Privacy Policy — DeletedGuard

Privacy Policy

Telegram bot DeletedGuard

Published: 7 June 2026
In effect from: 7 June 2026
Support: @DeletedGuard_support

1. The short version

DeletedGuard is a Telegram bot that saves copies of incoming messages in your private chats and shows them to you when the other person deletes or edits the original. The bot only works with the chats you have explicitly connected through Chat Automation in your Telegram settings.

We treat your data the way we would want ours treated: we keep the minimum, we encrypt the content, we share it with nobody, and we give you full control through the /my_data command.

2. Who the data controller is

The controller is the bot's administrator. Contact: @DeletedGuard_support.

The bot operates on the basis of the User's consent, given at the first /start (recorded in the privacy_accepted_at field). Without that consent, paid features are unavailable.

3. What data we collect

Automatically, when you connect

  • Your Telegram ID, username and name — needed to know who to show the recovered messages to.
  • The ID of the connected Business connection — issued by Telegram itself when you add the bot through Chat Automation.

While working in private chats

  • The content of incoming messages (text, media identifiers, metadata) — only from the chats covered by the Business connection.
  • Content is not stored for non-subscribers: for them we keep only the fact of a deletion (metadata without text) for 24 hours.
  • The other person's signature — name and @username — is stored encrypted, in a separate directory. Only a numeric Telegram identifier sits next to the message itself.

When you pay

  • The Telegram payment identifier, the amount, and the type of purchase (subscription / group pack / archive). We never receive card numbers or payment credentials — those are handled by Telegram and the payment providers.

When you use the referral programme

  • Who invited whom, and the fact that the new User accepted the Terms.

What we do NOT collect

  • Messages from chats you have not connected through Chat Automation.
  • Messages the sender deleted on their side but not on yours (a technical limitation of Telegram — the bot only sees what Telegram delivers through the Business API).
  • Calls, voice contacts, or profile data about the people you talk to beyond their name and username.

4. Where and how we store it

  • Server: a VPS in a data centre in the Russian Federation (hosting provider Beget LLC).
  • Database: SQLite, encrypted at the application level.
  • Message content is encrypted with AES-GCM using a unique data key, which is itself protected by a master key (Fernet). The data key rotates automatically every 1–7 days.
  • Without the master key, decrypting the stored messages is impossible — not even the administration holds a plaintext copy.

5. How long we keep it

CategoryRetention
Messages — by defaultas long as your access lasts
Trial period3 days
Monthly plan30 days
Yearly plan365 days
Privacy mode (chosen by the User)24 hours
Deletion metadata for non-subscribers24 hours
Payment metadatauntil the account is deleted
Referral linksuntil the account is deleted

Retention equals the length of your access. Bonus days extend both: subscribe to our channel or answer one of our questions and the retention window grows by exactly the same number of days. You cannot choose a window longer than what you were granted; you can shorten it at any time, and the 1-day option is available to everyone.

Old records are removed automatically by a background job once an hour. After a paid period ends, data does not disappear at once: for 3 days the service works as it does on an active subscription (the trial period has no such grace), then a window opens in which everything already saved stays available — 7 days for the Monthly plan and the trial, 30 days for the Yearly plan — after which only metadata remains for 24 hours, and then everything is deleted for good.

6. Who we share data with

Nobody, without your explicit consent, except:

  • Telegram — the platform the bot runs on.
  • Telegram's payment provider (to process payments in Stars).
  • The VPS hosting provider (to store the encrypted database) — with no access to the master key.

We do not sell, rent out or hand over your data for marketing or advertising purposes.

7. Encryption and security

  • The content of every stored message is encrypted at the application level before it is written to the database.
  • The master key is stored separately from the database, is inaccessible to other processes, and never reaches logs or database backups.
  • Database backups are stored encrypted; without the master key they cannot be read.
  • Communication between the bot and Telegram runs over HTTPS.
  • Server access is by the administration's SSH key only.

Should an incident occur that may have compromised data, we will notify affected Users through the bot within 72 hours.

8. Your rights

  • See your data/my_data → "Export all data (CSV)".
  • Delete all your data/my_data → "Delete all my data". Deletion is immediate and irreversible: messages and their full edit history, archives, tracked groups, contact names, chat titles, achievements, monthly summaries and answers to our questions are erased.
    Kept on purpose: the account itself, a paid subscription and payment records — they are needed in a dispute or refund and prove your right of access — plus the markers for bonuses already granted, without which they could be claimed again after every cleanup.
  • Change the retention period/retention in the bot or "More → Retention" in the app. The available options depend on the length of your access: you can always shorten it, but never choose more than you were granted.
  • Change your time zone/timezone.
  • Withdraw consent — disconnect the bot in Chat Automation and run /my_data → delete. After that the bot stops receiving your data.

If any of the above doesn't work, or you have questions about how your data is handled, write to @DeletedGuard_support.

9. Changes to this policy

We may update this policy. For material changes (a wider list of collected data, different retention periods, sharing with new third parties) you will be notified through the bot at least 7 days before the changes take effect.

The current version is always available at the address this document is published under, and through the /privacy command in the bot.

10. Contact

For questions about the processing of personal data, exercising your rights, or requests under Russian law 152-FZ or the GDPR:

We aim to reply within 3 working days.


By using DeletedGuard you confirm that you have read this Privacy Policy and accept its terms.

Version 1.0 of 7 June 2026.

This is a translation of the Russian original, published at deletedguard.ru/privacy/. Should the two differ, the Russian text prevails.

Try 3 days free