we use information to authenticate connections, retrieve account data, reconcile activity, and apply account, execution, or risk controls. When live execution becomes available, we also use information to submit, modify, or cancel orders in accordance with the instructions, strategy settings, allocations, account limits, or other permissions you configure.

Depending on the context and where required by law, we may rely on the following legal bases:

  • To perform a contract with you or take steps at your request, such as processing an early-access registration;
  • Our legitimate interests in operating, securing, and improving the Services and preventing abuse;
  • Your consent, where we ask for it;
  • Compliance with a legal obligation; or
  • Protection of the rights and safety of Mosaic, our users, or others where permitted by law.

4. Data Storage and Security

We use administrative, technical, and organisational safeguards designed to protect information from unauthorised access, loss, misuse, alteration, or disclosure.

These safeguards may include:

  • Encryption in transit and at rest where appropriate;
  • Access controls and authentication measures;
  • Restrictions on access to sensitive information;
  • Security monitoring and operational logging;
  • Separation of production systems and access permissions; and
  • Procedures for identifying and responding to security incidents.

No system, network, or storage method is completely secure. We therefore cannot guarantee the absolute security of information processed through the Services.

When a Service processes API keys, authentication tokens, delegated credentials, or similar connection credentials, we will limit access to the systems and people who need them to provide that Service.

5. How We Disclose Information

We do not sell your personal information.

We may disclose information in the following circumstances.

Service providers

We may provide information to vendors and service providers that help us operate the Services, including providers of:

  • Cloud hosting and infrastructure;
  • Databases and data storage;
  • Monitoring and error reporting;
  • Analytics, including PostHog;
  • Email and communications, including Resend when configured;
  • IP geolocation, including IPLocate when configured; and
  • Security and operational infrastructure.

These providers may process information on our behalf to provide their services, subject to applicable contractual and legal obligations.

We use PostHog to measure website usage and activity in the access and waitlist funnels. Our configuration uses cookieless mode, turns off session recording, and does not send email addresses or submitted form values to PostHog.

Exchanges and trading venues

When connected-account functionality becomes available, and you authorise it, we may transmit information and instructions to supported exchanges, protocols, wallets, and trading venues, including Hyperliquid, Lighter, and other venues supported by Mosaic.

This may be necessary to:

  • Authenticate a connection;
  • Retrieve account and trading information;
  • Submit, modify, or cancel live orders when live execution becomes available and is authorised by you, including through instructions, strategy settings, allocations, account limits, or other permissions you configure;
  • Reconcile orders and executions; or
  • Provide other functionality requested by you.

Third-party exchanges, protocols, wallets, websites, and other services operate independently from Mosaic and maintain their own terms, privacy policies, and security practices. You should review those terms and policies before connecting an account or using a third-party service through Mosaic.

Legal requirements

We may disclose information when we reasonably believe that disclosure is necessary to:

  • Comply with applicable law, regulation, court order, subpoena, or legal process;
  • Respond to a lawful request from a public authority;
  • Establish, exercise, or defend legal claims;
  • Investigate suspected fraud, abuse, or unlawful conduct; or
  • Protect the rights, property, privacy, or safety of Mosaic, our users, or the public.

Business transfers

Information may be disclosed or transferred as part of a merger, financing, acquisition, reorganisation, sale of assets, insolvency proceeding, or similar business transaction.

With your direction or consent

We may disclose information when you direct us to do so or otherwise provide your consent.

6. Cookies and Similar Technologies

The current landing website does not use cookies or local storage for analytics. PostHog is configured in cookieless mode, so its current analytics activity does not use cookies or browser storage.

Authenticated products may use cookies, local storage, or similar technologies that are necessary to:

  • Keep the website and Services functioning;
  • Maintain sessions and authentication;
  • Remember preferences;
  • Protect against fraud and unauthorised access;
  • Understand website and product usage; and
  • Diagnose errors and improve performance.

You may be able to control cookies through your browser settings. Blocking certain cookies or storage technologies may prevent parts of the Services from functioning correctly.

Where required by law, Mosaic will request consent before using non-essential cookies or similar technologies.

7. Data Retention

We do not currently publish a fixed retention period for every category of information. We retain information while it is reasonably needed for the purposes described in this Policy, including operating the waitlist, security, fraud prevention, analytics, compliance, and dispute resolution.

Waitlist records, IP and User-Agent data, IPLocate enrichment, server access logs, error logs, rotated logs, and backups may remain until they are deleted or overwritten under our operational practices. When information is no longer needed, we may delete, aggregate, or anonymise it.

When Mosaic stores connection credentials for a supported Service, we may retain them while the relevant account remains connected or while reasonably required to provide that Service.

8. Your Rights and Choices

Depending on where you live, you may have the right to:

  • Request access to personal information we hold about you;
  • Request correction of inaccurate or incomplete information;
  • Request deletion of personal information;
  • Request a portable copy of certain information;
  • Request restriction of certain processing;
  • Object to certain processing;
  • Withdraw consent where processing is based on consent;
  • Unsubscribe from non-essential marketing communications; and
  • Lodge a complaint with an applicable data-protection authority.

When a product supports a connected wallet or exchange account, you may disconnect it through the relevant product interface where that functionality is available.

Disconnecting an account prevents new information from being retrieved through that connection, but it does not necessarily delete information already processed or retained by Mosaic.

To exercise a privacy right, contact us at hello@mosaictrading.xyz.

We may ask you to verify your identity before completing a request. Certain rights may be limited where an exception applies or where retaining information is required for security, fraud prevention, legal compliance, recordkeeping, or the establishment or defence of legal claims.

9. Marketing Communications

We may send product and research updates, testing progress, and early-access invitations to waitlist subscribers.

Even if you opt out of marketing communications, we may continue to send important operational messages, such as security notices, waitlist or service notifications, or changes to the Services or applicable terms.

10. International Data Transfers

Mosaic and its service providers may process information in countries other than the country where you live.

Those countries may have data-protection laws that differ from the laws in your jurisdiction. Where required, we use appropriate safeguards for international transfers of personal information.

11. Children's Privacy

The Services are intended only for users who are at least 18 years old or the age of legal majority in their jurisdiction, whichever is higher.

We do not knowingly collect personal information from children. If we learn that personal information has been collected from a person who is not legally permitted to use the Services, we will take reasonable steps to delete it.

12. Changes to This Privacy Policy

We may update this Privacy Policy as Mosaic, its products, or applicable legal requirements evolve.

When changes are made, we will update the date at the top of this page. Where required or appropriate, we may also provide notice through the website, within the Services, or by email.

We encourage you to review this Privacy Policy periodically.

13. Contact Us

For privacy questions, rights requests, or concerns about how Mosaic handles personal information, contact:

Email: hello@mosaictrading.xyz

Mosaic

Trading intelligence from real trader behaviour.

Product

StrategyPortfolioTerminalVaults

About

How it worksResearchRoadmaphello@mosaictrading.xyz

Legal

TermsPrivacy

Social

X (formerly Twitter)
© 2026 Mosaic · mosaictrading.xyzTrading involves risk. Historical performance does not guarantee future results.