1. What we collect
- Your Telegram profile: user ID, username, first and last name, language and whether you have Telegram Premium, as Telegram passes them to the bot. We also record when you joined and were last active, how you came to the bot (for example a referral or ad link) and who invited you.
- What you send for processing: photos, videos, text requests and voice messages, in the chat or in the Mini App.
- Generation history: your prompts, the model or tool, the price in credits, the result status, the Telegram file ID of the result, a small preview (256 px) and the result link returned by the provider.
- Payments and credits: Telegram Stars payments (Telegram’s charge ID, amount, date); card payments through Lava.top (order, pack, amount, status); crypto payments through @CryptoBot (order, invoice ID, pack, amount, coin, status); your balance and a log of every top-up, charge and refund.
- Usage events: the commands, buttons and screens you use and how generations end. They are stored in our own database. We use no third-party analytics or advertising trackers.
- Support messages you send with /support or /paysupport.
- Consent records for the face tools (section 5).
We do not ask for your phone number, email, contacts or location.
2. Why we use it
- To run the bot: process your requests, deliver results, keep your balance and history.
- To take payments, return credits for failed generations and answer support requests.
- To keep the service safe: automatic checks block prohibited requests (see the Terms of Service).
- To improve the bot: statistics on which features, models and prices work.
- To message you about the bot: bonuses, new features, unfinished payments. To stop these messages, block the bot.
We do not sell your data, and we do not use your photos to train AI models.
3. Who processes your data
The bot works through these services. Each one handles data under its own terms and privacy policy.
- Telegram: the platform. Your messages and files, Telegram Stars payments.
- Wavespeed AI: runs the image, video and audio models. Your photos, videos and prompts are sent there to make the result. Wavespeed passes requests to the model makers, such as Google, ByteDance, OpenAI, Kling, Bria, MiniMax, PixVerse and Vidu. For some video tools your video is uploaded to Wavespeed’s file storage, and results come back as links hosted by Wavespeed.
- OpenRouter: the /chat assistant, turning voice messages into text, and automatic photo checks for the face tools (is there exactly one face, could anyone be under 18). Requests are sent with OpenRouter’s setting that excludes providers which collect data. For the chat we send a hashed identifier, not your Telegram ID.
- OpenAI: some older chat features (describing a photo, improving a prompt) call OpenAI directly.
- Railway: hosts our servers and the database where the data above is stored, and keeps server logs.
- Lava.top: card and SBP payments. You enter card details on Lava’s page, and we never receive them. Lava gets the order, the amount, your Telegram ID as the order reference and a technical email address made from it (not your real email).
- @CryptoBot (Crypto Pay): crypto payments in USDT or TON. You pay inside @CryptoBot; we receive the invoice status, the amount and the coin, and send CryptoBot only the pack, the price and our order number (not your Telegram ID).
The Mini App loads Telegram’s script from telegram.org. Its Persian version, like the Persian version of this page, loads the Vazirmatn font from Google Fonts.
4. How long we keep data
- Photos and videos uploaded in the Mini App: not saved. They are held in memory while your request runs and sent to the provider.
- A photo sent in the chat: in some chat modes the last photo (and a reference photo) is kept in your session so you can keep editing it. Your next photo replaces it, and /new, /cancel or /start clears it.
- Voice messages: turned into text; the audio is not stored. The text is kept like a typed prompt or chat message.
- /chat conversation: the last 6 messages (up to 500 characters each), so the assistant remembers the context, until /exit, /new, /cancel or a photo.
- Usage events: 30 days. After that only your latest 100 are kept.
- Profile, balance, payments, generation history and previews, support messages and consent records: while your account exists. There is no automatic deletion yet; we delete them when you ask (section 6).
- Server logs (Railway): technical records such as your Telegram ID and the requested address, not your photos. Railway keeps them for a limited period.
- Results in your Telegram chat stay there until you delete them. Copies held by the services in section 3 follow their own policies.
5. Face swap, motion and photoshoots with your own model
These tools ask you to confirm that the photo shows you or a person who agreed. We store your confirmation as a consent record: the tool, the statement you confirmed, the time and SHA-256 fingerprints of the photos. The photos themselves are not part of the record.
6. Your choices and rights
- Get a copy: ask in /support and we will send you the data we hold about you.
- Delete your data: write “delete my data” in /support. There is no automatic button yet: the team deletes your account by hand within 30 days and confirms in the chat. This removes your profile, balance (unused credits are lost), generation history and previews, session photos, chat history, events, consent records, support messages and our records of your payments. Telegram, Lava and @CryptoBot keep their own payment records.
- Your name and username update automatically from Telegram.
- To stop messages from the bot, block it.
7. Age
The bot is for people aged 18 and over. If we learn that we hold data of someone under 18, we delete it.
8. Security
Data is stored on Railway servers, and only the bot team can access it. Card details never reach us, and secrets are removed from our logs. No system is perfectly secure, but we work to protect your data.
9. Changes
When this policy changes, we update this page and the date at the top. We announce important changes in the bot.