Skip to content
Open navigation

Legal

Privacy Policy

Last updated:

1. Overview

This Privacy Policy describes how the Service handles personal data. Because the Service reads your Telegram history — which may include people who never used the Service — we minimize what we store and encrypt sensitive credentials.

2. Data we process

  • Account data: your email, name, and authentication identifier from our login provider.
  • Telegram session: for Search Agents, an encrypted MTProto session string obtained via QR login. This is treated as our highest-sensitivity secret, encrypted at rest, decrypted only at the moment of use, and never shown back to you or any client.
  • Findings and records: structured data found by searches and records you approve or add, stored in your database. This may include third-party personal data.
  • Message content during a search: processed to produce findings and passed to our model provider. Unless you build the optional message archive below, we do not retain a browsable copy of your raw message history.
  • Message archive (optional): if you build the Full archive on the Activity page, messages from your chats — including messages other people sent — are stored in your own tenant database so searches and extraction can read history without re-reading Telegram. This may include third-party personal data. The archive lives only in your database: it is included in your exports, and it is destroyed when the database or your account is deleted.
  • Operational data: subscription/billing status, usage counters, and audit logs of sensitive actions.

3. How we use data

We use data to authenticate you, run searches, answer Reply Agent queries, enforce trial limits, process payments, and secure the Service. We do not sell your data.

4. Prompt-injection and content safety

Telegram message content is treated strictly as untrusted data, never as instructions to our systems. This protects your account and the integrity of search results.

5. Sub-processors

We rely on the following sub-processors to provide the Service:

Sub-processorPurposeData involved
Auth0 (Okta)Platform authentication / loginEmail, name, auth identifier
NeonDatabase hostingYour findings, records, and record types
Mem0Reply Agent knowledge retrievalKnowledge you provide to Reply Agents
VercelApplication hosting & computeAll request/processing traffic
LLM provider (via AI Gateway / Anthropic)Search and reply processingMessage content processed during searches and replies
StripeSubscription billing & paymentsBilling contact & payment status
ResendLifecycle email deliveryEmail address & notification content
TelegramConnected messaging platformChats read by Search Agents and messages handled by Reply Agents

6. Data retention and deletion

You can export or delete any database at any time. Deleting a database destroys the underlying data irreversibly. Closing your account destroys all of your databases. We retain minimal audit records of sensitive actions for security and support.

7. Your rights

Depending on your jurisdiction, you may have rights to access, correct, export, or delete personal data. Because you are the controller of the data in your databases, you exercise many of these rights directly through the Service; for others, contact the operator of this deployment.

8. Security

We encrypt session secrets and other high-sensitivity credentials at rest, scope every data access to the authenticated account, and write approved records only to databases belonging to that account.