Privacy Policy
1. Who we are
Wenlong ("we", "us") operates the trading interface at wenlong.io and the Telegram Mini App. Wenlong is an interface to third-party decentralized infrastructure: your funds live in your own account on the Hyperliquid exchange, and your keys stay in your own wallet. For anything in this policy, contact us via Telegram: @whenlongbot.
2. What we collect
- Wallet addresses. Your TON and/or EVM wallet addresses, which you share by logging in. Blockchain addresses and their transaction history are public by design.
- Telegram account basics — only if you log in with Telegram: your Telegram ID, username, and display name, processed through our authentication provider (Privy). We do not see your phone number or contacts.
- TON login proof. If you log in with a TON wallet, we receive a cryptographic proof of address ownership (TON Connect
ton_proof/ signed data). We never receive your keys. - Service ledgers. Referral relationships, referral program balances, and season points are recorded against your wallet address to run those programs.
- Technical logs. Standard web-server logs (IP address, user agent, timestamps) and browser security reports (CSP), kept briefly for security and debugging, then rotated.
3. What we never collect
- Seed phrases, private keys, or wallet backups — never, in any form.
- Custody of funds: deposits, trades, and withdrawals settle in your own accounts.
- Identity documents. We have no KYC process.
- Advertising identifiers or cross-site tracking profiles.
4. How trading data flows
Market data, your positions, orders, and balances are read by your browser directly from Hyperliquid's public API. Orders you place are signed by a restricted agent key that can only trade — it cannot withdraw your funds. That key is derived and used inside a secure hardware enclave (AWS Nitro, attested); it never exists on our servers in plain form.
5. Third-party services
Running Wenlong involves these processors, each with its own privacy policy:
- Hyperliquid — the exchange where your account and trades live (public ledger).
- Privy — authentication (Telegram login and embedded EVM wallets).
- Telegram — if you use the Mini App or Telegram login.
- TON Connect wallets (Tonkeeper and others) — if you log in with TON.
- STON.fi / Omniston and Relay — swap and funding routes you choose to use.
- TradingView — the embedded chart (isolated in its own frame).
- Cloudflare — network security, DDoS protection, and cookieless analytics.
6. Cookies and local storage
We use browser storage for essentials only: your login session, language, and interface preferences. We do not use advertising cookies. The embedded TradingView chart sets its own cookies inside its isolated frame under TradingView's policy.
7. Where data lives and how long
Our servers are located in the European Union (Finland and Germany). Technical logs are rotated on a short schedule. Referral and points ledgers are kept for as long as those programs run. Authentication sessions expire automatically.
8. Your choices and rights
- You can use Wenlong with a TON wallet only — no Telegram account needed, no email, no phone.
- You can disconnect your wallet and stop using the service at any time.
- You can ask us to delete off-chain data tied to your address (e.g. referral/points records) via @whenlongbot. Note that on-chain and exchange-ledger data is public infrastructure we do not control and cannot erase.
9. Security
All traffic is encrypted (TLS). Trading keys are confined to attested secure enclaves. Signing requests are authenticated and rate-limited. Secrets held server-side are encrypted at rest in backups. No system is perfectly secure — never share your seed phrase with anyone, including anyone claiming to be Wenlong support. We will never ask for it.
10. Children
Wenlong is not intended for anyone under 18.
11. Changes
We may update this policy as the service evolves. The date at the top reflects the latest version; material changes will be visible on this page.
See also our Terms of Use.