Security and permissions

What Aped can and cannot access. Full legal text lives in the privacy policy.

What we store

Aped runs only on axiom.trade and connects to https://api.sol-aped.com to authenticate users and sync demo trading data.

  • Telegram auth fields — Telegram user ID and public profile fields used for login (such as username and first name when provided by Telegram).
  • Demo trading data — balances, simulated trades, positions, orders, strategies, challenges, analytics snapshots, and account settings.
  • Local extension storage — session token (JWT) and selected UI preferences on your device.
  • Optional diagnostics — if you submit a bug report, you may attach diagnostic details you choose to send.

Chrome permissions (why)

  • Storage — JWT session and local UI preferences for the extension.
  • Host access to axiom.trade — inject the paper-trading panel and read the market cap shown in the DOM for simulated fills.
  • Host access to api.sol-aped.com — authenticate and persist demo account data listed above.

What we never do

  • Access private keys, seed phrases, wallet credentials, or wallet funds
  • Request wallet connection or signing, or broadcast Solana transactions
  • Access Axiom login credentials
  • Read Telegram messages beyond the one-time login code you paste into the extension
  • Sell or share your trading data as a brokerage product

Demo disclaimer

All balances and PnL are simulated for practice and education. Not financial advice. Report issues via support or @sol_aped_bot.