Privacy Policy
Last updated: July 11, 2026
TL;DR — We don't collect personal information directly. There are no accounts, sign-ups, or payment forms. Google Analytics is off by default and only runs if you accept the consent banner. We keep short-retention server logs for security, and embedded videos/news streams are loaded from third parties when you choose to watch them. BloHunter Desktop stores your trading credentials and settings locally in an encrypted store on your device; they are never sent to BloHunter.
Who we are
blohunter.com is an independently operated project. For privacy-related questions, contact [email protected].
What we collect
Always (no consent needed — strictly necessary or legitimate interest):
- Server access logs. Our server writes standard web access logs: your IP address, timestamp, requested URL, HTTP status, user-agent, and referer. These are used to keep the site secure, debug issues, and detect abuse. They are rotated and deleted after 7 days.
- Cloudflare edge. Cloudflare acts as a CDN and DDoS protection layer in front of the site, so all of your requests pass through them. They may set a short-lived bot-management cookie (
__cf_bm, ~30 minutes) and process your IP. See Cloudflare's privacy policy. - Your consent choice. When you click Accept or Decline on the consent banner, your choice is stored in your browser's
localStorage(keybh_consent). It never leaves your browser.
Only if you accept the consent banner:
- Google Analytics 4. Property
G-2QK6J2RHT9. Google sets analytics cookies (e.g._ga,_ga_2QK6J2RHT9), receives information about your browser, device, approximate geography (Google infers this from IP and then discards the full IP), pages viewed, and on-page events. See Google's privacy policy. If you don't accept, GA sends only anonymous, cookieless pings (no identifier).
What we do not collect: we have no accounts, no sign-ups, no logins, no payment forms, and no contact/comment forms. We do not collect your name, email, address, or any other directly identifying information through the site itself. The market data shown on BloHunter is public exchange data — it is not yours.
Embedded content (third parties)
The dashboard embeds live video and news streams from third parties. When you choose to play them, your browser connects directly to those services and they can see your IP and standard request data:
- YouTube (Google) — embedded YouTube players follow Google's standard embed behavior and may set cookies on
youtube.com. - News HLS streams — Sky News, France 24, Deutsche Welle, Sky News Arabia, and TRT World are loaded from each broadcaster's own CDN.
BloHunter does not send any of your data to these services on your behalf — your browser simply connects to them when you watch.
Why we process the data we do
- Site operation, security, and abuse prevention — server access logs.
- Understanding how the site is used in aggregate — Google Analytics, only if you consent.
Lawful bases (GDPR)
- Consent (Article 6(1)(a)) — for Google Analytics and any non-essential cookies.
- Legitimate interest (Article 6(1)(f)) — for short-retention server access logs, to keep the site running and secure. We've balanced this against your interests: logs are minimal, retained briefly, and used only for site operation.
Cookies and similar storage
bh_consent— localStorage, not a cookie. Stores your consent choice (grantedordenied). Stays in your browser._ga,_ga_2QK6J2RHT9— set by Google Analytics, only if you accept. Typically persist up to 2 years.__cf_bm— set by Cloudflare for bot management. Short-lived (~30 minutes).
Third parties
- Google LLC — Google Analytics, only with your consent.
- Cloudflare, Inc. — CDN, TLS, and DDoS protection in front of the site.
- Vultr Holdings — server hosting. They provide the underlying infrastructure but do not directly process visitor data.
Retention
- Server access logs: 7 days, then automatically rotated and deleted.
- Google Analytics data: per Google's retention settings (in aggregate; not tied to you by us).
- Your
bh_consentchoice: until you clear your browser storage.
Your rights
If you are in the EEA, UK, or another jurisdiction that grants similar rights, you have the right to:
- Access, correct, or delete personal data we hold about you
- Object to or restrict processing
- Withdraw consent at any time (see below)
- Lodge a complaint with your local data-protection authority
In practice, because BloHunter has no accounts, the only data identifiably linked to a visit is in short-retention server logs and (if you consent) Google Analytics. If you want us to delete a specific log entry, email [email protected] with the date/time and IP of the visit; if the logs haven't already rotated out, we'll remove them.
How to withdraw consent
- Clear the
bh_consentkey in your browser's localStorage — the consent banner will re-appear on your next visit, and you can decline. - Install Google's opt-out add-on: tools.google.com/dlpage/gaoptout.
- Use your browser's "clear site data" option for blohunter.com.
Children
BloHunter is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has provided data, contact us and we'll remove it.
BloHunter Desktop application
BloHunter Desktop is a desktop application that mirrors supported BloHunter trade lifecycle events to a user-configured futures account and provides optional monitoring and Discord webhook alerts. It operates separately from this website: the application performs no analytics, sets no cookies, does no advertising or tracking, and loads no remote executable code into its runtime.
Data we store locally. BloHunter Desktop stores data locally on your device in an encrypted store protected by your operating system's encryption. This includes:
- an encrypted credential vault created from data provided by you
- trading settings such as order size, leverage, and max position settings
- API Lock settings and recent route verification results
- Discord webhook settings (only if you enable alerts)
- recent activity log entries
- local trade state, Hold state, Recovery state, OVERRIDE state, and sync diagnostics
- account equity history and close-history data used for dashboard monitoring
When you unlock the application with your vault password, decrypted exchange credentials are held in memory only for the current unlocked session so the application can place or manage exchange requests. Those unlocked session credentials are cleared when the application is locked, closed, or the session ends. Any credentials you provide are entered by you and stored locally in encrypted form on your own device; they are never sent to or stored by BloHunter.
Data sent to third parties. The application makes network requests only to the services needed for its functionality:
blohunter.com— to receive BloHunter trade lifecycle and policy data.openapi.blofin.com— to read account state and place or manage BloFin futures orders on your behalf.discord.com— for optional user-configured Discord webhook alerts; this is only used when you enable Discord alerts.www.cloudflare.com— to perform API Lock route verification.
How we use data. We use locally stored and remotely fetched data to:
- authenticate user-requested BloFin API access
- mirror supported BloHunter trade actions to BloFin
- enforce local trading safeguards such as API Lock, cooldowns, and exposure controls
- show monitoring and diagnostic information in the dashboard and popup
- send optional Discord notifications when enabled by you
What we do not do.
- We do not sell user data.
- We do not use BloHunter Desktop as a general advertising or tracking tool.
- We do not load remote executable code into the application runtime.
User controls. You can:
- enable or disable trading
- set, replace, or remove exchange credentials
- create, rotate, or remove a vault password
- enable or disable Discord alerts
- configure API Lock behavior
- clear recent activity log data or reset the local application store
Retention. Most stored data remains in the local encrypted store until it is overwritten, cleared by you, or removed when the application is uninstalled. Some diagnostic and dashboard history stores are automatically bounded — for example, Account Growth history is capped at 10,000 samples and 45 days, while incident, sync, and close-detail stores use their own documented caps.
Changes to this policy
We'll update the "Last updated" date at the top whenever this policy changes.
Contact
Questions, requests, or complaints: [email protected].
← Back to BloHunter