Privacy Policy
Last updated: May 10, 2026
This Privacy Policy explains how MBOT Finance, a project of XPayr LLC, collects, uses, stores, and protects information when you use mbot.finance and related MBOT services.
1. Information we collect
We may collect the following categories of information:
Account data:
- email address;
- username;
- password hash;
- recovery-code hash;
- preferred language and theme;
- two-factor authentication status and encrypted 2FA secret if enabled.
Tenant and subscription data:
- tenant identifier;
- package and subscription status;
- payment order records;
- billing interval, currency, chain, wallet address, transaction hash, provider order identifiers, and payment metadata.
Exchange API data:
- Binance API key;
- encrypted Binance API secret;
- environment selection such as testnet or live;
- validation status;
- API key fingerprint and key-related event logs.
Bot and trading data:
- bot settings;
- selected symbols;
- mode, profile, capital limits, and risk settings;
- order, trade, grid, balance, and runtime snapshots;
- worker status and bot event logs.
Support and communication data:
- support ticket messages;
- contact form submissions;
- newsletter subscription records;
- notification preferences;
- Telegram bot token encrypted by MBOT if you choose to enable Telegram notifications;
- Telegram chat ID.
Technical data:
- IP address;
- browser and device data;
- request logs;
- authentication and security events;
- cookies or local storage used for login, preferences, security, and reliability.
2. How we use information
We use information to:
- create and secure your account;
- authenticate sessions;
- provide the dashboard;
- validate exchange credentials;
- operate Binance spot bot automation;
- enforce package limits;
- verify XPayr payments;
- display subscription and billing history;
- provide support;
- send in-app or Telegram notifications if enabled;
- monitor security and platform reliability;
- investigate abuse, fraud, or technical incidents;
- comply with legal obligations where applicable.
3. Exchange API secrets
MBOT stores exchange API secrets in encrypted form. API secrets are used only to sign authorized exchange requests required for the configured bot workflow.
You should never enable withdrawal permission for an API key used with MBOT. You should rotate keys if you believe a key was exposed, copied, shared, or compromised.
4. Payments and XPayr
MBOT may use XPayr payment sessions and webhook events to verify subscription status. Payment records may include wallet address, transaction hash, network, currency, amount, payment status, provider session ID, and related metadata.
MBOT uses this information to determine whether a package should be activated, renewed, expired, or shown as pending.
5. Cookies and local storage
MBOT uses essential cookies and browser storage to:
- keep users signed in;
- protect authenticated routes;
- remember language and theme preferences;
- store security state needed by the application;
- improve reliability and diagnose errors.
If analytics or marketing cookies are added later, MBOT should present an appropriate consent mechanism where required.
6. Sharing information
We do not sell your personal information.
We may share limited information with service providers when necessary to operate MBOT, including hosting providers, database infrastructure, payment infrastructure, Binance API endpoints, blockchain infrastructure, notification providers, security tools, and support tools.
We may disclose information if required by law, court order, legal process, security investigation, fraud prevention, or to protect the rights, safety, and integrity of MBOT, XPayr LLC, users, or third parties.
7. Data retention
We retain account, billing, bot, support, security, and audit records for as long as reasonably necessary to provide the service, comply with legal obligations, resolve disputes, enforce agreements, maintain accounting records, and protect platform security.
Some trading and payment records may need to be retained even after account closure for audit, tax, security, or dispute reasons.
8. Your choices
You may:
- update profile information;
- change language and theme preferences;
- disable or rotate Binance API keys;
- disable Telegram notifications;
- create or close support tickets;
- request account deletion where available and legally permitted.
Deleting an account does not automatically delete records that MBOT must retain for legal, accounting, security, fraud-prevention, or dispute-resolution reasons.
9. Security
MBOT uses technical and organizational controls intended to protect user data, including encrypted secret storage, authentication controls, tenant boundaries, route protection, and operational logs.
No internet-connected system is perfectly secure. You are responsible for protecting your email account, device, browser, password, recovery code, 2FA device, Binance account, and Binance API keys.
10. International users
MBOT may be accessed from different countries. By using MBOT, you understand that information may be processed in jurisdictions where MBOT, XPayr LLC, hosting providers, or infrastructure providers operate.
11. Children's privacy
MBOT is not intended for children or minors. Do not use MBOT if you are below the age of majority in your jurisdiction.
12. Changes
We may update this Privacy Policy as MBOT develops. The updated version will be posted on mbot.finance with a new effective date.
13. Contact
Privacy questions may be sent through the MBOT support area or the support contact published on mbot.finance.

