Legal
Privacy Policy
Last updated 18 August 2026
This Privacy Policy explains what Why Protocol LTD (“WHY”, “we”, “us”) collects when you use whytradingbot.com, the WHY Partner Portal, the Telegram bot and related services (together, the “Services”), why we collect it, and the choices you have.
1. What we collect
- Account data — name or alias, email address, and a one-way hash of your password when you create a Partner Portal account.
- Exchange API credentials — if you choose to connect an exchange (currently Binance or Bybit), the API key and secret you provide. These are encrypted at rest with a key stored separately from the database, are never displayed back to you, and are used only to read your account and, where you have enabled it, to transmit trade instructions. We refuse keys with withdrawal permissions.
- Telegram data — your Telegram user ID and username when you interact with the bot.
- Usage and technical data — IP address, browser type, pages visited, timestamps and error logs, used for security (for example rate-limiting sign-in attempts) and to keep the Services running.
We do not collect payment card details on our own systems, and we never take custody of your funds or private keys.
2. How we use it
- To provide and secure the Services, including verifying your email with a one-time code and protecting accounts against brute-force sign-in.
- To operate automated trading on your connected exchange only where you have explicitly enabled it.
- To show you performance information and send you service messages (verification codes, security notices).
- To comply with legal obligations and to prevent abuse or fraud.
We do not sell personal data and we do not use it for third-party advertising.
3. Sharing
We share data only with processors that help us run the Services (hosting, email delivery for verification codes, the exchange you connect, Telegram) and where required by law. Each processor receives only what it needs.
4. Retention
Account data is kept while your account is active. Exchange credentials are deleted when you remove them from the portal or close your account. Security logs are kept for a limited period and then rotated.
5. Your rights
You may access, correct or delete your account data, and remove connected exchange credentials at any time from the portal. To exercise any other right, or to close your account entirely, contact us via the Telegram bot @Whytradingbot.
6. Security
Passwords are hashed with bcrypt, sessions use secure HttpOnly cookies, exchange credentials are encrypted at rest, and all traffic to the Services is served over HTTPS. No system is perfectly secure; if we become aware of a breach affecting your data we will notify you as required by law.
7. Changes
We may update this policy from time to time. The date at the top shows the current version; material changes will be announced through the Services.