Privacy Notice
Version 1.0, effective —
This notice explains how personal data is handled by the service at https://stage-app.stmadm.com (the "Service"). It is written to meet the transparency requirements of Articles 13 and 14 of the General Data Protection Regulation (GDPR) for users in the European Economic Area.
A Russian-language policy governs processing under Russian Federal Law No. 152-FZ and is available at https://stage-app.stmadm.com/legal/privacy. Where the two documents describe the same processing, they are intended to be consistent; this notice adds the disclosures specific to the GDPR.
1. Controller
| Controller | —, a natural person |
| Established in | — |
| Contact | — |
The Service is a non-commercial personal project. The controller is not a company and has not appointed a data protection officer, as none is required under Article 37.
Please note: the controller is established outside the European Economic Area, and the Service's infrastructure is located in the Russian Federation, a country for which the European Commission has not issued an adequacy decision under Article 45. If you are in the EEA, your personal data will be stored outside the EEA without an adequacy decision in place. Consider this before creating an account.
2. What data is processed
2.1 Account data
Email address, display name, login, optional profile image, interface language, password hash if you chose to set a password, assigned roles, and a record of the consents you gave.
Passwords are optional. An account can exist without one, in which case sign-in uses a one-time link sent to your email address.
2.2 Technical data
IP address and browser information recorded on sign-in attempts and when consent is given; session identifiers; last activity timestamp; a log of actions performed in administrative areas.
2.3 Telegram connection data
If — and only if — you choose to connect Telegram from your profile: your numeric Telegram account identifier, your Telegram username where set, and the identifier of your chat with the bot. Your phone number is never received or stored. You can disconnect at any time; the account survives.
2.4 Content processed by the Service
The purpose of the Service is to produce short summaries of messages from Telegram group chats and public channels that you select. To do this, the Service receives and stores the text of messages from those sources — including messages written by other people, not only by you — along with author names and identifiers, media attachments from public channels, and the summaries produced from them.
If you connect a group chat, you are causing the personal data of everyone in that chat to be processed. In that situation you are acting as a controller in your own right for those participants, and it is your responsibility to have a lawful basis and to inform them. The Service processes that content only to produce summaries.
3. Purposes and legal bases
| Purpose | Data | Legal basis (Art. 6(1)) |
|---|---|---|
| Providing access to the Service and maintaining your session | 2.1, 2.2 | (b) performance of a contract |
| Sending service email: sign-in links, invitations, confirmations | 2.1 | (b) performance of a contract |
| Producing and delivering summaries | 2.3, 2.4 | (b) performance of a contract |
| Protecting accounts against credential stuffing and automated abuse | 2.2 | (f) legitimate interests — keeping the Service and its accounts secure |
| Keeping an administrative audit trail | 2.2 | (f) legitimate interests — accountability of administrative action |
| Recording that you accepted the legal documents | 2.1, 2.2 | (c) legal obligation, and (f) evidencing lawful processing |
Your data is not used for advertising, for profiling with legal or similarly significant effects, or for automated decision-making within the meaning of Article 22. It is not sold and is not shared with third parties for their own purposes.
4. Recipients
Each of the following acts as a processor on the controller's instructions.
| Recipient | Data shared | Purpose | Location |
|---|---|---|---|
| Yandex Cloud | All stored data | Hosting of databases, applications and object storage | Russian Federation |
| Brevo | Recipient address, name, contents of service email | Email delivery | European Union |
| Language model providers, depending on configuration: Groq, DeepSeek, Google Gemini | Text of messages from connected sources | Producing summaries | United States, China |
| Telegram | Chat identifier and the text delivered | Delivery of summaries to the messenger | Per Telegram's own terms |
5. Public accessibility
Nothing in the Service is published to the general public. Summaries and the content behind them are visible only to authenticated users, within the limits of their access rights. There are no publicly reachable pages carrying personal data.
Files in object storage — attachments from public channels — are served through links that the Service generates at display time and that expire shortly afterwards. Anonymous access to the storage is closed.
One deliberate exception: your profile image is reachable by direct link without authentication. You upload it yourself and it exists to be shown. If you would rather it were not reachable that way, do not upload one, or remove an existing one in your profile settings.
Note that a public Telegram channel being public gives the controller a basis to process its content, but no right to republish that content in its own name — and the controller does not.
6. International transfers
Personal data is stored in the Russian Federation and, for the purpose of producing summaries, transmitted to language model providers in the United States and China. None of these countries is covered by a European Commission adequacy decision.
The controller is a natural person operating a non-commercial project and has not put Standard Contractual Clauses or other Article 46 safeguards in place with these providers beyond their standard terms of service. This is disclosed plainly so that you can make an informed decision. If your personal data or the content you would connect requires transfers backed by Article 46 safeguards, do not use the Service.
7. Retention
| Category | Retention |
|---|---|
| Account data | Until the account is deleted; no more than 30 days after a deletion request |
| Sign-in attempt records | 90 days |
| Administrative audit log | 12 months |
| Sessions | Until expiry, and no longer than 30 days from issue |
| One-time links | Until used or expired, whichever comes first |
| Consent records | For the life of the account and 3 years afterwards, as evidence that processing was lawful |
| Messages from connected sources and their summaries | Until you disconnect the source or delete the account |
| Attachments and media from public channels | 14 days from upload, then deleted automatically |
| Service email delivery log | 12 months; link and token values are not stored in the log |
8. Your rights
Under Articles 15 to 21 you have the right to access your personal data, to rectification, to erasure, to restriction of processing, to data portability, and to object to processing carried out on the basis of legitimate interests. Where processing rests on consent, you may withdraw it at any time; withdrawal does not affect the lawfulness of processing carried out beforehand.
How to exercise these rights. Write to —. A response follows within 30 days. Identity may be verified by sending a message to the email address on the account.
Deletion is currently handled manually on request within 30 days. A self-service deletion control in the interface is not yet available; its introduction will be announced in a new version of this notice.
Withdrawing consent results in the account being deleted, because the Service cannot be provided without processing the data described above.
Complaints. You may lodge a complaint with the supervisory authority of the EU member state where you live, work, or where the alleged infringement took place. Given that the controller is established outside the EEA, you may also raise the matter directly at the address above.
9. Security
Traffic between you and the Service travels over an encrypted connection. Passwords are stored only as hashes produced by an algorithm resistant to brute-force attack. One-time links are stored as hashes, expire, and are consumed on first use. Access is separated by role and administrative actions are logged. Rate limits apply to sign-in and registration. Password, token, and key values are excluded from application logs.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, you will be notified at the email address on your account, and the relevant supervisory authority will be notified where required under Article 33.
10. Cookies
The Service uses strictly necessary cookies and browser local storage to maintain your session and remember your language and interface preferences. There are no advertising or third-party analytics trackers, so no consent banner is required. Blocking these cookies makes sign-in impossible.
11. Children
The Service is not intended for anyone under 16. Data of such users is not knowingly collected and is deleted if found.
12. Changes
Each version of this notice carries a version number and effective date. Where a change affects the data collected, the purposes, the recipients, the retention periods, or your rights, the version is raised and you are asked to review and accept the new version at your next sign-in.
The current version is always available at https://stage-app.stmadm.com/legal/privacy-en.
Version history
| Version | Date | Changes |
|---|---|---|
| 1.0 | — | Initial version |