Privacy Policy
Revision of 29 August 2026
This is a translation. The binding text of this Policy is the Russian one — see the Russian version. The translation is here so you can read the Policy in English; where the two differ, the Russian text governs. Questions about any clause: support@everhoot.com.
1. General provisions
This Policy sets out how the data of EverHoot users is processed. The operator of the processing is The everhoot.com website administration (contacts — in section 10). The Policy is drawn up with regard to Federal Law No. 152-FZ of 27 July 2006 “On Personal Data” and Federal Law No. 149-FZ of 27 July 2006 “On Information, Information Technologies and Protection of Information”.
2. What data is processed
| Category | Contents | Source |
|---|---|---|
| Identification | Telegram account identifier, name, username, interface language, identifier of the chat with the bot | Passed by Telegram when the bot or the mini app is started |
| User content | Texts of contacts and posts, group settings, uploaded images | Created by the User |
| Correspondence | Messages of incognito chats between the owner of a link and the senders | The participants of the correspondence |
| Service data | Group moderation journal, publishing errors, time of last sign-in, time zone | Generated automatically while the Service runs |
| Proof of consent | Version of the accepted documents, time and place of acceptance (in the app or in the bot chat), IP address and browser string at that moment | The User's request when accepting the documents |
The Service does not request and does not store phone numbers, identity document or payment details, and uses no advertising trackers or third-party analytics.
3. Purposes of processing
The main purpose is performing the contract with the User: delivering messages, publishing materials at the appointed time, moderating groups according to the rules that were set, keeping a journal of decisions and providing technical support. In addition, materials are reviewed for content whose distribution is prohibited or restricted by law, on the basis of the operator's legitimate interests (section 4).
4. Legal grounds
- performance of a contract to which the data subject is a party (the public offer);
- the subject’s consent, given at the first start of the Service;
- the operator’s legitimate interest in protecting the Service from abuse.
5. Storage periods
| Data | Period |
|---|---|
| Contents of incognito chats | 180 days from the message |
| Text of a message deleted by its author (the other side sees a "deleted" mark) | 180 days from the deletion |
| Details of a conversation without its contents: which contact and which account it ran between, when it started and when the last message was | 1 year |
| A contact after the User deletes it: name, description, links and the related conversations | 180 days from the deletion |
| Published and cancelled posts, the history of their publication | 180 days |
| Drafts and scheduled posts | until the User deletes them |
| Group moderation journal | 1 year |
| Support requests | 1 year |
| Snippets saved in the bot chat | 24 hours if unused, 180 days once used |
| Profile and settings, including a copy of the profile photo and photos of connected chats | 90 days from a deletion request; if unused — one year without a sign-in, then a warning in the bot chat and deletion a month later. Automatic deletion does not apply to an account blocked for a violation: its data is deleted on request to support |
| Depersonalised record of an account deletion | 180 days from the request |
| Record of an account blocked for violating the Rules: date, reason, list of targets, Telegram identifier and name as of the decision | 3 years from the date of blocking |
| Proof of consent to the documents, including IP address and browser string | while the account exists; deleted together with it |
| Log of administration decisions: blocks and their removal | 3 years |
| Posts suggested by subscribers: sender's name, Telegram identifier, text | 180 days from the channel owner's decision, or from submission if there was none |
| Members of connected groups: identifier and join date (needed for the captcha and the warning counter) | while the bot is in the group; the records are erased 30 days after it is removed |
| The owner's block list: who they blocked in their groups and chats — Telegram identifier, where the block came from, and the reason if they gave one | while the block is in force: the owner can lift it at any time |
| Records of destroyed materials: what was destroyed and when, without the materials themselves | indefinitely — this is the proof that retention periods are met |
| Materials of an account blocked for a violation: texts of publications and details of attachments (Telegram identifiers, not the files themselves) | 1 year from the date of blocking |
| Backups | up to 60 days |
Drafts and scheduled posts are deleted by the User immediately and irreversibly. Deleting a message or a contact hides it from the interface at once, while final erasure happens when the period above expires: until then the other side sees a deletion mark on a message, and a contact is erased together with its conversations.
5.1. Account deletion
Deletion is started with the /delete command in the bot chat or from the app settings and requires confirmation. From the moment of confirmation the Service is suspended for the User: incognito contacts stop accepting messages, scheduled posts are moved to drafts and do not go out, group moderation is not performed. If the request is cancelled, the posts stay drafts — the User decides whether to put them back on the schedule.
Within 90 days the request can be cancelled with one button, and the data is kept in full. Once 90 days pass, the profile, correspondence, posts, group and channel settings are deleted and uploaded files are erased from disk irreversibly; the service journal keeps only a depersonalised record: the file’s identifier (token), its type, size and date of deletion — without the content.
A depersonalised record of the fact of deletion (an irreversible fingerprint instead of the identifier, dates of the request and of the deletion, counts) is kept for 180 days from the request — it is needed to handle enquiries and disputes. After that period it is deleted too.
6. Where the data is processed
Processing takes place on a server located in the Swiss Confederation. Backups are placed with a third-party object storage provider located in the Russian Federation: there is no public access to them, and they are retrieved with the operator's keys. Only the operator has access to the infrastructure; authorisation is by cryptographic key.
Switzerland provides an adequate level of protection of the rights of personal data subjects: it is on the list of states party to the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data.
7. Disclosure to third parties
Data is not sold. It is passed to third parties only where the Service cannot work without it: Telegram Messenger Inc. — it is through its API that messages, posts and notifications initiated by the User travel; and the infrastructure providers whose servers run the Service and hold the backups, in the countries named in section 6. The infrastructure providers act on the operator's instructions: they supply capacity and storage and do not use the data for their own purposes.
8. Rights of the data subject
The User has the right to:
- obtain information about the data being processed;
- demand that data be corrected, blocked or destroyed;
- withdraw consent to processing;
- delete contacts, posts and groups themselves in the app;
- delete the whole account — with the
/deletecommand or from the app settings.
Requests are sent to support@everhoot.comand are handled within 30 calendar days.
9. Protection measures
- data is transferred over HTTPS only;
- identification is by Telegram’s signature; the Service stores no passwords;
- contact avatars are re-encoded, which discards photo metadata; other files are not modified by the Service — any metadata present in the original is kept and passed to Telegram with the file;
- server access is by key only, password authentication is disabled;
- regular backups with restore checks.
10. Operator’s contacts
The everhoot.com website administration
Website: everhoot.com
App: app.everhoot.com
Email: support@everhoot.com
11. Changes to the Policy
A new revision takes effect from the moment it is published on this page. Where the change is material, the Service asks the User for consent again.