Privacy Policy
Last updated: 2026-08-13
This policy describes how the Telegram assistant available at
https://esam-bot.duckdns.org («the bot») handles your data.
The operator of this bot is not named on this page yet. Until it is, treat the bot as a private, non-commercial installation and do not entrust it with data you would not give to an individual.
What the bot stores
- Your Telegram user id and chat id — to know whose data is whose and where
to send reminders.
- The text of the messages you send to the bot, and what the bot derived
from them: appointments, client names, notes and payment records you
dictated.
- A copy of the events from the Google Calendar you connected, limited to a
window of about 45 days in the past and 120 days ahead. The copy exists so
that reading your schedule is instant and works while Google is
unreachable.
- The email address of the Google account you connected, so the bot can show
you which account is in use.
- A Google refresh token, stored encrypted, so the bot can keep your
calendar in sync without asking you to sign in again.
Google user data
When you connect your calendar, the bot requests the
https://www.googleapis.com/auth/calendar.app.created scope, plus openid email to show you which
account is connected. calendar.app.created means the bot can only
see and change the calendar it created for you itself. Your
existing calendars stay invisible to it — it cannot read them, and it cannot
change or delete anything in them.
The bot uses that access for one purpose only: to create, move and delete
the appointments you dictate. The bot's use of information received from Google
APIs adheres to the
Google
API Services User Data Policy, including the Limited Use requirements.
Who else sees it
- Google — calendar events you ask the bot to create or
change.
- Google Gemini — the text (or transcript of the voice message) you send, so it can be turned into a structured request. It is sent for that single request. The bot runs on the paid Gemini API, where Google states that submitted content is not used to improve its products and is not reviewed by people.
Your data is never sold, never used for advertising, and never shared with
anyone else.
How long it is kept
- Everything listed above is kept for as long as you use the bot, and goes
when you delete it — there is no separate expiry.
- Backups: 14 days. The database is copied once a
night and the 14 most recent copies are kept; older ones are
deleted automatically. A copy made before you asked for deletion still
contains your data until it ages out.
- Per-day counts of how many requests went to the AI:
92 days. These are numbers, not text — no message
content.
- Error and complaint records: the last 500 entries
across the whole bot. They contain the beginning of the message the error
happened on. Yours are deleted immediately when you delete your data,
without waiting for that limit.
- Past appointments older than a year are removed from the bot's copy
automatically. The events in your Google Calendar are not touched.
Deleting your data
Open the bot, go to settings → Delete my data. The bot shows
exactly what will go — clients, appointments, notes, money records, your
settings, your error records and your calendar connection — and deletes all of
it once you confirm. There is no undo.
What still remains, and why. «Everything» would
be a comfortable thing to write here and it would not be true:
- Your Telegram id alone, with no name, no settings and no
records attached. Without it the very next message you send would create
a fresh account, which looks exactly like «the deletion did not
work». Nothing about you can be reconstructed from it.
- Backups already made — see above. They are not opened to
edit out one person; they expire on their own. If you need it sooner, ask
at the operator of this bot, through the bot itself and the copies are destroyed manually.
Google access. The stored refresh token is deleted at the
same moment, and the bot asks Google to revoke the access. That request is
best-effort: if Google is unreachable it is not retried, and the token stays
valid on Google's side until it expires. You can always revoke it yourself,
immediately and with certainty, at
myaccount.google.com/permissions.
The bot cannot use it either way — its copy is gone.
Events already in your Google Calendar are not deleted: that
calendar is yours, not ours. You remove them there if you want to.
If you would rather someone did it for you, write to the operator of this bot, through the bot itself.
Security
Data lives on a single server, in a file-based database readable only by the
account that runs the bot. Google refresh tokens are additionally encrypted with
a key kept outside the database. Traffic to the bot and to Google is encrypted
in transit.
Contact
the operator of this bot, through the bot itself