Security — DeletedGuard

Security

What exists, what does not, and what you decide yourself

In short

To send you a copy of a deleted message, the service has to receive that message and store it. So conversations from connected chats do reach our server — otherwise there would be nothing to restore. Everything else on this page is about what we do with them, and what we do not.

What exists

  • AES-GCM encryption. Every message is encrypted under its own key before it reaches the database.
  • Key rotation. Data keys change automatically, every 1–7 days.
  • Sender names are encrypted separately. Only a numeric Telegram id sits next to a message; the name and @username live in a separate encrypted directory.
  • Backups are encrypted and stored apart from the database.
  • Security scanner runs and internal code reviews.
  • Complete deletion on your command/my_data in the bot.

What does not exist — and we say so plainly

  • An independent third-party audit. There has not been one. Everything above is our own statement, not the finding of an independent review.
  • Open source code. Our claims cannot be checked against the code.
  • A bug bounty programme.
  • End-to-end encryption.

We write this ourselves because we think the decision to trust a service with your conversations should be made with the full picture rather than the marketing one.

What the encryption actually protects

Every message is encrypted with AES-256-GCM under its own key before it reaches the database. The keys themselves are not kept in that database and rotate automatically every 1–7 days. Sender names and @usernames are encrypted separately — only a numeric Telegram id sits next to a message.

Which gives the guarantee that matters: a stolen database is useless. Neither a copy of the database, nor a backup archive, nor the hosting provider's access to the disk yields the text of your conversations — or even the picture of who talked to whom and when. Backups are stored encrypted as well.

Where all of this is kept

The server is located in Russia, at the hosting provider Beget LLC. Data is not passed to third parties and is not used for advertising. Requests under GDPR are accepted through support.

How long we keep your data

Retention equals the length of your access. When it ends, saved messages do not vanish at once: for three days the service behaves as if the subscription were active — enough time to renew — and then a window opens in which what is already saved stays readable.

AccessKept while it lastsStill readable afterwards
3-day trial3 days7 days
Monthly plan30 days7 days
Yearly plan365 days30 days
Privacy modecontent is not stored at all; deletion facts live 24 hours

That period is a maximum, not an obligation

You control it yourself, with the /retention command in the bot:

  • Shorten it at any moment, down to a single day. The one-day option is available on every plan.
  • Privacy mode stores no content at all — only the bare facts that something was deleted, and those for 24 hours.
  • It cannot be extended beyond the access you paid for. We keep data exactly as long as the access lasts, not a day longer.

Disconnecting the bot in Telegram settings stops new messages from being saved, but does not by itself erase what is already stored — /my_data does that.

Which permissions the bot does not hold

On connection Telegram shows the line "the bot manages your account". That is the name of a whole permission group, not a description of what this particular bot received. DeletedGuard cannot change your name, @username, photo or bio, post stories, or dispose of gifts and stars.

You can verify it in half a minute: Telegram Settings → Telegram Business → Chatbots → our bot → Permissions. Nothing should be enabled under "Profile".

Security questions — @DeletedGuard_support. Full wording is in the privacy policy and the terms of service.

Try 3 days free