Privacy Policy
Last updated: July 16, 2026
This policy explains, directly, what personal data PoweX collects, what we use each type for, and what rights you have over it. We wrote this to reflect exactly what the system does today — no generic language copied from another product.
1. Data we collect
- Account identification: email (web signup) or Telegram ID/username (bot signup).
- Credentials: your password is stored hashed (never in plain text); your withdrawal PIN is also stored hashed; your 2FA secret is stored encrypted.
- Verification data (KYC): when you choose to raise your withdrawal limits, we collect the name, country, document type and document number you type into that form. We do not collect document images.
- Transaction data: deposits, withdrawals, swaps, internal transfers, wallet addresses used, amounts and timestamps — needed for the account to function and for anti-money-laundering obligations.
- Session/device data: IP address, browser or app user-agent, and login time — used for the "Active Sessions" screen in Settings, and to alert about logins from unrecognized locations.
2. What we do NOT collect
We do not use third-party cookies or tracking scripts for advertising (see Cookie Policy for technical details). We never sell personal data to third parties, under any circumstances.
3. What we use your data for
- Operate your account: process deposits, withdrawals, swaps, and display your history and balance;
- Security: detect suspicious logins, enforce 2FA/antiphishing, investigate fraud;
- Legal compliance: anti-money-laundering (AML) prevention and response to applicable regulatory obligations;
- Support: respond to tickets and requests you submit via the Support Center;
- Essential account communication: operation confirmations, security alerts — marketing notifications have separately configurable preferences.
4. Who we share data with
We share strictly necessary data with: the custody infrastructure provider (to process on-chain deposits/withdrawals on your behalf), technical infrastructure providers (hosting, database), and competent authorities when required by law or a valid court order.
5. How long we keep it
Account and transaction data is kept while your account is active, and for an additional period after closure when required by legal obligation (e.g. accounting and anti-money-laundering records typically have a minimum legally defined retention period).
6. Your rights
You can request access to your data, correction of inaccurate information, or export of your history (already available directly under History → Export, no request needed). For account deletion requests or other questions about your data, use the Support Center — we handle these manually while there is no dedicated self-service flow for it yet.
7. Data security
Passwords and PINs are never stored in plain text. Communication between your device and our servers is encrypted (HTTPS). Internal access to sensitive data is restricted by role within the team.
8. Contact
Questions about this policy can be sent via the Support Center.