Three details, then you're searching loads from Telegram.
Your password (and your code, if you enter one) are encrypted in transit and at rest. We log in to CX on your behalf, save the session cookie, and discard the code. We never store any long-term 2FA secret: for authenticator apps we never see the secret behind your QR, and for mobile we only ask you for each texted code as it's needed. Reply /forgetme in Telegram any time to wipe everything.
And the bot never bids without you. Every quote starts with you tapping a button on a specific load, and odd-looking prices get a second confirm before anything is submitted. The full plain-English rundown is at how we protect your login.
Why this is allowed. TEG's terms (Courier Exchange's parent) permit automated tools as long as they stay within human-equivalent request rates, that's clause (i) of their T&Cs. This bot rate-limits every account to enforce it: at least 60 seconds between searches, no more than ~200 searches per day, ~30 quote submissions per day, and polling intervals never tighter than 5 minutes. Strictly slower than a determined human refreshing the CX web app by hand. If you ever hit a limit the bot will tell you, and you can DM /limits to see your current usage.