wen.
legalprivacydocs

wen Privacy Policy - Web App & Telegram Mini App

Last updated: 13 August 2026 · Effective: 13 August 2026

Applies to: wen.live web application and the wen Telegram mini app (together, the "Web Services").

Contents
  1. 1. Who we are
  2. 2. Summary
  3. 3. Data we collect, why, and on what legal basis
  4. 4. Non-custodial keys: what wen can and cannot access
  5. 5. Blockchain data: limits on erasure and pseudonymity
  6. 6. How we share data
  7. 7. International transfers
  8. 8. Retention
  9. 9. Your rights
  10. 10. Security
  11. 11. Telegram mini app
  12. 12. Cookies and similar technologies
  13. 13. Children
  14. 14. California residents (CCPA/CPRA)
  15. 15. United Kingdom
  16. 16. Global availability and your local law
  17. 17. Changes
  18. 18. Contact

1. Who we are

The Web Services are operated by AxonTech OÜ, an Estonian private limited company, registry code 17430331, registered address Harju maakond, Tallinn, Kesklinna linnaosa, Tornimäe tn 5, 10145 ("wen", "we", "us"). For the purposes of the EU General Data Protection Regulation (GDPR), we are the data controller of the personal data described in this Policy.

Privacy contact / Data Protection Officer: privacy@wen.live.

2. Summary

wen is a non-custodial social trading application. We never take custody of your crypto assets and cannot move, withdraw, or freeze funds in your wallet. Balances shown in wen are read live from public blockchains and trading venues. We collect the minimum personal data needed to operate your account, secure it, run social and trading features, comply with law, and improve the Web Services. We do not sell your personal data. The Web Services are available worldwide; you are responsible for ensuring that your use of them is lawful where you live.

3. Data we collect, why, and on what legal basis

CategoryExamplesPurposeGDPR legal basis
Account & identityEmail, password hash, username, profile detailsCreate and manage your account; login; supportContract (Art. 6(1)(b))
Security credentialsTOTP 2FA secret, session and refresh tokens, encrypted key-export materialTwo-factor authentication; secure optional key export; session securityContract; legitimate interests in security (6(1)(b)/(f))
Wallet & on-chain dataWallet addresses, transaction hashes, public on-chain balances and historyEnable trading; display balances; core functionalityContract (6(1)(b))
Trading activitySpot orders, perps positions, copy-trading settings and limits, resultsExecute and display trades; operate copy tradingContract (6(1)(b))
Referral dataWho referred you, users you referred, reward accrualsOperate the referral programContract; legitimate interests (6(1)(b)/(f))
Gamification dataXP, rank, streaks, quests, wheel/chest outcomes, badges, leaderboardsOperate rewards and social featuresContract (6(1)(b))
User-generated contentChat messages, theses, team content, profile media, reputationSocial features; moderation; safetyContract; legitimate interests (6(1)(b)/(f))
Device & usage dataBrowser/OS type, app version, feature usage, crash and error logsReliability, security, product analyticsLegitimate interests; consent where required (6(1)(f)/(a))
Network dataIP address, timestamps, approximate region derived from IPSecurity, fraud and abuse prevention, sanctions screening, legal complianceLegitimate interests; legal obligation (6(1)(f)/(c))
Telegram identifiersTelegram user ID, username, language (mini app only)Authenticate and operate the mini appContract (6(1)(b))
CommunicationsSupport requests and related correspondenceProvide supportContract; legitimate interests (6(1)(b)/(f))
Marketing preferencesConsent records, notification opt-insSend communications you opt intoConsent (6(1)(a))

We do not intentionally collect special-category data (health, religion, etc.). Please do not post it in chats or profiles.

4. Non-custodial keys: what wen can and cannot access

Your wallet is created and secured through our embedded-wallet provider, Privy. Private keys are managed such that wen does not hold, control, or have access to your private keys and cannot move or withdraw your funds. Optional key export is protected by your password and TOTP 2FA and is end-to-end encrypted in your browser; our servers relay ciphertext they cannot read. For perpetual futures executed on an independent third-party venue, wen uses an agent key that can place orders but is technically incapable of withdrawing funds.

5. Blockchain data: limits on erasure and pseudonymity

Blockchains are public, immutable, and decentralized. When you transact, data such as wallet addresses, amounts, timestamps, and transaction hashes are recorded on public ledgers that wen does not control and cannot alter or delete. Consequently:

  • We cannot erase, rectify, or restrict on-chain data. GDPR erasure and rectification rights apply to personal data held in wen's own systems, not to the blockchain itself.
  • Wallet addresses are pseudonymous, not anonymous. On-chain activity may become linkable to you, particularly once an address is associated with your account or shared publicly.
  • Anyone can view public on-chain data using block explorers and analytics tools.

6. How we share data

We use service providers acting as processors under Art. 28 GDPR data-processing agreements, and disclose data only as needed:

  • Embedded wallet / key management: Privy
  • Perps execution venue provider (agent-key order routing)
  • Hosting and infrastructure: EEA-based cloud infrastructure
  • Analytics and error reporting: none; no third-party analytics or crash-reporting provider receives your data, and diagnostics stay in wen's own systems
  • Email and communications: Resend
  • Customer support tooling: none; support is handled by email
  • Compliance, sanctions, and fraud screening: performed in-house against publicly available sanctions lists, including the EU consolidated list and the OFAC SDN list; no third-party screening provider receives your data
  • Telegram, for mini-app users (see §11)

We may disclose data to regulators, law enforcement, or courts where legally required, and to advisors or an acquirer in a corporate transaction, under confidentiality. We do not sell personal data.

7. International transfers

We operate from the EEA. Where providers process data outside the EEA or your region, we rely on European Commission adequacy decisions or Standard Contractual Clauses with supplementary measures as required. Details are available from privacy@wen.live.

8. Retention

We keep personal data only as long as necessary: account data for the life of the account and 2 years after closure for legal, audit, and fraud purposes; security and access logs for 12 months; support records for 2 years; analytics in aggregated or pseudonymized form. Certain records may be kept longer where law requires. On-chain data persists on the blockchain indefinitely (§5).

9. Your rights

Subject to the GDPR and equivalent laws, you may request: access; rectification; erasure; restriction; objection; data portability; and withdrawal of consent (without affecting prior processing). You will not be subject to solely automated decisions producing legal or similarly significant effects. Contact privacy@wen.live. You may lodge a complaint with your supervisory authority; for Estonia this is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee), or you may use the authority in your country of residence.

10. Security

We use encryption in transit and at rest, hashed passwords, TOTP 2FA, refresh-token rotation with revocation, access controls, and monitoring. No system is perfectly secure; safeguard your credentials, your 2FA device, and any exported keys. wen will never ask you for your password, 2FA codes, or exported keys.

11. Telegram mini app

When you use wen inside Telegram, we receive the data Telegram provides on your authorization: typically your Telegram user ID, username, and language. We do not receive your phone number or your Telegram message history. Your use of Telegram itself is governed by Telegram's own Privacy Policy and Terms, which we do not control.

12. Cookies and similar technologies

The web app uses strictly necessary cookies and local storage for login sessions and security, and, where required with your consent, analytics cookies. Details and controls: wen.live/legal/cookies.

13. Children

The Web Services are not directed to persons under 18 (or the age of majority where you live, if higher). We do not knowingly collect data from minors; if you believe a minor has used the Web Services, contact privacy@wen.live and we will delete the data.

14. California residents (CCPA/CPRA)

California residents have the rights to know/access, delete, correct, and to opt out of "sale" or "sharing" of personal information and to limit use of sensitive personal information. wen does not sell or share personal information as defined by the CPRA and does not use sensitive personal information for purposes requiring a right to limit. We do not discriminate against you for exercising rights. Submit requests to privacy@wen.live; you may use an authorized agent.

15. United Kingdom

For UK users this Policy operates under the UK GDPR and Data Protection Act 2018; the supervisory authority is the Information Commissioner's Office (ICO). UK representative, if appointed: Blockmob Labs Limited (United Kingdom), contact privacy@wen.live.

16. Global availability and your local law

The Web Services are provided from Estonia and are accessible worldwide. Crypto products are regulated differently in different countries, and some features may be unavailable, restricted, or unlawful where you live. You are responsible for ensuring your use of the Web Services complies with the laws of your jurisdiction. We may process IP and region data (§3) to meet our own legal obligations, including sanctions compliance, and we may restrict access where the law requires us to.

17. Changes

We will post updates here with a new "Last updated" date and provide additional notice of material changes.

18. Contact

AxonTech OÜ, Harju maakond, Tallinn, Kesklinna linnaosa, Tornimäe tn 5, 10145 · privacy@wen.live · DPO: privacy@wen.live

Privacy PolicyPrivacy Policy (mobile app)Terms of ServiceTerms of Service (mobile app)CookiesDelete your accountRisk disclosureBack to wen