Privacy Policy

Last updated: 2026-08-13

This policy describes how the Telegram assistant available at https://esam-bot.duckdns.org («the bot») handles your data.

The operator of this bot is not named on this page yet. Until it is, treat the bot as a private, non-commercial installation and do not entrust it with data you would not give to an individual.

What the bot stores

Google user data

When you connect your calendar, the bot requests the https://www.googleapis.com/auth/calendar.app.created scope, plus openid email to show you which account is connected. calendar.app.created means the bot can only see and change the calendar it created for you itself. Your existing calendars stay invisible to it — it cannot read them, and it cannot change or delete anything in them.

The bot uses that access for one purpose only: to create, move and delete the appointments you dictate. The bot's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Who else sees it

Your data is never sold, never used for advertising, and never shared with anyone else.

How long it is kept

Deleting your data

Open the bot, go to settings → Delete my data. The bot shows exactly what will go — clients, appointments, notes, money records, your settings, your error records and your calendar connection — and deletes all of it once you confirm. There is no undo.

What still remains, and why. «Everything» would be a comfortable thing to write here and it would not be true:

Google access. The stored refresh token is deleted at the same moment, and the bot asks Google to revoke the access. That request is best-effort: if Google is unreachable it is not retried, and the token stays valid on Google's side until it expires. You can always revoke it yourself, immediately and with certainty, at myaccount.google.com/permissions. The bot cannot use it either way — its copy is gone.

Events already in your Google Calendar are not deleted: that calendar is yours, not ours. You remove them there if you want to.

If you would rather someone did it for you, write to the operator of this bot, through the bot itself.

Security

Data lives on a single server, in a file-based database readable only by the account that runs the bot. Google refresh tokens are additionally encrypted with a key kept outside the database. Traffic to the bot and to Google is encrypted in transit.

Contact

the operator of this bot, through the bot itself

Subscription Terms · Open the bot