Personal Data Processing Policy
Service: from-friends.space, the Telegram bot @from_friends_bot, and the related From Friends Mini App — a service for creating collaborative pages from loved ones' words, stories, voice notes, videos, and photos (hereinafter — the "Service"). Operator: Individual Entrepreneur Chesnova Lilya Gennadyevna, OGRNIP 320774600424255, INN 772985080404 (hereinafter — the "Operator"). Contact: chesnova.lilya@yandex.ru Revision of: September 19, 2026 Version: 1.4
1. General provisions
1.1. This Policy is drawn up in accordance with the requirements of Federal Law No. 152-FZ of 27.07.2006 "On Personal Data" (hereinafter — 152-FZ) and defines the procedure for processing personal data and the measures to ensure their security taken by the Operator.
1.2. The Operator sets as its most important goal the observance of the rights and freedoms of the individual and citizen in the processing of their personal data, including the protection of the rights to privacy of private life, personal and family secrecy.
1.3. This Policy applies to all personal data that the Operator may obtain from users of the Service.
2. Key terms
- Personal data (PD) — any information relating directly or indirectly to a specified or identifiable natural person.
- Processing of PD — any action (operation) or set of actions with PD (collection, recording, systematization, accumulation, storage, clarification, use, transfer, deletion, destruction).
- Organizer — a user who has opened the Mini App and started or completed creation of a Greeting; payment is not required for this status.
- Participant — a user of the Service who has followed the Organizer's invitation and left a greeting.
- Recipient — the person for whom the Greeting is created. Their name, event date, and optional contact details are provided by the Organizer rather than by the Recipient.
- Greeting — the set of questions, participants' answers, and the HTML page generated from them, created within a single instance of the service.
3. Categories of PD subjects and composition of the data processed
3.1. Organizer
| PD category | Source | Purpose |
|---|---|---|
| Telegram user ID, name, username | Telegram WebApp API when opening the Mini App | Identification in the Service, delivery of links and notifications |
| Recipient's name, event date, optionally @username/phone | Provided by the Organizer in the interview | Creation of a personalized greeting |
| Text of "what matters for the atmosphere", list of questions, styling | Provided by the Organizer | Configuration of the Greeting and the book template |
| Orders, plan and price snapshots, discounts, payment/refund amounts, statuses and dates | Service and payment provider; legacy manual confirmation | Service delivery, reconciliation, refunds, accounting and tax records |
| Receipt email or phone; promo usage and non-personal campaign label; accepted terms version and timestamp | Organizer checkout action and Service | Receipt delivery, promo eligibility and limits, evidence of agreed order terms (see section 6.3a) |
Short acquisition-source label (for example, guide_questions) | From the current public-site referral link; submitted only when a collection is created after the Organizer consents | Aggregate evaluation of acquisition sources and the creation/payment funnel without advertising personalization |
3.2. Participant
| PD category | Source | Purpose |
|---|---|---|
| Telegram user ID, name, username | Telegram Bot API when following the deep-link | Identification of the participant within the Greeting, linking answers to a signature |
| Answer contents: text, voice messages, video notes, photos | Sent by the Participant | Inclusion in the HTML greeting passed to the Birthday person |
| The signature under which the Participant wishes to be listed | Provided by the Participant | Signature of the answer in the book |
| Consent to PD processing and its date/time | Action of the Participant in the bot | Confirmation of the legal grounds for processing |
3.3. Anonymous ("shadow") answers
3.3.1. The Service allows the Organizer to mark individual questions as shadow (anonymous).
3.3.2. The content of a shadow answer is stored without a participant_id and shown to the Organizer without authorship. Technical participation records and event timestamps are stored separately; the text or image may also identify its author by its content. The Service therefore does not guarantee absolute anonymity.
3.3.3. For shadow answers, only text and photos are allowed; voice messages and video notes are prohibited, since their content may make it possible to identify the author.
3.4. Public website visitor
After the visitor gives separate consent, the website sends Yandex Metrica technical and statistical data: IP address, the Metrica cookie identifier, browser and device information, visited public pages, referral source, and the fact of clicking through to Telegram. Greeting content, Telegram user IDs, and Mini App data are not sent to Metrica.
3.5. User contacting support
When /feedback is submitted, the Service stores the Telegram user, chat and message IDs, name, language, text or caption, a supported Telegram file reference for a photo or voice message, delivery status and timestamps. These data are used to handle the request and retry delivery after a temporary error. The request is delivered privately to the Operator or an appointed administrator; the recipient's public username is not disclosed to the user.
4. Purposes of PD processing
The Operator processes PD solely for:
a) providing the Service (creating the Greeting, delivering it to the Birthday person); b) identifying and communicating with the Organizer/Participant in Telegram; c) accounting for payment of the service; d) fulfilling the requirements of 152-FZ and other applicable legislation of the Russian Federation; e) ensuring the security of the Service and preventing abuse; f) analyzing visits to public pages and click-throughs to Telegram, only after the visitor's consent; g) aggregate evaluation of which sources lead to created and paid Greetings, using a short referral label and without advertising personalization.
The Operator does not use PD for marketing, profiling, transfer to third parties for commercial purposes, and does not sell PD.
5. Legal grounds for processing
5.1. Consent of the PD subject (clause 1, part 1, article 6 of 152-FZ) is the main ground for Greeting content. Consent is recorded:
- for the Organizer — through separate personal data consent referring to this Policy while creating the first Greeting. When the Mini App is first opened, before that confirmation, the Service already receives from Telegram a technical identifier, name/username when available, language, and opening time in order to establish the session and display existing drafts;
- for the Participant — at first contact with the bot via deep-link, by the "Agree and continue" button.
5.2. Contract / provision of the service (clause 5, part 1, article 6 of 152-FZ) — for establishing the Organizer's session, authentication, displaying collections belonging to the Organizer, preventing access to other users' collections, payment, and service delivery. No new Greeting content is created before separate explicit consent.
5.3. Obligations established by law (clause 2, part 1, article 6 of 152-FZ) — for accounting and tax records (402-FZ, the Tax Code).
5.4. Yandex Metrica is enabled on public pages only after the visitor clicks the consent button. Refusal does not restrict viewing the website or using the Service's core features. Further collection can be stopped through “Analytics settings”; data previously retained by Yandex is handled under Yandex Metrica's applicable rules. The visitor may also contact the Operator.
5.5. The short acquisition-source label contains no Telegram ID, Metrica cookie, or Greeting content. Before a Greeting is created it remains only in the current Mini App session; the Service stores it with the Greeting only after the Organizer's explicit consent. This Mini App label is not sent to Yandex Metrica.
5.6. Personal data consent is obtained separately from acceptance of service and refund terms. Neither reading the Policy nor accepting checkout terms replaces explicit personal data consent.
6. Term and procedure for storing PD
6.1. All new plans provide access and storage for 365 days, starting at first publication. Republishing or rebuilding does not restart the period. A paid upgrade does not restart or shorten the access period already granted. Existing legacy collections retain their previous conditions, including extensions; their standard period is 90 days. The actual expiry date appears in the Mini App. Free legacy extensions do not apply to new plans.
6.2. After the published page's final expiry, including all extensions, a scheduled job removes its HTML. Raw answers (text and media links) are deleted no later than 7 days after the HTML is actually removed. This period is used as a buffer in case of claims or restoration.
6.3. After content deletion, only anonymized information required for accounting and tax records is retained: payment fact, recorded amount (if available), status, date, and a safe payment reference. If a payment identifier contains the original Greeting ID, only its irreversible SHA-256 reference is retained. The Organizer's Telegram ID, the birthday person's name, and the original Greeting identifier are not included in that record. One explicit exception to this rule is the free-plan anti-abuse record described in section 6.3b: it directly contains the Organizer's Telegram ID and is not anonymized.
6.3a. Quotes, initial and upgrade orders store plan and price snapshots, discounts, amounts paid, currency, status, provider references, timestamps and accepted terms/refund-policy versions. Promo reservations/redemptions link the Organizer, order and discount; the system stores a code digest and suffix, not the full code. Non-personal campaign labels support aggregate reporting. Full codes are excluded from error logs and client analytics. Receipt email or phone details are passed to the payment provider to deliver the fiscal receipt. These records support service delivery, eligibility checks, reconciliation, refunds and accounting. On personal data deletion, Organizer links are removed from orders and redemptions; aggregate usage and minimal accounting snapshots remain for their applicable purposes and statutory retention periods. Provider records follow the provider’s obligations and policy. The post-removal buffer does not extend public page access.
6.3b. To enforce the "one free collection per Organizer per calendar month" limit (section 4.d), the Service keeps a separate record: the Organizer's Telegram ID and the month the free plan was used. This record has no foreign key to the Greeting and is not removed when the Greeting itself is deleted, or even when the Organizer's technical account record is deleted (if the deleted collection was their last one). A daily scheduled job deletes it automatically about 11 months after issuance, i.e. within 12 months; if deletion is delayed by a technical failure, the record is deleted as soon as the failure is fixed. It is deleted sooner on request under section 11.
6.4. Participants' Telegram user IDs and signatures are deleted together with the answers no later than 7 days after the page HTML is actually removed.
6.5. If the Organizer explicitly selects “Delete permanently,” the page and related personal data are removed from the live system immediately — except for the free-plan anti-abuse record described in section 6.3b, which by design survives Greeting deletion and follows its own retention period. Previously created, closed disaster-recovery backups may retain old data until their rotation ends, approximately up to 14 days; they are inaccessible to the application and ordinary admin interface and are used only for disaster recovery.
6.6. No automatic maximum retention period is currently implemented for unfinished drafts or the technical Organizer record created when a user only opens the Mini App. Those data remain until deletion by the Organizer or fulfillment of a request sent to the address in section 11. The Operator plans to introduce a separate retention period for inactive drafts.
6.7. No automatic maximum retention period is currently implemented for support requests. A record is retained for handling and retry until it is deleted with /delete_me or a request under section 11 is fulfilled. /delete_me removes the support record from the Service's live database. A copy already delivered to the Operator's or administrator's private Telegram chat is not automatically removed by that command and follows the settings and retention period of that Telegram chat.
7. Storage and cross-border transfer
7.1. The Service's primary production infrastructure is hosted by Hetzner Online GmbH in Helsinki, Finland. This involves cross-border processing of Service user data. Before actively acquiring users in the Russian Federation, the Operator separately verifies and implements all applicable localization and cross-border-transfer requirements.
7.2. When external services are used, data may be processed outside the Russian Federation. The exact scope depends on the selected function: Telegram for messages and media; Hetzner for the application and database; Sentry for technical diagnostics; Google Gemini API for text-processing features; payment providers for payments; and object storage for backups. The Operator transfers only data needed for the relevant function and does not send Greeting content to Yandex Metrica.
8. Transfer of PD to third parties
8.1. The Operator engages external processors and transfers data only to the extent required for a user-selected feature, security, analytics, or payment processing:
- technically necessary transfer through the Telegram Bot API (Telegram Messenger Inc.) — for the bot's operation;
- YANDEX LLC — for consent-based analytics of visits to the public website through Yandex Metrica;
- Hetzner Online GmbH — as the production infrastructure and technical storage provider;
- Functional Software, Inc. (Sentry) — for technical error diagnostics; sending PD by default is disabled and selected technical fields are filtered;
- Google LLC (Gemini API) — for text-processing features when such a feature is invoked in the Service;
- T-Bank JSC and/or another payment provider shown to the user — for processing and confirming a payment;
- the object-storage provider used for disaster-recovery backups;
- at the request of authorized state bodies in cases established by the law of the Russian Federation;
8.2. Data within a single Greeting is visible to:
- the Organizer — all answers of the participants of this Greeting, except shadow answers linked to their authors (the Organizer sees shadow answers only in a depersonalized form);
- the Participant — only their own answers and the overall progress in a depersonalized form ("40% of participants have answered");
- the Recipient and other people who receive the final link; if the Organizer enables a password, people who have both the link and password.
9. Protection measures
The Operator takes the following technical and organizational measures:
- HMAC validation of Telegram WebApp initData on every request to the API;
- HTTPS/TLS on all public endpoints (Let's Encrypt);
- storage of secrets outside the source code (environment variables);
- an automatic scrubber masking any tokens and secrets in logs;
- access to production infrastructure — only for the Operator;
- automatic monitoring via Sentry with PD transmission disabled by default and selected technical fields filtered;
- closed disaster-recovery backups with rotation of approximately up to 14 days; they are inaccessible to the application and ordinary admin interface.
10. Rights of the PD subject
In accordance with article 14 of 152-FZ, the PD subject has the right to:
a) obtain information about the operator processing the PD, the purposes and methods of processing; b) demand clarification, blocking, or destruction of their PD; c) request deletion by emailing the Operator at the address in section 11. The Organizer may also use “Delete permanently” in the Mini App. Complete deletion from the working system follows the timeframes in section 6; d) appeal the actions or inaction of the Operator to the authorized body for the protection of the rights of PD subjects (Roskomnadzor) or in court.
Limitation for shadow answers. Because shadow-answer content is not stored with a participant_id, the Operator may be unable to reliably match a particular answer to the requesting Participant. Such requests are reviewed individually using available information, without disclosing authorship to the Organizer.
11. Requests and inquiries
Requests and inquiries on matters of PD processing are to be sent to: chesnova.lilya@yandex.ru.
The response period is no more than 30 days from the moment the inquiry is received.
12. Withdrawal of consent
Consent to PD processing may be withdrawn by email to chesnova.lilya@yandex.ru. The Organizer may also use “Delete permanently” in the Mini App. After withdrawal, processing ceases, and the data is deleted within the periods specified in section 6 and section 10(c).
13. Changes to the Policy
The Operator has the right to make changes to this Policy. The current revision is available at the permanent link: https://from-friends.space/privacy/.
In case of material changes, the Operator notifies current users through the bot.