Folybot · Privacy policy
Version of 9 October 2026.
1. Who we are and how to reach us
Folybot is the Telegram bot @folydevbot and the website https://folybot.app. The controller of your personal data is Taras Romaniuk, an individual, Tvorcha St 16, 79037 Lviv, Ukraine (“we”). As a data subject, you can reach us with any question about your data by email at tomoonkee@gmail.com or in Telegram: https://t.me/folybot.
2. What we store
- Your Telegram id, name, username, language, consent record (date and version of this policy) and your separate AI consent: yes or no, its date and the version of the text you answered.
- Reminders: the time, your note on it (the comment with a forward or the context you add), the text you wrote to the bot or of a message you replied to or forwarded (yours or another person’s) up to 1000 characters, its author’s name, the chat title and a link to the message when the chat has one, and a short title of a long or forwarded text (made by AI or cut from the text itself; you can change it). When one message, written or said, holds several tasks (Pro with AI), the bot shows them as a list that lives only in its memory for up to 15 minutes; only what you save is stored, as ordinary reminders.
- Forwarded messages: when you forward a message to the bot (another person’s or your own), we keep its text up to 1000 characters (no photos or files), the chat title when Telegram gives one and when it was written, with the person it came from, even if you set no reminder: that is how the person’s card shows where they came from. Only you see them; when you have a deal with that person in a team of two or more, your teammates see in the deal’s history only that you forwarded the bot their message, and when, without the text.
- Contacts: the name, Telegram id and username of the authors of those messages and of the other person in a meeting, plus when you last opened “Prepare message” for someone or tapped “Write” on a deal with them. Whoever agrees to your call appears among your people at once, marked “new” until you open their card: with their name, Telegram id and username when they agreed through Telegram, and with their email when it is known (the one they agreed with, or from the attendees of your Google Calendar event). Only you see this email: your team doesn’t, and it never goes to AI. It is deleted with the person, and, if someone who agreed through Folybot deletes their data, from your card too.
- A contact’s profile photo, when Telegram makes it available to the bot: we keep a small copy, refresh it weekly and delete it with the contact.
- Notes about people and on calls that you write yourself in “My tasks” or in a reply to the bot about a call. Only you see a note on a call, even when the call is shared. You can change a note and pin a note about a person to the top of their card; we then also keep when it was last changed or pinned.
- Settings: your time zone (from your device or picked by you), the morning digest hour (or that it is off), whether the weekly deals summary is off, the “Maybe time to write” threshold, up to 5 quick currencies, and for people the date you hid them until with “Not now”, or that you tapped “Don’t suggest again”.
- The person brief (“What I know”, Pro) made by AI: kept while the data about that person stays the same, 30 days at most, and deleted with the person.
- Deals: the person, title, amount and currency, stage and stage history (who changed it, and when), who handles the deal, the next step, the other side’s promise (“Waiting for”: what and by when, as a reminder of whoever handles the deal, including one noted after a call with “They promised something”) and who tapped “Nudge” or “It came” under it, marked a step done or tapped “Write” on the deal, and when, the chat the deal started from, plus the currency you last picked. Every deal belongs to a team (while you are on your own in it, that is just you): every member of the team sees it, with the deal person’s name, @username and photo while that person is among the contacts of whoever added that person to the deal. You can be in several teams, and each sees only its own deals; a deal moved to another of your teams goes there with its history and notes, and from then on that team sees it. Quotes, reminders and notes about people are seen only by whoever saved them. In the history of a deal of a team of two or more, members see each other’s calls with the deal’s person (the date, the length and who had the call, without the call’s title or its notes; a call changed in Google Calendar only its participants see) and that one of them forwarded the bot that person’s message (who and when, without the text). Deals never appear in shared chats.
- Team: its name, deal stages, owner and members, when each joined and agreed to the team’s rules (date and version of the text), notification settings and notes on deals with their author’s name (and when one of them was pinned to the top of the deal). Members see each other’s Telegram name, username and profile photo: when Telegram makes the photo available to the bot, we keep a small copy, refresh it weekly and delete it once the person is in no team.
- Team invites: only a one-time code, when it was made and whether it was used. We store nothing about the person it was sent to until they accept the terms and agree to join. When an invite no longer works, whoever opened it can ask for a new one: the team’s owner gets their Telegram name and the team’s name. If a team invite brought you here, for the counts we remember only that, without the inviter’s name.
- Meetings: title, time, duration, chat title, links to the event and to Meet, the Telegram ids of people who tapped “Remind me”, and the emails of people who agreed to the meeting. When someone taps “Can’t make it” on a card, we keep their name and Telegram id with that answer, even if they don’t use Folybot: the organizer is told, and the card shows the name to everyone who sees it, as it does the names of those who agreed. We keep a call’s participants with it (name, Telegram id, email when known, their answer and how they came: from the chat, the card, by email or added by the organizer); the people of one call see each other’s names and answers in the app, never their emails; people invited only in Google Calendar are seen by the organizer alone. The organizer can add someone to a call from their People, by @username or by email, and remove people from it. Only someone who uses Folybot gets an invitation from the bot, and when adding someone the organizer sees whether the bot can write to them; the organizer sends the card to anyone else from their own Telegram, and Google Calendar sends the invitation to an email. Whoever taps “Agree”, “Can’t make it” or “Remind me” on the card becomes a participant of the call. Someone removed is told by the bot if they use Folybot, and Google emails them if they were on the Google Calendar event. The organizer can also change a call in words, in reply to its card or to the bot’s message about it; when others will hear of the change, the bot asks first, and in a shared chat everyone sees that question, with the names, as the card shows them, of those the bot will write to or Google will email. The email someone was invited with is kept with the call. When you have a deal with someone on the call in a team of two or more, your teammates see in the deal’s history the call’s date and length and that you had it.
- If you agree to a call on its card before you use Folybot and let it message you, we keep your Telegram id only for that call’s reminders and delete it a day after the call. It goes at once if you tap “Don’t remind me” or “Can’t make it”, or the organizer removes you from the call or cancels it.
- Shared cards: when you mention the bot in a chat with “remind us”, “I promise” or “ask for” (or the same words in another language), the bot posts a card in that chat that everyone in it sees: the task, the time, your Telegram name and the Telegram name of whoever it is for. We keep the card (its task, time, chat title, kind, and the Telegram name of whoever it is for) and who tapped a button on it: their Telegram id and Telegram name, even if they don’t use Folybot, and the reminder it made for them. The card shows the names of those who tapped “Me too” or “I’ll do it” to everyone who sees it. When you complete the reminder, the card shows it; when you delete it, the card loses its text. A call recap: when you tap “Send” under it, the bot prepares a card with the next steps (yours and the other person’s, with Telegram names) that you yourself send to a chat you pick; everyone in that chat sees it, and those who tap a button on it are kept the same way.
- Assignments: when you write an @username (or “assign”) right after mentioning the bot, the bot posts the same kind of card in the chat for that person, and we keep that @username with the card. Only that person can take it (anyone, when there is no @username): whoever takes it gets the reminder, and you get a wait on them. The card shows everyone who tapped “I’ll take it” or “Not mine” by their Telegram name, and when the assignment is done.
- Time picker: when you mention the bot in a chat and list several times to choose from, the bot posts a card that everyone in the chat sees, and we keep it (the title, the length, the times, the chat). Whoever taps a time, even without Folybot, leaves their Telegram id and Telegram name: the card shows those names to everyone who sees it. When you book a time, the card becomes the usual call card, and those who chose that time and use Folybot get the call’s reminders.
- Groups: when you use the bot in a group chat (a call, a shared card, an assignment, a time picker), we keep the group’s title and, if it is public, its @username, to show the group as a card in People. We keep nothing about the group’s members beyond what the cards already keep.
- If you connect Google: your Google email and a calendar access token. If you agree to someone’s meeting on its card: the email you chose, so the next “Agree” takes one tap (change or remove it in Settings).
- A record of AI calls (model, tokens or audio length, cost, purpose) without any content.
- Voice notes (Pro): the transcript is stored just like typed text; the audio is not: it exists only in memory while it is transcribed and is deleted right after.
- A voice note or round video you ask to be brought back later (it is not transcribed or passed to anyone): the message itself stays in Telegram, and the bot keeps its file reference and kind until the reminder is done or deleted (a done one, until the next daily clean-up).
- Photos (Pro): the text read from a photo or an image is stored only when you tap “Yes, save”, like the text of a forwarded message; the image itself is not: it exists only in memory while it is read and is deleted right after.
- Time phrases (the command only, up to 200 characters) that the bot’s rules were unsure about or read differently from the AI, and phrases the AI reads instead of the rules (a message in another language or with several tasks), with the AI’s answer, and the commands the bot turned into a call or a reminder offered with an “It’s a call” or “It’s a reminder” button, marked if that button was tapped, the reminder was deleted or moved within a minute, or a new try came right after “not understood”. They are kept for 30 days to improve recognition and are never shown to anyone else. Once a week they are reviewed automatically on the server; only generalised shapes of phrases and single words written by at least two people leave the server, never the phrases themselves and never tied to anyone.
- A reminder that didn’t fit the Free limit: its text, person and time. It waits until you free a slot or get Pro, and is deleted after 30 days if not saved.
- If you pay for a plan: the plan, its end date, the amount in Telegram Stars, Telegram’s payment id and when you confirmed that Pro starts as soon as you pay. We never receive card details.
- Pro for the team: which owner paid for a pack, its seats, price and end date, Telegram’s payment id and whether its renewal is off. We don’t store who has a seat: it follows from the order people joined the team. If a team’s owner paid for Pro for the team, the members see that their Pro comes from the team. The owner sees only how many seats are taken; whether someone has a subscription of their own, the owner doesn’t see. When an invitee asks for a seat, the owner gets the request without a name.
- Invites: your link’s code, how many people accepted the terms by it and how many of them got Pro (no names), the Pro days they brought you, and days waiting in reserve for your subscription to end. If you came by a friend’s link, we remember whose it was until your first Pro payment, 60 days at most, and, for the counts, a mark that you came by an invite, without the inviter’s name. If your first payment brought someone Pro days, its record keeps whom, so a refund can take them back. We only tell the inviter that someone got Pro by their link and show how many people came and paid, never who. Taps on “Share” and “Copy” are counted only as a number per day.
We do not read your conversations: the bot only sees what you give it. When you mention the bot in a shared chat, everyone in that chat sees your message and the bot’s short reply; the reminder itself comes only to you, unless you share it on a shared card. Messages you send with /paysupport or /report are forwarded to us in Telegram and not stored; only a daily count remains. The database is kept on an encrypted disk, and backups are encrypted with a separate key.
Other people’s messages, names and photos reach us only when you pass them to the bot yourself, and only you see them (the exception is the Telegram id and Telegram name of those who tap a button on a shared card, a time picker or a call card: everyone who sees the card sees them, as said above); your team also sees a deal person’s name, @username and photo, and in the deal’s history your calls with that person (date and length) and that you forwarded the bot their messages, without the text. Those people have the same rights as you and can reach us at the contacts above. We do not intentionally collect sensitive data (health, religious or political views and the like), so please don’t send it to the bot; if such data ends up in a reminder, it is processed only for that reminder.
3. Why, and on what legal basis
Reminders (voice notes put off for later included), meetings, shared cards, assignments, time pickers, groups, your list of people, deals and teams, the digest, invites, payments and subscription records are needed to perform our contract with you, the Terms of use (Art. 6(1)(b) GDPR; Art. 11(1)(3) of the Law of Ukraine “On Personal Data Protection”). AI features run only with your separate consent (Art. 6(1)(a) GDPR; Art. 11(1)(1) of the Law). Encrypted backups, AI call records for cost control, the deletion record and time phrases kept to improve recognition rest on our legitimate interest in running the service reliably, securely and affordably (Art. 6(1)(f) GDPR; Art. 11(1)(6) of the Law). When someone who doesn’t use Folybot taps a button on a shared card or a time in a time picker, we keep their name and Telegram id on the card owner’s legitimate interest in the card showing who took it on or what was chosen (the same articles).
Nothing is used for advertising, sold, or used to train models. Your Telegram id is needed for the bot to work, and the service is impossible without it; Google and AI are optional, and without them only meetings and AI features are unavailable. We make no decisions about you based solely on automated processing that have legal or similarly significant effects: AI only suggests times, titles and texts, and you decide. You may use Folybot if you meet Telegram’s age requirements.
4. Who processes it
Processors that handle data on our behalf under a data processing agreement:
- Hetzner — server hosting, Finland (EU); a data processing agreement under Art. 28 GDPR was concluded on 3 October 2026.
- Cerebras, only with your separate consent to AI (the bot asks for it before anything goes to AI for the first time; you can change it in Settings), — AI reading of what you write to the bot, a command mentioning @folydevbot in a chat (the command only; for a call, see below), the comment with a forward and a typed answer to “When should I remind you?”, up to 1,000 characters: to read the time, understand messages in other languages, on Pro split a message with several tasks into separate ones and make a short reminder title from a long or forwarded message, and for a forward also suggest an action: a reminder time, an amount, a deal and whether the author promised you something, only when the text itself names them; nothing is created until you tap (the AI then gets that message, up to 1,000 characters, its author’s name and today’s date); and, only on Pro and only when you tap “Prepare message”, “Write” on a person’s or a deal’s card, “✗ Not yet” under a promise, or “Another one”, an AI suggestion: the person’s name, their quotes from open reminders, your notes about them, the open reminders and deals with them and the number of days, up to 2,000 characters in all; and, only on Pro and only when you tap “What I know”, the person brief: their name, the reminders with them (dates, quotes, notes), your notes about them, the deals (title, stage, amount, next step) and the meetings of the last 365 days and ahead (date and title), up to 3,000 characters in all; and, only on Pro and when you open an open deal’s card, next-step suggestions for deals: the deal’s title, stage, amount and next step, the day it started and up to three deal notes (on a team deal these may be your teammates’), and on a deal you started also what the person said and the person facts used for “What I know”, up to 3,000 characters in all, to suggest the next step and a day (asked again only when those facts change); and, only on Pro and once a day when the morning digest comes, the smart digest: that digest's items (names, titles or the start of quotes, times, deal titles and amounts), up to 2,000 characters, to write the “Today’s focus” paragraph (not stored); and, only on Pro and only when you tap “Recap” after a call, a call recap: the text you type or the transcript of the voice message you say, up to 4,000 characters, and the stage names of your deals, to split it into decisions, your steps, the other side’s steps and a suggested deal stage (nothing is kept until you tap “Save”; the stage never changes by itself). USA. Under Cerebras’s terms, inputs are used only to produce the answer, kept only as long as that needs, and not used for training. When you mention @folydevbot in reply to a message to set up a call and don’t say what it is about, the text of that message (up to 1,000 characters) also goes to Cerebras, only with your consent to AI, to name the call; the bot keeps nothing of it beyond that name. Without AI consent the bot sends nothing to Cerebras: times are read by the rules and titles come from the text itself.
- Groq, only on Pro and only with your consent to AI, — transcription of a voice message you send or forward to the bot (up to 10 minutes): the audio is deleted right after transcription and stored nowhere, Zero Data Retention is on at Groq, never used for training, USA. The transcript then goes the way typed text goes.
- OpenAI, only on Pro and only with your consent to the AI text that names OpenAI, — reading the text in a photo or an image you send or forward to the bot (up to 10 MB): the bot does not keep the image and drops it from memory right after the answer. Under OpenAI’s terms, data sent through its API is not used to train models, and OpenAI keeps abuse-monitoring logs for up to 30 days. USA. You see the text read first, and it is stored only if you tap “Yes, save”.
Cerebras, Groq and OpenAI are in the USA, so data leaves the EU and Ukraine. These transfers are protected by the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914), which are part of the Cerebras, Groq and OpenAI data processing agreements; write to us for a copy of these safeguards.
Independently, under their own rules, data is processed by Telegram, the messenger the bot runs in (Telegram’s policy), and by Google, Calendar and Meet, only when you connect Google (Google’s policy).
5. How long
- Your profile (Telegram id, name, language), settings and consent records — while you use the bot, until /forget.
- If you started the bot but did not accept the terms — your Telegram id, name, username and language: 30 days after your last action, then deleted.
- Your Google email and access token — until you disconnect Google or delete your data.
- Texts of completed reminders, their titles and notes — 365 days after completion; a deleted reminder goes at once, with its note.
- Forwarded messages — 365 days; they also go with the person (“Delete contact” on their card).
- Contacts with no reminders, meetings, notes or deals — 180 days; notes — while the person is in your list or until you delete them; a note on a call with no person — as long as the call itself is kept.
- Ended and cancelled meetings — 365 days.
- The Telegram id of someone who agreed to a call on its card before using Folybot and let it message them — until 1 day after the call; “Don’t remind me” deletes it at once.
- Shared cards (assignments included), with who tapped them — 30 days after the card’s time (or after it was made, when it has no time); “Delete everything” takes your cards out of the chats and you off others’ cards.
- Time pickers, with their votes — 7 days after a time is booked, or after the last of the times when none was; “Delete everything” takes your votes out of others’ pickers.
- A group in People — as long as anything of yours (a call, a card, a time picker) points at it: when nothing is left, the row goes with the next daily clean-up; “Delete everything” removes it at once.
- Open deals — until they are closed or deleted; won and lost deals — three years (1095 days) after closing.
- A team with its deals — while one of its members has Pro; when no member has had Pro for a year, the team is deleted with its deals, and every member is warned 30 days before. Membership records — while the person is in the team. An invite works once and for 7 days at most; its code is kept 30 days from when it was made, so whoever opens an old one can ask for a new one.
- AI call records — 90 days. We don’t keep the audio of voice messages or the photos you send at all.
- Person briefs — while the data about the person stays the same, 30 days at most; deleted with the person. Profile photos — with the contact; a team member’s own photo — while they are in a team.
- The file reference of a voice note or video put off for later — until the reminder is done or deleted.
- Time phrases the rules were unsure about, phrases the AI reads instead of the rules, and commands marked as corrected — 30 days.
- A reminder that didn’t fit the Free limit — 30 days if not saved.
- Payment records — while the account exists; /forget deletes them and stops the subscription. Team Pro packs — while the team exists; the payer’s /forget switches their renewal off, and the seats last until the end of the paid period.
- Whose link brought you — until your first Pro payment, 60 days at most; the mark that you came by an invite, your link’s code and the counts — while the account exists. The number of link shares a day and the teams’ and deals’ counts a day (invites, joins, deals moved, new deals and where they were made, steps done, stage changes, nudges about promises; numbers only) — 90 days.
- Encrypted backups — 30 days.
- The deletion record (Telegram id and date only) — 35 days.
The /forget command or “Delete everything” in “My tasks” cancels your future meetings (attendees are notified, and Google emails them the cancellation), disconnects Google, stops the subscription and deletes all your data from the bot at once. The encrypted backups drop it within 30 days. In each of your teams that has others in it, the deals stay with the team: the ones you handled go to the owner (or, if you are the owner, the team goes to its longest-standing member), the deal’s person stays as their name, @username and id, your notes on deals are deleted, and the deals’ history keeps you as a “former member” with no id. A team you are alone in is deleted with its deals. People who came by your link are no longer linked to you. So that a restore from a backup cannot bring your data back, we keep only your Telegram id and the deletion date for 35 days; AI call records stay, no longer linked to you, until their 90 days run out.
6. Your rights
As a data subject, you have the right to know what data about you we process, to access it and get a copy (“My tasks” → Settings → “Export to CSV”), to rectify it, to erase it (/forget or “Delete everything”), to restrict its processing, to object to processing based on legitimate interest (for example, to keeping time phrases) and to withdraw any consent. Withdrawing consent does not affect the lawfulness of processing before it. You can withdraw AI consent on its own, any time: /settings or “My tasks” → Settings → “AI features”; from then on the bot sends nothing to the AI, and everything else keeps working.
For anything else, write to us at tomoonkee@gmail.com or in Telegram; we reply within one month. You can complain to the Ukrainian Parliament Commissioner for Human Rights (ombudsman.gov.ua) or to the data-protection authority of the EU country where you live or work.
7. Google data
Folybot’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
When you connect Google as a meeting organizer, we receive your Google email, so the bot knows which calendar to work in, and permission to create, change and cancel only the events Folybot creates (calendar.events.owned). We don’t read the other events in your calendar. From someone who agrees to a meeting by signing in with Google, we receive only their email address and name (openid, email, profile).
All of this is used only to create the event with a Meet link in the organizer’s calendar, add as attendees the people who agreed and those the organizer invited by email, remove the people the organizer removed, show their names on the card in the chat and to the organizer, show the organizer, and only the organizer, who of those invited in the event itself accepted or declined (the bot reads these answers from the event’s attendee list; when someone who agreed through Folybot changes their answer in Google, the answer they gave in Folybot changes too), change the event’s title, time or length or cancel it when asked, and keep the Telegram card current: until an hour after the start, the bot re-reads the event every few minutes. If you use Folybot and agree to a meeting, we remember the email you agreed with, so your next “Agree” is one tap.
Someone who accepts in the Google event itself is added to the organizer’s people with the email and name the event shows. Only the organizer sees them, they never go to AI, and the organizer’s team never sees the email; the team sees the name only if the organizer adds a deal with that person to the team. For this we get nothing from Google beyond the event’s attendee list, which the bot already re-reads.
We use Google user data only to provide the meeting features this section describes. We don’t sell it, share it with anyone beyond what this section describes, or make aggregated or anonymized data from it. Our hosting provider Hetzner (Finland, EU) stores it on our behalf, and attendees’ emails go to Google as event invitations. It is never used or transferred for advertising of any kind, including targeted, personalized, retargeted or interest-based ads, never passed to data brokers or information resellers, never used to determine creditworthiness or for lending, and not read by humans unless you ask us to, security requires it or the law demands it.
We do not use data received from Google Workspace APIs (here, Google Calendar), whether raw or aggregated, anonymized or derived from it, to develop, improve or train generalized or non-personalized AI or ML models, and we do not transfer it to anyone for that purpose; Folybot trains no AI or ML models at all. Event titles changed in Google Calendar, attendees’ emails and the names Google gives are never sent to AI. The only Google data that can reach AI is a call’s time. When someone replies in words about a call and the bot’s own rules can’t read the reply (another language, or a shift they don’t know, such as “an hour and a half later”), Cerebras gets the call’s current start and length, which may have been set in Google Calendar, to work out the new time. This happens only for that reply and only if its author consented to AI, and under Cerebras’s terms (section 4) it is not used for training.
This data travels only over HTTPS, is stored on an encrypted disk and in encrypted backups, and the calendar access token is used only by the bot’s server. Section 8, “How we protect your data”, describes these safeguards in detail.
Your Google email and token are kept until you disconnect Google (“My tasks” → Settings → Google) or delete your data (/forget or “Delete everything”). They are then deleted at once, and we revoke the token at Google. Removing Folybot’s access in your Google Account stops all calendar work. In the same Settings you can change or forget the email for “Agree” and switch the calendar to another Google account; the remembered email is deleted with the rest of your data.
Meeting data (the event link, and the emails and names of those who agreed) is deleted 365 days after the meeting’s start, once it has ended or been cancelled, and leaves the encrypted backups within 30 days. The event itself stays in the organizer’s Google Calendar until they delete it.
8. How we protect your data
Data is encrypted in transit. The website and the Google sign-in work only over HTTPS, and a request over plain HTTP is redirected to HTTPS. The bot talks to Telegram, Google and the AI services in section 4 over HTTPS as well. The website’s sign-in cookie is sent only over HTTPS and cannot be read by scripts on the page.
The database is stored on a disk volume encrypted with LUKS2 (AES-256). It holds everything listed in section 2, Google emails and calendar access tokens included, and profile photos are kept on the same volume. The encryption key can be read only by the server’s administrator account and is never copied into backups. Every night the server backs the database up and encrypts the copy with age to a key whose private half is kept off the server, so the server cannot read its own backups. They are kept for 30 days.
The calendar access token is the OAuth refresh token Google issues when an organizer connects Google Calendar. It is stored only on the encrypted volume and in the encrypted backups: it is never written to logs, shown in the app or included in the CSV export. Only the bot’s server process uses it, and for two things only: to get a short-lived token from Google to create, read, change or delete an event Folybot makes, and to revoke access at Google when you disconnect Google, switch accounts or delete your data. The short-lived token is never stored; it exists in memory for that one action. Someone who signs in with Google only to agree to a meeting gives us no token at all, just their email and name.
Each part of the system has only the access it needs to work. From Google, Folybot asks for the narrowest calendar scope that is enough, calendar.events.owned, and touches only the events it created, by their id (section 7). On the server, the bot runs as a separate system user that cannot log in and can write only to its own folder and the encrypted volume. The app’s keys, including the Google client secret, are in a file that only this user and the administrator can read.
The web app accepts connections only from the web server on the same machine, and the firewall lets in only web traffic and SSH. Only we, as the controller, can sign in to the server, over SSH with a key; password sign-in is turned off. Security updates install automatically, and repeated failed SSH sign-ins are blocked. Inside Folybot every request is checked against your Telegram account, so you see only your own data and your teams’ deals.
We keep only the data listed in section 2, for the periods in section 5, and don’t store the audio of voice notes or the images you send at all. Data received from Google, including event titles and attendees’ emails and names, is never sent to AI; the one exception, a call’s time, is explained in section 7. Server logs record technical events such as errors and counts, with Telegram ids and, for a failed Google call, the event’s id. They never contain the text of your messages or notes, photos, voice notes, email addresses or Google tokens, and the web server keeps no access log. The processors in section 4 work under data processing agreements, and the transfers to the USA are covered by the Standard Contractual Clauses described there.
If a personal data breach happens, we will report it to the supervisory authority within 72 hours of becoming aware of it, unless it is unlikely to put people’s rights and freedoms at risk. If it is likely to put your rights and freedoms at high risk, we will also tell you without undue delay. This is what Articles 33 and 34 GDPR require.
9. Changes
We will tell you in the bot before any material change to this policy, including any change in how we use Google user data.