Privacy Policy

Last updated 5 August 2026

CaptainPost is a publishing automation service for Telegram channels, available through @CaptainPost_bot. This document explains what data is processed, why, and how to have it removed.

1. What we store

2. What we do not store

3. Logs

Service logs record a short derived token such as u:a3f9d1bc in place of a user identifier. It is enough to trace events within a single incident and not enough to identify a person. Logs are retained for no longer than 30 days.

4. Third parties

Some features pass data to external providers:

We do not sell or share data with advertising networks, data brokers, or cross-site tracking analytics.

5. Revoking access

You can revoke our access to your account at any time, independently of us: in Telegram open Settings → Devices and terminate the CaptainPost session. The service loses the ability to act on your channels immediately.

6. Deleting your data

Send a deletion request to @CaptainPost_support_bot. All records tied to your hash are removed within 30 days. Note that revoking a session in Telegram does not delete your task configuration — a request is needed for full deletion.

7. Your rights

Where the GDPR or comparable law applies, you have the right to access, rectify, erase, restrict processing of and port your data, and to object to processing. Requests go to the support contact above and are answered within 30 days. You may also lodge a complaint with your local supervisory authority.

The legal basis for processing is performance of a contract — the service cannot function without the data listed in section 1.

8. Security

Traffic to the web application is protected with TLS. Data arriving from the Telegram Web App is verified server-side against its HMAC signature; requests without a valid signature are rejected. Secrets live in environment variables and are never committed to the repository.

No system is perfectly secure. The most sensitive item we hold is the session string granting account access. If you are not actively using the service, revoke the session.

9. Children

The service is not directed at anyone under 16 and does not knowingly collect their data.

10. Changes

Users are notified in the bot when this document changes materially. The revision date appears at the top of this page.

11. Contact

For any question about data processing: @CaptainPost_support_bot