BeWhale Privacy Policy
Last updated: 9 August 2026
1. Who we are
BeWhale is the data controller for personal data processed through BeWhale — the BeWhale Telegram Mini App, the BeWhale web application (hub.bewhale.app), and the websites bewhale.app and bewhale.pro (the “Service”).
Contact for privacy matters: info@bewhale.app
We process personal data in accordance with applicable data-protection law, and applicable local law where it grants you additional rights.
2. Personal data we collect
Account data. When you sign in via Telegram (in the Mini App or through the Telegram login widget): your Telegram user ID, username, display name, profile photo, and language setting. When you sign in with Google or Apple: the identifier and basic profile information those providers return, including the email address they release to us — which, for Apple, may be a private relay address. When you register with an email address and password: your email address and a cryptographic hash of your password (we never store the password itself). Where you use more than one of these methods, we link them to a single account.
Wallet and portfolio data. Public blockchain wallet addresses you connect (read-only), and the publicly available on-chain data associated with them (balances, tokens, transaction history). We never collect private keys or seed phrases.
Payment data. Records of purchases and subscriptions (product, amount, timestamp, payment method). Telegram Stars payments are processed by Telegram. Cryptoasset payments are made from a wallet you control to an address we publish for the order, and are recorded permanently on public blockchains — including the sending address, which we retain as the reference for that payment and for any refund.
Usage and content data. Your in-app activity (cards owned, market activity, game progress, leaderboard standing, settings), the messages you send to AI features and the responses generated, and support correspondence.
Technical data. Device and browser type, IP address, approximate location derived from IP (used among other things to enforce territorial restrictions), timestamps, and diagnostic logs.
Analytics and attribution data. Usage events collected through Google Tag Manager and Google Analytics 4, both in the browser and — for some events — sent from our servers to Google Analytics against your account identifier. Our marketing site also records the referral code you arrived with — in a first-touch bw_ref cookie and a matching entry in your browser’s local storage — so that a referral can be credited when you later create an account. The first code recorded is kept: a later invite link does not replace it, and once an account exists its referrer cannot be changed.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing the Service: accounts, portfolio tracking, cards, games, subscriptions | Contract |
| Processing payments and preventing payment fraud | Contract; legitimate interests |
| Operating AI features (processing your prompts and portfolio context to generate responses) | Contract |
| Enforcing eligibility and territorial restrictions; sanctions screening | Legal obligation; legitimate interests |
| Service analytics, performance, and product improvement | Legitimate interests; consent where required for analytics cookies and similar technologies. Where consent is required we ask before any optional cookie is set, and you can change or withdraw your choice at any time via “Cookie settings” in the footer. |
| Security, abuse and fraud prevention | Legitimate interests |
| Referral attribution and reward crediting | Contract; legitimate interests |
| Marketing communications (if any) | Consent |
| Legal compliance, accounting, disputes | Legal obligation; legitimate interests |
We do not use personal data to make solely automated decisions producing legal or similarly significant effects.
4. AI processing
The messages you send to AI features, together with limited context (such as your connected portfolio composition), are processed to generate responses by Amazon Web Services (Amazon Bedrock), acting as our processor. If that service is unavailable, requests may fall back to an alternative AI infrastructure provider engaged on equivalent terms. We also use an application-monitoring provider, which receives traces of AI requests and responses so we can debug faults and monitor reliability. The current list of these providers is available on request at info@bewhale.app.
We do not permit these providers to use your content to train their models.
Your AI conversations are stored as part of your chat history and retained for 12 months.
5. Who we share data with
- Processors / service providers: cloud hosting and AI inference (Amazon Web Services), analytics (Google), a fallback AI infrastructure provider and an application-monitoring provider (see §4), customer-support tooling, and email delivery. We will name any of these on request at info@bewhale.app.
- Market and blockchain data providers: we query third-party data sources — including Arkham, CoinGecko, TonAPI, and public block explorers — about the wallet addresses and assets shown in your portfolio.
- Telegram: by the nature of a Mini App, Telegram processes data about your use as an independent controller under its own privacy policy. Where we send you in-app or bot notifications, they are delivered through Telegram.
- Blockchain networks and marketplaces: transactions you initiate, and payments and prizes we send to your address, are public and permanent by design.
- Authorities: where required by law, or to establish or defend legal claims.
- Corporate events: a buyer or successor in a merger, acquisition, or restructuring (including transfer to a group entity), under confidentiality obligations.
We do not sell personal data.
6. International transfers
Our infrastructure is hosted primarily in the Asia Pacific (Singapore) region of Amazon Web Services, and some AI inference is performed in the United States. Other providers operate in further countries. Where personal data is transferred internationally, we use safeguards recognised by applicable data-protection law — adequacy decisions where available, otherwise approved standard contractual clauses or equivalent transfer mechanisms.
7. Retention
We keep personal data only as long as needed:
- Account data — for the life of your account. When you delete your account we remove the data that identifies you straight away, and keep only a stripped record with no identifying details so that referral and account-history links do not break. Residual copies persist in our encrypted backups for up to 90 days.
- Payment and tax records — 6 years from the end of the relevant accounting period, because tax law requires it. These survive account deletion, and for cryptoasset payments they include the wallet address the payment was sent from, which is also the address any refund would go to.
- Diagnostic logs — 30 days, after which they are deleted automatically.
- Analytics data — 14 months, after which it is deleted by our analytics provider. The clock restarts if you are active again in that period.
- AI chat history — 12 months, and deleted when you delete your account.
We then delete or anonymise the data. On-chain data is public and permanent by nature and cannot be deleted by us.
8. Your rights
Subject to conditions in applicable law, you may: access your data; rectify it; erase it; restrict or object to processing; receive a portable copy; and withdraw consent where processing is based on consent. To exercise rights, contact info@bewhale.app. You may also complain to your local supervisory authority.
9. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit, access controls, and segregated environments. No system is perfectly secure; notify us immediately at info@bewhale.app of any suspected compromise of your account.
10. Children
The Service is for adults aged 18+. We do not knowingly process children’s data; if you believe a child is using the Service, contact us and we will delete the account.
11. Cookies and similar technologies
The web application and websites use cookies and similar technologies. Where we say “cookie” below we also mean equivalent storage on your device, such as your browser’s local storage, which we use for the referral code described in the table. They fall into two groups.
Strictly necessary — always active, no consent needed. These are required to deliver what you asked for, and the Service does not work without them:
| Cookie | Purpose | Duration |
|---|---|---|
| Session and sign-in cookies | Keep you signed in and secure your session | Session to 30 days |
| Preference cookies | Remember settings such as your language | Up to 12 months |
bw_ref (cookie and local storage) | Records the invite code you arrived with on our marketing site, so that the person who invited you receives their referral credit and you receive any joining bonus. First-party only: never shared with third parties, never used for advertising, profiling, or tracking you across other websites. | Cookie: 30 days. A matching entry is also kept in your browser’s local storage, which has no fixed expiry and restores the cookie if it lapses — so attribution can persist until you clear your browser’s site data. |
bw_ref_app, bw_ref_src | Carry the same invite code, and which page it came from, inside the web application, so the referral can be credited when your account is created. First-party only. | 30 days |
Optional — only with your consent. Analytics and marketing cookies, described in the table in section 3. Where consent is required, we ask before these are set, and you can change or withdraw your choice at any time via “Cookie settings” in the footer.
You can also control cookies via your browser settings; blocking strictly necessary cookies may break sign-in.
12. Changes
We may update this policy. Material changes will be notified in-app or by other reasonable means before they take effect.
Data controller: BeWhale.