This Privacy Policy describes how APYbot ("we", "the Service") collects, uses, stores, and protects your personal data when you interact with the @DeFi_APY_bot Telegram bot and associated web endpoints at apybot.io.
We are strictly committed to data minimization, transparency, and full compliance with international data protection laws, including the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA).
We collect only the minimal technical data strictly required to operate and maintain the Service:
| Data Type | Source | Purpose |
|---|---|---|
| Telegram User ID | Telegram API | Unique identifier to link your account and settings |
| Telegram Username | Telegram API | Displayed in admin status/digest logs and support interactions |
| Watched Assets List | User input (/watch) |
Stored in DB to deliver personalized APY spike alerts |
| Alert Threshold Setting | User input (/settings) |
Personalizes alert trigger sensitivity (e.g., 5% or 10% change) |
| Subscription Tier & Expiry | Payment flows | Enforces Free vs. Paid plan limits and access durations |
| On-Chain Transaction Hashes & Sender Addresses | Alchemy Webhook / Viem | When paying with cryptocurrency (EVM/TRON), public txHash and from address are logged to verify payment and prevent replay attacks |
| Telegram Stars Payment Records | Telegram API | Verification of in-app subscription status and renewals |
| Sent Alert History | Automated engine | Tracks delivered notifications to enforce 24-hour cooldowns and prevent spam |
We process collected technical data exclusively for the following operational purposes:
We never sell, rent, monetize, or transfer your personal data to advertisers or data brokers.
| Data Category | Retention Policy |
|---|---|
| Account Profile & Watchlist | Retained while active; permanently wiped upon /delete |
Alert History (sent_alerts) |
Automatically purged after a 90-day rolling window |
Pool APY History (pool_apy_history) |
Automatically purged after a 30-day rolling window |
Payment Records (crypto_payments) |
Retained for up to 2 years strictly for tax, accounting, and anti-fraud verification |
To deliver reliable real-time monitoring, APYbot integrates with secure, industry-standard infrastructure providers:
We employ robust technical controls to secure your data against unauthorized access:
.env) and never committed to source code.If you reside in the European Economic Area (EEA), United Kingdom, or California, you hold complete control over your data:
/delete command to the bot at any time. This action is self-service, immediate, and irreversible./unwatch, /watch) and threshold preferences (/settings) autonomously inside the bot./cancel or stopping the bot.APYbot operates primarily as a Telegram bot and minimal static web portal. We do not use advertising cookies, third-party tracking pixels, or cross-site behavioral analytics on our landing or payment pages.
The Service is intended solely for individuals aged 18 and older. We do not knowingly collect or solicit data from minors under 18. If you believe a minor has accessed the Service, please contact support for immediate account removal.
We reserve the right to revise this Privacy Policy periodically to reflect infrastructure or regulatory changes. Material revisions will be broadcast to active users inside the bot. Continued interaction with the bot after notification signifies acceptance of the updated terms.
For data subject access requests, GDPR/CCPA inquiries, or privacy-related questions: