Folybot

Folybot · Privacy policy

Version of 10 October 2026.

1. Who we are and how to reach us

Folybot is the Telegram bot @folydevbot and the website https://folybot.app. The controller of your personal data is Taras Romaniuk, an individual, Tvorcha St 16, 79037 Lviv, Ukraine (“we”). As a data subject, you can reach us with any question about your data by email at tomoonkee@gmail.com or in Telegram: https://t.me/folybot.

2. What we store

We do not read your conversations: the bot only sees what you give it. When you mention the bot in a shared chat, everyone in that chat sees your message and the bot’s short reply; the reminder itself comes only to you, unless you share it on a shared card. Messages you send with /paysupport or /report are forwarded to us in Telegram and not stored; only a daily count remains. The database is kept on an encrypted disk, and backups are encrypted with a separate key.

Other people’s messages, names and photos reach us only when you pass them to the bot yourself, and only you see them (the exception is the Telegram id and Telegram name of those who tap a button on a shared card, a time picker or a call card: everyone who sees the card sees them, as said above); your team also sees a deal person’s name, @username and photo, and in the deal’s history your calls with that person (date and length) and that you forwarded the bot their messages, without the text. Those people have the same rights as you and can reach us at the contacts above. We do not intentionally collect sensitive data (health, religious or political views and the like), so please don’t send it to the bot; if such data ends up in a reminder, it is processed only for that reminder.

3. Why, and on what legal basis

Reminders (voice notes put off for later included), meetings, shared cards, assignments, time pickers, groups, your list of people, deals and teams, the digest, invites, payments and subscription records are needed to perform our contract with you, the Terms of use (Art. 6(1)(b) GDPR; Art. 11(1)(3) of the Law of Ukraine “On Personal Data Protection”). AI features run only with your separate consent (Art. 6(1)(a) GDPR; Art. 11(1)(1) of the Law). Encrypted backups, AI call records for cost control, the deletion record and time phrases kept to improve recognition rest on our legitimate interest in running the service reliably, securely and affordably (Art. 6(1)(f) GDPR; Art. 11(1)(6) of the Law). When someone who doesn’t use Folybot taps a button on a shared card or a time in a time picker, we keep their name and Telegram id on the card owner’s legitimate interest in the card showing who took it on or what was chosen (the same articles).

Nothing is used for advertising, sold, or used to train models. Your Telegram id is needed for the bot to work, and the service is impossible without it; Google and AI are optional, and without them only meetings and AI features are unavailable. We make no decisions about you based solely on automated processing that have legal or similarly significant effects: AI only suggests times, titles and texts, and you decide. You may use Folybot if you meet Telegram’s age requirements.

4. Who processes it

Processors that handle data on our behalf under a data processing agreement:

Cerebras, Groq and OpenAI are in the USA, so data leaves the EU and Ukraine. These transfers are protected by the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914), which are part of the Cerebras, Groq and OpenAI data processing agreements; write to us for a copy of these safeguards.

Independently, under their own rules, data is processed by Telegram, the messenger the bot runs in (Telegram’s policy), and by Google, Calendar and Meet, only when you connect Google (Google’s policy).

5. How long

The /forget command or “Delete everything” in “My tasks” cancels your future meetings (attendees are notified, and Google emails them the cancellation), disconnects Google, stops the subscription and deletes all your data from the bot at once. The encrypted backups drop it within 30 days. In each of your teams that has others in it, the deals stay with the team: the ones you handled go to the owner (or, if you are the owner, the team goes to its longest-standing member), the deal’s person stays as their name, @username and id, your notes on deals are deleted, and the deals’ history keeps you as a “former member” with no id. A team you are alone in is deleted with its deals. People who came by your link are no longer linked to you. So that a restore from a backup cannot bring your data back, we keep only your Telegram id and the deletion date for 35 days; AI call records stay, no longer linked to you, until their 90 days run out.

6. Your rights

As a data subject, you have the right to know what data about you we process, to access it and get a copy (“My tasks” → Settings → “Export to CSV”), to rectify it, to erase it (/forget or “Delete everything”), to restrict its processing, to object to processing based on legitimate interest (for example, to keeping time phrases) and to withdraw any consent. Withdrawing consent does not affect the lawfulness of processing before it. You can withdraw AI consent on its own, any time: /settings or “My tasks” → Settings → “AI features”; from then on the bot sends nothing to the AI, and everything else keeps working.

For anything else, write to us at tomoonkee@gmail.com or in Telegram; we reply within one month. You can complain to the Ukrainian Parliament Commissioner for Human Rights (ombudsman.gov.ua) or to the data-protection authority of the EU country where you live or work.

7. Google data

Folybot’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

When you connect Google as a meeting organizer, we receive your Google email, so the bot knows which calendar to work in, and permission to create, change and cancel only the events Folybot creates (calendar.events.owned). We don’t read the other events in your calendar. From someone who agrees to a meeting by signing in with Google, we receive only their email address and name (openid, email, profile).

All of this is used only to create the event with a Meet link in the organizer’s calendar, add as attendees the people who agreed and those the organizer invited by email, remove the people the organizer removed, show their names on the card in the chat and to the organizer, show the organizer, and only the organizer, who of those invited in the event itself accepted or declined (the bot reads these answers from the event’s attendee list; when someone who agreed through Folybot changes their answer in Google, the answer they gave in Folybot changes too), change the event’s title, time or length or cancel it when asked, and keep the Telegram card current: until an hour after the start, the bot re-reads the event every few minutes. If you use Folybot and agree to a meeting, we remember the email you agreed with, so your next “Agree” is one tap.

Someone who accepts in the Google event itself is added to the organizer’s people with the email and name the event shows. Only the organizer sees them, they never go to AI, and the organizer’s team never sees the email; the team sees the name only if the organizer adds a deal with that person to the team. For this we get nothing from Google beyond the event’s attendee list, which the bot already re-reads.

We use Google user data only to provide the meeting features this section describes. We don’t sell it, share it with anyone beyond what this section describes, or make aggregated or anonymized data from it. Our hosting provider Hetzner (Finland, EU) stores it on our behalf, and attendees’ emails go to Google as event invitations. It is never used or transferred for advertising of any kind, including targeted, personalized, retargeted or interest-based ads, never passed to data brokers or information resellers, never used to determine creditworthiness or for lending, and not read by humans unless you ask us to, security requires it or the law demands it.

We do not use data received from Google Workspace APIs (here, Google Calendar), whether raw or aggregated, anonymized or derived from it, to develop, improve or train generalized or non-personalized AI or ML models, and we do not transfer it to anyone for that purpose; Folybot trains no AI or ML models at all. Event titles changed in Google Calendar, attendees’ emails and the names Google gives are never sent to AI. The only Google data that can reach AI is a call’s time. When someone replies in words about a call and the bot’s own rules can’t read the reply (another language, or a shift they don’t know, such as “an hour and a half later”), Cerebras gets the call’s current start and length, which may have been set in Google Calendar, to work out the new time. This happens only for that reply and only if its author consented to AI, and under Cerebras’s terms (section 4) it is not used for training.

This data travels only over HTTPS, is stored on an encrypted disk and in encrypted backups, and the calendar access token is used only by the bot’s server. Section 8, “How we protect your data”, describes these safeguards in detail.

Your Google email and token are kept until you disconnect Google (“My tasks” → Settings → Google) or delete your data (/forget or “Delete everything”). They are then deleted at once, and we revoke the token at Google. Removing Folybot’s access in your Google Account stops all calendar work. In the same Settings you can change or forget the email for “Agree” and switch the calendar to another Google account; the remembered email is deleted with the rest of your data.

Meeting data (the event link, and the emails and names of those who agreed) is deleted 365 days after the meeting’s start, once it has ended or been cancelled, and leaves the encrypted backups within 30 days. The event itself stays in the organizer’s Google Calendar until they delete it.

8. How we protect your data

Data is encrypted in transit. The website and the Google sign-in work only over HTTPS, and a request over plain HTTP is redirected to HTTPS. The bot talks to Telegram, Google and the AI services in section 4 over HTTPS as well. The website’s sign-in cookie is sent only over HTTPS and cannot be read by scripts on the page.

The database is stored on a disk volume encrypted with LUKS2 (AES-256). It holds everything listed in section 2, Google emails and calendar access tokens included, and profile photos are kept on the same volume. The encryption key can be read only by the server’s administrator account and is never copied into backups. Every night the server backs the database up and encrypts the copy with age to a key whose private half is kept off the server, so the server cannot read its own backups. They are kept for 30 days.

The calendar access token is the OAuth refresh token Google issues when an organizer connects Google Calendar. It is stored only on the encrypted volume and in the encrypted backups: it is never written to logs, shown in the app or included in the CSV export. Only the bot’s server process uses it, and for two things only: to get a short-lived token from Google to create, read, change or delete an event Folybot makes, and to revoke access at Google when you disconnect Google, switch accounts or delete your data. The short-lived token is never stored; it exists in memory for that one action. Someone who signs in with Google only to agree to a meeting gives us no token at all, just their email and name.

Each part of the system has only the access it needs to work. From Google, Folybot asks for the narrowest calendar scope that is enough, calendar.events.owned, and touches only the events it created, by their id (section 7). On the server, the bot runs as a separate system user that cannot log in and can write only to its own folder and the encrypted volume. The app’s keys, including the Google client secret, are in a file that only this user and the administrator can read.

The web app accepts connections only from the web server on the same machine, and the firewall lets in only web traffic and SSH. Only we, as the controller, can sign in to the server, over SSH with a key; password sign-in is turned off. Security updates install automatically, and repeated failed SSH sign-ins are blocked. Inside Folybot every request is checked against your Telegram account, so you see only your own data and your teams’ deals.

We keep only the data listed in section 2, for the periods in section 5, and don’t store the audio of voice notes or the images you send at all. Data received from Google, including event titles and attendees’ emails and names, is never sent to AI; the one exception, a call’s time, is explained in section 7. Server logs record technical events such as errors and counts, with Telegram ids and, for a failed Google call, the event’s id. They never contain the text of your messages or notes, photos, voice notes, email addresses or Google tokens, and the web server keeps no access log. The processors in section 4 work under data processing agreements, and the transfers to the USA are covered by the Standard Contractual Clauses described there.

If a personal data breach happens, we will report it to the supervisory authority within 72 hours of becoming aware of it, unless it is unlikely to put people’s rights and freedoms at risk. If it is likely to put your rights and freedoms at high risk, we will also tell you without undue delay. This is what Articles 33 and 34 GDPR require.

9. Changes

We will tell you in the bot before any material change to this policy, including any change in how we use Google user data.