Personal Data Processing Policy

Service: from-friends.space, the Telegram bot @from_friends_bot, and the related From Friends Mini App — a service for creating collaborative pages from loved ones' words, stories, voice notes, videos, and photos (hereinafter — the "Service"). Operator: Individual Entrepreneur Chesnova Lilya Gennadyevna, OGRNIP 320774600424255, INN 772985080404 (hereinafter — the "Operator"). Contact: chesnova.lilya@yandex.ru Revision of: September 19, 2026 Version: 1.4

1. General provisions

1.1. This Policy is drawn up in accordance with the requirements of Federal Law No. 152-FZ of 27.07.2006 "On Personal Data" (hereinafter — 152-FZ) and defines the procedure for processing personal data and the measures to ensure their security taken by the Operator.

1.2. The Operator sets as its most important goal the observance of the rights and freedoms of the individual and citizen in the processing of their personal data, including the protection of the rights to privacy of private life, personal and family secrecy.

1.3. This Policy applies to all personal data that the Operator may obtain from users of the Service.

2. Key terms

3. Categories of PD subjects and composition of the data processed

3.1. Organizer

3.2. Participant

3.3. Anonymous ("shadow") answers

3.3.1. The Service allows the Organizer to mark individual questions as shadow (anonymous).

3.3.2. The content of a shadow answer is stored without a participant_id and shown to the Organizer without authorship. Technical participation records and event timestamps are stored separately; the text or image may also identify its author by its content. The Service therefore does not guarantee absolute anonymity.

3.3.3. For shadow answers, only text and photos are allowed; voice messages and video notes are prohibited, since their content may make it possible to identify the author.

3.4. Public website visitor

After the visitor gives separate consent, the website sends Yandex Metrica technical and statistical data: IP address, the Metrica cookie identifier, browser and device information, visited public pages, referral source, and the fact of clicking through to Telegram. Greeting content, Telegram user IDs, and Mini App data are not sent to Metrica.

3.5. User contacting support

When /feedback is submitted, the Service stores the Telegram user, chat and message IDs, name, language, text or caption, a supported Telegram file reference for a photo or voice message, delivery status and timestamps. These data are used to handle the request and retry delivery after a temporary error. The request is delivered privately to the Operator or an appointed administrator; the recipient's public username is not disclosed to the user.

4. Purposes of PD processing

The Operator processes PD solely for:

a) providing the Service (creating the Greeting, delivering it to the Birthday person); b) identifying and communicating with the Organizer/Participant in Telegram; c) accounting for payment of the service; d) fulfilling the requirements of 152-FZ and other applicable legislation of the Russian Federation; e) ensuring the security of the Service and preventing abuse; f) analyzing visits to public pages and click-throughs to Telegram, only after the visitor's consent; g) aggregate evaluation of which sources lead to created and paid Greetings, using a short referral label and without advertising personalization.

The Operator does not use PD for marketing, profiling, transfer to third parties for commercial purposes, and does not sell PD.

5. Legal grounds for processing

5.1. Consent of the PD subject (clause 1, part 1, article 6 of 152-FZ) is the main ground for Greeting content. Consent is recorded:

5.2. Contract / provision of the service (clause 5, part 1, article 6 of 152-FZ) — for establishing the Organizer's session, authentication, displaying collections belonging to the Organizer, preventing access to other users' collections, payment, and service delivery. No new Greeting content is created before separate explicit consent.

5.3. Obligations established by law (clause 2, part 1, article 6 of 152-FZ) — for accounting and tax records (402-FZ, the Tax Code).

5.4. Yandex Metrica is enabled on public pages only after the visitor clicks the consent button. Refusal does not restrict viewing the website or using the Service's core features. Further collection can be stopped through “Analytics settings”; data previously retained by Yandex is handled under Yandex Metrica's applicable rules. The visitor may also contact the Operator.

5.5. The short acquisition-source label contains no Telegram ID, Metrica cookie, or Greeting content. Before a Greeting is created it remains only in the current Mini App session; the Service stores it with the Greeting only after the Organizer's explicit consent. This Mini App label is not sent to Yandex Metrica.

5.6. Personal data consent is obtained separately from acceptance of service and refund terms. Neither reading the Policy nor accepting checkout terms replaces explicit personal data consent.

6. Term and procedure for storing PD

6.1. All new plans provide access and storage for 365 days, starting at first publication. Republishing or rebuilding does not restart the period. A paid upgrade does not restart or shorten the access period already granted. Existing legacy collections retain their previous conditions, including extensions; their standard period is 90 days. The actual expiry date appears in the Mini App. Free legacy extensions do not apply to new plans.

6.2. After the published page's final expiry, including all extensions, a scheduled job removes its HTML. Raw answers (text and media links) are deleted no later than 7 days after the HTML is actually removed. This period is used as a buffer in case of claims or restoration.

6.3. After content deletion, only anonymized information required for accounting and tax records is retained: payment fact, recorded amount (if available), status, date, and a safe payment reference. If a payment identifier contains the original Greeting ID, only its irreversible SHA-256 reference is retained. The Organizer's Telegram ID, the birthday person's name, and the original Greeting identifier are not included in that record. One explicit exception to this rule is the free-plan anti-abuse record described in section 6.3b: it directly contains the Organizer's Telegram ID and is not anonymized.

6.3a. Quotes, initial and upgrade orders store plan and price snapshots, discounts, amounts paid, currency, status, provider references, timestamps and accepted terms/refund-policy versions. Promo reservations/redemptions link the Organizer, order and discount; the system stores a code digest and suffix, not the full code. Non-personal campaign labels support aggregate reporting. Full codes are excluded from error logs and client analytics. Receipt email or phone details are passed to the payment provider to deliver the fiscal receipt. These records support service delivery, eligibility checks, reconciliation, refunds and accounting. On personal data deletion, Organizer links are removed from orders and redemptions; aggregate usage and minimal accounting snapshots remain for their applicable purposes and statutory retention periods. Provider records follow the provider’s obligations and policy. The post-removal buffer does not extend public page access.

6.3b. To enforce the "one free collection per Organizer per calendar month" limit (section 4.d), the Service keeps a separate record: the Organizer's Telegram ID and the month the free plan was used. This record has no foreign key to the Greeting and is not removed when the Greeting itself is deleted, or even when the Organizer's technical account record is deleted (if the deleted collection was their last one). A daily scheduled job deletes it automatically about 11 months after issuance, i.e. within 12 months; if deletion is delayed by a technical failure, the record is deleted as soon as the failure is fixed. It is deleted sooner on request under section 11.

6.4. Participants' Telegram user IDs and signatures are deleted together with the answers no later than 7 days after the page HTML is actually removed.

6.5. If the Organizer explicitly selects “Delete permanently,” the page and related personal data are removed from the live system immediately — except for the free-plan anti-abuse record described in section 6.3b, which by design survives Greeting deletion and follows its own retention period. Previously created, closed disaster-recovery backups may retain old data until their rotation ends, approximately up to 14 days; they are inaccessible to the application and ordinary admin interface and are used only for disaster recovery.

6.6. No automatic maximum retention period is currently implemented for unfinished drafts or the technical Organizer record created when a user only opens the Mini App. Those data remain until deletion by the Organizer or fulfillment of a request sent to the address in section 11. The Operator plans to introduce a separate retention period for inactive drafts.

6.7. No automatic maximum retention period is currently implemented for support requests. A record is retained for handling and retry until it is deleted with /delete_me or a request under section 11 is fulfilled. /delete_me removes the support record from the Service's live database. A copy already delivered to the Operator's or administrator's private Telegram chat is not automatically removed by that command and follows the settings and retention period of that Telegram chat.

7. Storage and cross-border transfer

7.1. The Service's primary production infrastructure is hosted by Hetzner Online GmbH in Helsinki, Finland. This involves cross-border processing of Service user data. Before actively acquiring users in the Russian Federation, the Operator separately verifies and implements all applicable localization and cross-border-transfer requirements.

7.2. When external services are used, data may be processed outside the Russian Federation. The exact scope depends on the selected function: Telegram for messages and media; Hetzner for the application and database; Sentry for technical diagnostics; Google Gemini API for text-processing features; payment providers for payments; and object storage for backups. The Operator transfers only data needed for the relevant function and does not send Greeting content to Yandex Metrica.

8. Transfer of PD to third parties

8.1. The Operator engages external processors and transfers data only to the extent required for a user-selected feature, security, analytics, or payment processing:

8.2. Data within a single Greeting is visible to:

9. Protection measures

The Operator takes the following technical and organizational measures:

10. Rights of the PD subject

In accordance with article 14 of 152-FZ, the PD subject has the right to:

a) obtain information about the operator processing the PD, the purposes and methods of processing; b) demand clarification, blocking, or destruction of their PD; c) request deletion by emailing the Operator at the address in section 11. The Organizer may also use “Delete permanently” in the Mini App. Complete deletion from the working system follows the timeframes in section 6; d) appeal the actions or inaction of the Operator to the authorized body for the protection of the rights of PD subjects (Roskomnadzor) or in court.

Limitation for shadow answers. Because shadow-answer content is not stored with a participant_id, the Operator may be unable to reliably match a particular answer to the requesting Participant. Such requests are reviewed individually using available information, without disclosing authorship to the Organizer.

11. Requests and inquiries

Requests and inquiries on matters of PD processing are to be sent to: chesnova.lilya@yandex.ru.

The response period is no more than 30 days from the moment the inquiry is received.

12. Withdrawal of consent

Consent to PD processing may be withdrawn by email to chesnova.lilya@yandex.ru. The Organizer may also use “Delete permanently” in the Mini App. After withdrawal, processing ceases, and the data is deleted within the periods specified in section 6 and section 10(c).

13. Changes to the Policy

The Operator has the right to make changes to this Policy. The current revision is available at the permanent link: https://from-friends.space/privacy/.

In case of material changes, the Operator notifies current users through the bot.