wen Privacy Policy - Web App & Telegram Mini App
Last updated: 13 August 2026 · Effective: 13 August 2026
Applies to: wen.live web application and the wen Telegram mini app (together, the "Web Services").
Contents
- 1. Who we are
- 2. Summary
- 3. Data we collect, why, and on what legal basis
- 4. Non-custodial keys: what wen can and cannot access
- 5. Blockchain data: limits on erasure and pseudonymity
- 6. How we share data
- 7. International transfers
- 8. Retention
- 9. Your rights
- 10. Security
- 11. Telegram mini app
- 12. Cookies and similar technologies
- 13. Children
- 14. California residents (CCPA/CPRA)
- 15. United Kingdom
- 16. Global availability and your local law
- 17. Changes
- 18. Contact
1. Who we are
The Web Services are operated by AxonTech OÜ, an Estonian private limited company, registry code 17430331, registered address Harju maakond, Tallinn, Kesklinna linnaosa, Tornimäe tn 5, 10145 ("wen", "we", "us"). For the purposes of the EU General Data Protection Regulation (GDPR), we are the data controller of the personal data described in this Policy.
Privacy contact / Data Protection Officer: privacy@wen.live.
2. Summary
wen is a non-custodial social trading application. We never take custody of your crypto assets and cannot move, withdraw, or freeze funds in your wallet. Balances shown in wen are read live from public blockchains and trading venues. We collect the minimum personal data needed to operate your account, secure it, run social and trading features, comply with law, and improve the Web Services. We do not sell your personal data. The Web Services are available worldwide; you are responsible for ensuring that your use of them is lawful where you live.
3. Data we collect, why, and on what legal basis
| Category | Examples | Purpose | GDPR legal basis |
|---|---|---|---|
| Account & identity | Email, password hash, username, profile details | Create and manage your account; login; support | Contract (Art. 6(1)(b)) |
| Security credentials | TOTP 2FA secret, session and refresh tokens, encrypted key-export material | Two-factor authentication; secure optional key export; session security | Contract; legitimate interests in security (6(1)(b)/(f)) |
| Wallet & on-chain data | Wallet addresses, transaction hashes, public on-chain balances and history | Enable trading; display balances; core functionality | Contract (6(1)(b)) |
| Trading activity | Spot orders, perps positions, copy-trading settings and limits, results | Execute and display trades; operate copy trading | Contract (6(1)(b)) |
| Referral data | Who referred you, users you referred, reward accruals | Operate the referral program | Contract; legitimate interests (6(1)(b)/(f)) |
| Gamification data | XP, rank, streaks, quests, wheel/chest outcomes, badges, leaderboards | Operate rewards and social features | Contract (6(1)(b)) |
| User-generated content | Chat messages, theses, team content, profile media, reputation | Social features; moderation; safety | Contract; legitimate interests (6(1)(b)/(f)) |
| Device & usage data | Browser/OS type, app version, feature usage, crash and error logs | Reliability, security, product analytics | Legitimate interests; consent where required (6(1)(f)/(a)) |
| Network data | IP address, timestamps, approximate region derived from IP | Security, fraud and abuse prevention, sanctions screening, legal compliance | Legitimate interests; legal obligation (6(1)(f)/(c)) |
| Telegram identifiers | Telegram user ID, username, language (mini app only) | Authenticate and operate the mini app | Contract (6(1)(b)) |
| Communications | Support requests and related correspondence | Provide support | Contract; legitimate interests (6(1)(b)/(f)) |
| Marketing preferences | Consent records, notification opt-ins | Send communications you opt into | Consent (6(1)(a)) |
We do not intentionally collect special-category data (health, religion, etc.). Please do not post it in chats or profiles.
4. Non-custodial keys: what wen can and cannot access
Your wallet is created and secured through our embedded-wallet provider, Privy. Private keys are managed such that wen does not hold, control, or have access to your private keys and cannot move or withdraw your funds. Optional key export is protected by your password and TOTP 2FA and is end-to-end encrypted in your browser; our servers relay ciphertext they cannot read. For perpetual futures executed on an independent third-party venue, wen uses an agent key that can place orders but is technically incapable of withdrawing funds.
5. Blockchain data: limits on erasure and pseudonymity
Blockchains are public, immutable, and decentralized. When you transact, data such as wallet addresses, amounts, timestamps, and transaction hashes are recorded on public ledgers that wen does not control and cannot alter or delete. Consequently:
- We cannot erase, rectify, or restrict on-chain data. GDPR erasure and rectification rights apply to personal data held in wen's own systems, not to the blockchain itself.
- Wallet addresses are pseudonymous, not anonymous. On-chain activity may become linkable to you, particularly once an address is associated with your account or shared publicly.
- Anyone can view public on-chain data using block explorers and analytics tools.
6. How we share data
We use service providers acting as processors under Art. 28 GDPR data-processing agreements, and disclose data only as needed:
- Embedded wallet / key management: Privy
- Perps execution venue provider (agent-key order routing)
- Hosting and infrastructure: EEA-based cloud infrastructure
- Analytics and error reporting: none; no third-party analytics or crash-reporting provider receives your data, and diagnostics stay in wen's own systems
- Email and communications: Resend
- Customer support tooling: none; support is handled by email
- Compliance, sanctions, and fraud screening: performed in-house against publicly available sanctions lists, including the EU consolidated list and the OFAC SDN list; no third-party screening provider receives your data
- Telegram, for mini-app users (see §11)
We may disclose data to regulators, law enforcement, or courts where legally required, and to advisors or an acquirer in a corporate transaction, under confidentiality. We do not sell personal data.
7. International transfers
We operate from the EEA. Where providers process data outside the EEA or your region, we rely on European Commission adequacy decisions or Standard Contractual Clauses with supplementary measures as required. Details are available from privacy@wen.live.
8. Retention
We keep personal data only as long as necessary: account data for the life of the account and 2 years after closure for legal, audit, and fraud purposes; security and access logs for 12 months; support records for 2 years; analytics in aggregated or pseudonymized form. Certain records may be kept longer where law requires. On-chain data persists on the blockchain indefinitely (§5).
9. Your rights
Subject to the GDPR and equivalent laws, you may request: access; rectification; erasure; restriction; objection; data portability; and withdrawal of consent (without affecting prior processing). You will not be subject to solely automated decisions producing legal or similarly significant effects. Contact privacy@wen.live. You may lodge a complaint with your supervisory authority; for Estonia this is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee), or you may use the authority in your country of residence.
10. Security
We use encryption in transit and at rest, hashed passwords, TOTP 2FA, refresh-token rotation with revocation, access controls, and monitoring. No system is perfectly secure; safeguard your credentials, your 2FA device, and any exported keys. wen will never ask you for your password, 2FA codes, or exported keys.
11. Telegram mini app
When you use wen inside Telegram, we receive the data Telegram provides on your authorization: typically your Telegram user ID, username, and language. We do not receive your phone number or your Telegram message history. Your use of Telegram itself is governed by Telegram's own Privacy Policy and Terms, which we do not control.
12. Cookies and similar technologies
The web app uses strictly necessary cookies and local storage for login sessions and security, and, where required with your consent, analytics cookies. Details and controls: wen.live/legal/cookies.
13. Children
The Web Services are not directed to persons under 18 (or the age of majority where you live, if higher). We do not knowingly collect data from minors; if you believe a minor has used the Web Services, contact privacy@wen.live and we will delete the data.
14. California residents (CCPA/CPRA)
California residents have the rights to know/access, delete, correct, and to opt out of "sale" or "sharing" of personal information and to limit use of sensitive personal information. wen does not sell or share personal information as defined by the CPRA and does not use sensitive personal information for purposes requiring a right to limit. We do not discriminate against you for exercising rights. Submit requests to privacy@wen.live; you may use an authorized agent.
15. United Kingdom
For UK users this Policy operates under the UK GDPR and Data Protection Act 2018; the supervisory authority is the Information Commissioner's Office (ICO). UK representative, if appointed: Blockmob Labs Limited (United Kingdom), contact privacy@wen.live.
16. Global availability and your local law
The Web Services are provided from Estonia and are accessible worldwide. Crypto products are regulated differently in different countries, and some features may be unavailable, restricted, or unlawful where you live. You are responsible for ensuring your use of the Web Services complies with the laws of your jurisdiction. We may process IP and region data (§3) to meet our own legal obligations, including sanctions compliance, and we may restrict access where the law requires us to.
17. Changes
We will post updates here with a new "Last updated" date and provide additional notice of material changes.
18. Contact
AxonTech OÜ, Harju maakond, Tallinn, Kesklinna linnaosa, Tornimäe tn 5, 10145 · privacy@wen.live · DPO: privacy@wen.live