Privacy Policy
This Privacy Policy explains how Botalka (“the App”, “we”, “us”) accesses, collects, uses, stores, and shares information when you use the App. It is written to meet Google Play User Data expectations: transparency about data practices, a privacy contact, retention and deletion, and secure handling.
1. Who we are
Botalka is an independent Android application that lets you create and run AI-powered bots that work with the Telegram Bot API from your phone. Botalka is not affiliated with, endorsed by, or sponsored by Telegram Messenger Inc. “Telegram” is a trademark of its respective owners.
2. What the App does
When you use Botalka, you can:
- Create an account (email/password or Google Sign-In)
- Configure bots (name, personality instructions, group reply settings)
- Store a Telegram bot token from BotFather on your device
- Run bots via a foreground service that long-polls Telegram and sends AI replies
3. Information we collect and process
We collect and process only what is needed to provide Botalka’s core features. We do not sell personal data. We do not use advertising SDKs, and the App currently does not include Firebase Analytics or Crashlytics.
| Data | Examples | Where it goes |
|---|---|---|
| Account data | Email address, password (hashed by Firebase), Google account ID token, Firebase user ID | Firebase Authentication (Google) |
| Bot configuration | Bot name, instructions/personality text, Telegram username (optional), group reply mode, enabled flag, timestamps | Cloud Firestore under your account (users/{uid}/bots/…) |
| Telegram bot token | BotFather token you paste into the App | Stored only on your device (local preferences). Not uploaded to Firestore. Sent to Telegram’s servers when the bot runs. |
| Message content | Incoming Telegram message text; short recent chat history kept in memory (about 12 turns); AI-generated replies | Processed on device in memory; sent to Telegram Bot API and to Google Gemini via Firebase AI Logic to generate replies. Not saved to Firestore by Botalka. |
| App preferences | Selected Gemini model name | Local device storage |
| Integrity / abuse protection | App Check / Play Integrity attestation signals | Google / Firebase App Check (to protect AI and backend abuse) |
| Technical / device signals | Standard network and OS signals needed for HTTPS, Auth, and Play services | Google Play services / Firebase as part of those services (no advertising ID collection by Botalka) |
3.1 Data about people who message your bots
If you run a bot, Telegram users who chat with that bot send messages that Botalka processes on your phone and forwards to the AI provider to generate replies. You are responsible for how you operate your bots and for complying with Telegram’s terms and applicable privacy laws toward those end users. Botalka does not provide a separate account for those end users.
4. How we use information
- Authenticate you and sync bot configuration across your devices
- Keep your Telegram bots online while the App’s runtime is running
- Fetch updates and send replies through the Telegram Bot API
- Generate AI replies with Gemini through Firebase AI Logic
- Protect the service from abuse (App Check / Play Integrity)
- Respond to privacy or support requests you send us
- Comply with law when required
5. Who we share data with
We share data with service providers only as needed to run the App—not for advertising, and not for sale:
- Telegram (Telegram Privacy Policy) — bot tokens, chat IDs, and message content for Bot API calls
- Google / Firebase (Auth, Cloud Firestore, Firebase AI Logic / Gemini, App Check, Play Integrity) — account data, bot configuration, AI prompts/completions, integrity tokens. See Google Privacy Policy and applicable Gemini / Firebase terms for how Google processes AI inputs.
- Google Sign-In / Credential Manager — if you choose Google sign-in
We may disclose information if required by law, regulation, legal process, or governmental request, or to protect users, the App, or others from harm or fraud.
6. Permissions the App uses
- Internet — Telegram and Firebase / Google services
- Foreground service / remote messaging — keep bots running while the App is in the background
- Notifications — persistent status while bots are running (and related alerts)
- Receive boot completed — restore enabled bots after device reboot or update
Runtime notification permission is requested on supported Android versions before posting notifications.
7. Storage, security, and retention
- Network traffic to Telegram and Google/Firebase uses HTTPS.
- Android backup for the App is disabled (
allowBackup=false) to reduce accidental backup of local secrets. - Telegram bot tokens are stored in on-device preferences. They are not currently encrypted at rest by the App; protect your device with a lock screen and do not root/jailbreak or share device backups of the App data.
- Chat history used for replies is kept in memory only and is discarded when the process stops.
- Bot configuration in Firestore is retained while your account exists (or until you delete the bot / account).
- Account credentials and cloud data are retained by Firebase according to your account lifecycle and Google’s retention practices for those services.
8. Your choices and rights
- Stop bots at any time in the App (stops processing new Telegram messages for those bots).
- Edit or delete individual bot configurations in the App.
- Remove local Telegram tokens by clearing App data or uninstalling the App (cloud bot config may remain until account/bot deletion).
- Request access, correction, or deletion of personal data we hold, subject to applicable law, by emailing the privacy contact above.
If you are in the EEA, UK, or Switzerland, you may also have rights under GDPR / UK GDPR (access, rectification, erasure, restriction, portability, objection) and the right to lodge a complaint with a supervisory authority. Contact us to exercise these rights.
9. Account and data deletion
Because Botalka offers account creation, you can request deletion of your account and associated App data.
External web instructions: see Account deletion.
Summary of what we delete on a verified request:
- Your Firebase Authentication account
- Bot configuration stored in Firestore under your user ID
Local data on your device (including Telegram tokens) is removed by clearing App storage or uninstalling Botalka. Message content that already left your device via Telegram or Google/Gemini is subject to those providers’ retention policies and is outside Botalka’s direct control after transmission.
We aim to complete account deletion within 30 days of a verified request (often sooner). We may retain limited records if required for security, fraud prevention, or legal compliance, and we will disclose that where applicable.
10. Children
Botalka is not directed to children under 13 (or the minimum age required in your country). We do not knowingly collect personal data from children. If you believe a child has provided data, contact us and we will delete it.
11. International transfers
Firebase / Google and Telegram may process data in countries other than where you live. Those providers apply their own transfer mechanisms and terms. By using the App, you understand that your data may be processed outside your country.
12. Changes to this policy
We may update this Privacy Policy when the App’s data practices change. The “Last updated” date at the top will change. Continued use of the App after an update means you accept the revised policy, unless applicable law requires additional consent.
13. Contact
Privacy questions, data requests, and account deletion requests:
igautomation@igautomation.com