> For the complete documentation index, see [llms.txt](https://www.degenbot.wiki/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://www.degenbot.wiki/help-and-account/security-and-privacy.md).

# Security and privacy

Protect your Telegram identity and avoid credential requests that do not belong in an alerts service.

### Use the verified access route

Open Degen through the official link provided with the product. Check the exact account identifier, not just a display name, logo, or unsolicited claim of being support.

Do not send money to an individual because they say it will activate alerts, recover a loss, or unlock a guaranteed return. Check account and billing issues through the purchase platform.

### Information you must not send

Do not share passwords, Telegram login codes, recovery codes, wallet seed phrases, private keys, exchange API secrets, or card details in a bot or support conversation.

An alerts-only service does not need permission to trade or withdraw from your exchange account. Older Ninja Bot linking instructions are not the current member setup process.

### Protect Telegram itself

Use Telegram's **Settings → Privacy and Security → Two-Step Verification** and review connected devices or active sessions. Keep your recovery email secure. Telegram's [official account-security guidance](https://telegram.org/faq#q-how-does-2-step-verification-work) explains the available controls.

Telegram states that bots can see messages you send to them and public profile information. Treat a bot conversation as communication with the service operator, not as a place to store secrets. See [Telegram's explanation of bot safety](https://telegram.org/faq#q-are-bots-safe).

### Privacy is more than deleting a chat

This guide is not Degen's privacy policy. The owner must publish the actual data collected, purposes, retention rules, support contact, and account-deletion process before presenting this as a complete production policy.

Do not assume that deleting a conversation deletes records held by the service, a payment provider, or another participant. For a data request, use the contact in the current privacy notice and share only what is needed to identify the account.

### Suspected compromise

Stop sharing information. Use the affected provider's official security settings to secure the account and remove access you do not recognise. If an exchange credential was exposed, revoke it through the exchange's own account settings.

Report impersonation or suspicious messages through official channels. Preserve relevant evidence without reposting secrets or personal details publicly.
