Privacy Policy
Adfura, the Telegram Ads autopilot
Contents
- 1. Who is responsible for your data
- 2. What this policy covers
- 3. What we collect
- 4. Why we use it, and on what legal basis
- 5. Your Ads API token
- 6. Who else sees your data
- 7. Where we keep it
- 8. How long we keep it
- 9. Deleting your data, and your other rights
- 10. How we protect it
- 11. Children
- 12. Changes to this policy
- 13. Contact
This policy says what we collect, why, who sees it, how long we keep it and how you get it deleted. It is written to be read, not to be waved at you.
1. Who is responsible for your data
Adfura ("we", "us") decides what is collected here and why.
- Our bot: @adfurabot
- Support, and any request about your data: @adfurasupport
2. What this policy covers
It covers @adfurabot, from your first message through setup and payment; our site; discovery; and the Connect beta.
It does not cover Telegram itself. Our bot and your ads live on Telegram, and Telegram's own privacy policy governs what Telegram does with your data. It also does not cover your own customers' relationship with you.
3. What we collect
3.1 When you start in @adfurabot
| What | Why we need it |
|---|---|
| Your Telegram user id | To know who is setting up and to message you in @adfurabot |
| Your Telegram username | To recognise you when you write to us |
| The link you submit (bot, channel or Mini App) | To check your niche and show your discovery preview |
| Your language (Persian or English) | To write to you in your language |
| Your niche | To check which lane it falls in (terms, section 10) and to show your preview |
| Your monthly ad budget and your target cost per result | To price the service and pick your plan: which fee applies, whether your budget meets the Connect minimum, and whether it is priced by quote (terms, section 12.1) |
| The date you started, and your last step | To know how far you got, and how long to keep your record if you stop (section 8) |
| Which version of the terms and of this policy you accepted, and when | To show what you agreed to (terms, section 3) |
If you become a customer, your budget and target cost per result carry on as your instructions (section 3.3).
We do not ask for your name, phone number or email. Telegram passes your display name to any bot you write to; we do not keep it.
3.2 If you see a discovery preview
The link, the proof that the link is yours (for example, that our bot could confirm it), the date, and the preview we showed you. The preview itself is drawn from our catalogue (section 3.9), not from anything about you.
3.3 If you use Connect
- Your business and contact: business name, the Telegram user id and username of the person who connects, language, niche lane, plan.
- Your Ads API token. Section 5 explains how we keep it.
- Data from your Telegram ad account, read through Telegram's Ads API: your ads and their text, links and settings, budgets, balance, spend, statistics (views, clicks, results), transactions, and Telegram's review decisions.
- Your instructions: budget, target cost per result, and the baseline recorded for the guarantee.
- Your full discovery run: which places we found and tested for you, and how they did for you.
- Your messages and choices in @adfurabot.
3.4 When you pay
The wallet address you pay from, the transaction id, the amount, the asset, the network, the time, and the invoice. If you pay in Gram, the invoice record also includes the rate we used to convert our fee from US dollars, the public source that rate came from, and the exact time it was taken. We keep that so you and we can both check the amount afterwards (terms, section 12.2). Blockchain payments are public and permanent: anyone can see them, and nobody, including us, can delete them.
3.5 If you connect your sales data (optional)
To count results per ad, we can receive events from your bot or shop, such as "someone who came from this ad started your bot" or "made a purchase". We ask you to send a reference for each of your users that does not identify them by name, and we do not want names, phone numbers or message contents. For this data, you decide what is collected and why; we handle it for you and use it only to measure your results.
3.6 When you contact us
The messages you send us and our replies.
3.7 Technical records
Our servers keep short logs: the time, which part of the service ran, and errors. Tokens are never written to a log. Our site is served by a hosting provider, whose own logs may record your IP address and browser. Our site sets no cookies and runs no trackers.
3.8 What we never do
We do not sell your data. We do not buy data about you. We do not use your data to target ads of our own at you, and we do not follow you around the web.
3.9 Discovery: information about Telegram channels and bots
To show advertisers where their ads could run, we keep a catalogue of Telegram channels, bots and search keywords where ads can be placed. It holds two kinds of information:
- Public Telegram information about channels and bots, such as a channel's or bot's name, username, description, language, topic and subscriber count.
- Prices: what advertising in those places typically costs, from market statistics that combine many accounts and name no customer (section 6).
The catalogue is about channels and bots, not about our customers. Nothing you tell us and none of your results go into it, apart from the "proven in your niche" badge (section 6). What the full discovery run finds about public channels and bots is added to it.
Some public information can be about a person, for example when a channel's public name or username is someone's own name. If a channel or bot is yours and you want its entry corrected or removed from our catalogue, write to us (section 9).
4. Why we use it, and on what legal basis
| Why | Which data | Legal basis |
|---|---|---|
| Taking you through setup in @adfurabot, including pricing the service and picking your plan | 3.1 | Steps you ask us to take before a contract |
| Showing you the discovery preview | 3.2 | Steps you ask us to take before a contract |
| Recording which terms and policy you accepted | 3.1 | Our legitimate interest in being able to show what was agreed |
| Running your campaigns, including your full discovery run | 3.3 | Our contract with you |
| Checking your niche (terms, section 10) | 3.1, 3.2, 3.3 | Our contract, and our legitimate interest in keeping to Telegram's rules and the law |
| Measuring your results | 3.3, 3.5 | Our contract with you |
| Invoicing, accounting and tax | 3.4 | Our legal obligations |
| Security, and preventing fraud and abuse | 3.3, 3.7 | Our legitimate interest in a safe service |
| Improving the service, and market statistics that name nobody | Aggregated and anonymised results | Our legitimate interest |
| Keeping the discovery catalogue | 3.9 | Our legitimate interest in showing advertisers where they can advertise |
Our software makes the bidding decisions in your ad account. That is the service you asked for, and you set its budget and target and can stop it at any time. A decision to refuse a niche, or to stop running your ads under section 11 of the terms, is made or confirmed by a person.
5. Your Ads API token
Your token controls your ad account and the money in it, so we treat it as the most sensitive thing we hold.
- It is encrypted before it is stored, with a key that is kept apart from the database and from its backups.
- It is decrypted only in memory, only to call Telegram's Ads API for you.
- Our software never displays it: not in the app, not in messages, not in support replies, not in logs, and not to us.
- Each stored token is bound to your account alone. It cannot be read by, or moved to, another customer.
- When you paste it in @adfurabot, the bot deletes that message once the token is stored.
- You can revoke it at any time in your Telegram ad account. After that it no longer works for us. Please tell us as well, so we delete our copy.
- When you close your account, we delete it immediately. A token you replace is overwritten.
- If we ever believe your token may have been exposed, we tell you straight away so that you can revoke it.
6. Who else sees your data
- Other customers: never. Your data never crosses to another customer, and each customer's data is kept apart from every other customer's. The one thing others see that draws on your results is a "proven in your niche" badge on a placement, which never names you. The price ranges in our catalogue come from market statistics that combine many accounts, so that no figure can be traced back to one customer.
- Us: only the people who run Adfura, and only as far as they need to in order to run, support or repair the service.
- Our service providers: the companies that host our servers and our site; and Telegram, because our bot's messages and our API calls pass through it.
- The public blockchain you pay on, for payments, which are public by design (section 3.4).
- Authorities, where the law requires it and after we have checked that the request is valid.
- A buyer of the business, if Adfura is ever sold or merged, under this same policy.
We never sell your data to anyone.
7. Where we keep it
Our servers and our service providers may be in a different country from yours, so your data may be moved between countries. Wherever it is kept, we protect it as this policy describes.
8. How long we keep it
| What | How long |
|---|---|
| Setup record, including your budget and target cost per result, if you do not become a customer (3.1) | 90 days after your last message, or until you ask us to delete it |
| Record of which terms and policy you accepted (3.1) | If you become a customer: while you are a customer, and 12 months after you leave. If you do not: deleted with your setup record |
| Discovery preview (3.2) | 90 days |
| Discovery catalogue entries (3.9) | While the channel or bot is public and useful for advertising; corrected or removed when its owner asks |
| Your Ads API token (3.3) | Until you revoke or replace it, or close your account, when it is deleted at once |
| Account and campaign data (3.3) | While you are a customer, and 12 months after you leave, then deleted or anonymised |
| Sales-data events (3.5) | 12 months, or less if you ask |
| Payment and invoice records (3.4) | As long as tax and accounting law requires |
| Support messages (3.6) | 12 months |
| Technical logs (3.7) | 30 days |
| Backups | Overwritten within 30 days |
| Payments on a blockchain | Public and permanent; not ours to delete |
9. Deleting your data, and your other rights
Write to us in @adfurabot or at @adfurasupport and ask us to:
- delete your data;
- send you a copy of it;
- correct it;
- stop a particular use, or object to it;
- withdraw any consent you have given us;
- correct or remove the catalogue entry of a channel or bot that is yours (section 3.9).
We answer within 30 days, and it costs nothing. We check that the request comes from the same Telegram account, or from your registered contact.
When you ask us to delete, we delete your setup record, your previews, your account and campaign data, your sales-data events and your support messages. Two things we cannot delete: records that tax and accounting law makes us keep (section 8), and payments on the blockchain, which nobody can delete. If you are or were a customer, we also keep the record of which terms and policy you accepted for the period in section 8, because it shows what we agreed. Copies inside backups go when the backups are overwritten.
Before you pay, you can delete it yourself. Send /leave or /delete in @adfurabot and we delete your setup record (section 3.1) at once, with everything in it: your link, niche, budget and target cost per result, and the record of which version of the terms and of this policy you accepted. You do not need to write to us, and you can start again with /start at any time. Copies inside backups go, as above, when the backups are overwritten.
Once you have paid, /leave and /delete do not delete anything on the spot, because your account and your invoices are involved. Write to us in @adfurabot and we walk you through closing your account (terms, section 15) and deleting your data as this section describes.
Closing your Connect account is not the same as deleting your data. Closing deletes your token at once; ask us, and we delete the rest as well.
If you think we have handled your data badly, tell us first. You may also have the right to complain to the data protection authority where you live.
10. How we protect it
- Tokens are encrypted, as section 5 describes.
- Each customer's data is separated from every other customer's, and our tests check that separation.
- Access to our servers is limited to the people who run Adfura, and backups are kept apart from the encryption key.
- No system is perfect. If a breach affects your data, we tell you and the authorities where the law requires, and we aim to tell you within 72 hours of finding it.
11. Children
Adfura is for businesses, and it is not for anyone under 18. If we learn that we hold a child's data, we delete it.
12. Changes to this policy
We may update this policy. We will tell you in @adfurabot at least 14 days before a change that matters, and the date at the top always shows the current version.
13. Contact
- Our bot: @adfurabot
- Support, and any request about your data: @adfurasupport