1. General provisions
This Privacy Policy describes what data the ком17 Telegram bot (the "Service") receives from a user, why and on what basis it is processed, who it is shared with, and how long it is kept.
The data controller is ком17. By starting to use the Service the user confirms that they have read this Policy and the Terms of Use. If you do not agree with the Policy, stop using the Service; your data can be deleted as described in section 8.
Revision of 2026-09-29.
2. Data processed
The Service runs inside Telegram and does not request identity documents, a home address, card credentials or confirmation codes. It processes:
- Telegram identifiers: numeric ID, username, display name, client
language code — sent by Telegram itself with every message.
- Usage data: the internal coin balance and operation history (top-ups,
purchases, wagers in the game features, transfers between users, withdrawal requests, donations to groups together with any note the user attached to one), achievements, registration date.
- User-set preferences: interface language, city for the weather forecast,
time zone, display currency.
- Group activity statistics for groups where the Service was added by an
administrator: the fact and time of messages, to the extent needed for ratings, flood protection and activity rewards. Message content is not stored, except in the two cases named below.
- Support requests: the text of the request and the correspondence about
it, plus the reply contact where the user supplied one themselves — for example when writing through the web form. The web form neither stores nor forwards an IP address or browser details: the operator receives only what was typed into its fields.
- AI requests: the text a user has themselves addressed to the bot in AI
reply or voice transcription mode. Where such a request is sent as a reply to someone else's message, that message's text (up to 400 characters) and its author's display name and @username are processed along with it — without them the bot cannot tell who is being addressed, or about what. That context exists only while the answer is being prepared and is not written to the database.
- Technical payment details: the provider's payment identifier, amount,
currency, status and the internal order number.
3. Purposes
Providing the Service's features; crediting and debiting internal coins; operating the game, group and reference features; user support and the resolution of payment disputes; protection against fraud, multi-accounting and automated farming; compliance with applicable law.
4. Legal basis
The user's consent, given by starting to use the Service; performance of the contract (the Terms of Use entered into by using the Service); the operator's legitimate interest in security and the prevention of abuse; requirements of applicable law.
5. Sharing with third parties
The operator does not sell user data and does not share it for advertising purposes. Data is shared only to the extent the Service needs to work:
- Telegram — the platform all interaction runs through; Telegram's own
privacy policy applies to it;
- payment providers — to accept payments and confirm crediting;
- AI providers — the text of a request the user has themselves sent to the
bot in AI mode and, where that request is a reply to someone else's message, that message's text, its author's display name and @username, and the title of the group the question was asked in. The chat feed at large is not sent;
- external reference services (weather, exchange rates) — only the query
itself (a city, a currency pair), with no user identifiers;
- the hosting provider of the server the Service runs on;
- competent public authorities — upon a lawful request.
6. Payment data
Payment happens on the payment provider's side, on their page or in a banking application. Card number, expiry date, CVV, confirmation codes and banking application data are never passed to the Service and never stored by it. The Service receives only the payment identifier, amount, currency, status and internal order number — the minimum needed to credit coins and to investigate a dispute.
7. Storage and protection
Data is stored on the operator's server; access is limited to the operator and persons authorised by them. Communication with Telegram and with payment providers uses a secure connection (HTTPS); payment notifications are accepted only with a valid cryptographic signature from the provider.
Retention: account data — while the account is in use and thereafter for as long as needed to resolve possible disputes; records of financial operations — at least three years from the date of the operation; support requests — one year after the request is closed.
8. User rights
A user may: request what data about them is stored; ask for it to be corrected; ask for the account and associated data to be deleted; withdraw consent to processing. Requests go through the /support command in the bot or the contacts in section 10; an answer is provided within 30 days.
Deleting an account ends access to the internal coins and is not a ground for paying them out. Records of financial operations already carried out are retained to the extent and for the period prescribed by law and cannot be deleted.
9. Age restriction
The Service is not intended for persons under 18. The operator does not knowingly collect data about minors; an account found to belong to one is blocked and the associated data deleted.
10. Contacts
- Operator: ком17
- Support tickets: the
/supportcommand in the bot - Web form: https://tgbot.delabs.space/contact/en
11. Changes to this Policy
The operator may amend this Policy. The current revision is always available on this page and is dated. Continuing to use the Service after a new revision is published means acceptance of it.