Privacy Policy
aisavetime.ru — AI personal assistant service. Last updated: August 18, 2026.
This Privacy Policy explains what information the aisavetime service ("we", "the Service")
collects, how it is used, and your choices. The Service is an AI-powered personal assistant
that operates through Telegram and helps users manage tasks and create and publish their own
content to their social media accounts.
1. Information we collect
- Account information — your Telegram user ID and display name, used to identify
your workspace.
- Messages and content — text, voice messages, photos, videos and documents you send
to your assistant, so it can perform the tasks you request (e.g. transcribe, edit,
caption and publish your videos).
- Social account tokens — when you connect a social account (Instagram, Threads,
YouTube, TikTok), we store the access token authorizing the Service to publish content
on your behalf. We never see or store your social media passwords.
- Usage data — technical logs (timestamps, error diagnostics) needed to operate the
Service.
2. How we use information
- To provide assistant features you request: task management, reminders, content creation,
video editing and publishing to accounts you connected.
- To process your content with AI models (see Section 3).
- To maintain, debug and improve the Service.
We do not sell your personal data, do not use it for advertising, and do not share it
with third parties except as described below.
3. Third-party services
To perform the tasks you request, the Service uses third-party APIs and processes the minimum
data required:
- AI providers (Anthropic, OpenAI) — your messages and content are processed by AI
models to generate responses, transcriptions and captions.
- Meta Platforms (Instagram, Threads) — to publish content to your connected accounts.
- Google / YouTube — to upload videos to your connected YouTube channel. The Service
uses YouTube API Services; by connecting YouTube you agree to the
YouTube Terms of Service. Google's handling
of data is described in the Google Privacy
Policy. You can revoke the Service's access at any time at
Google security
settings. Our use and transfer of information received from Google APIs adheres to the
Google API
Services User Data Policy, including the Limited Use requirements.
- TikTok — to publish videos to your connected TikTok account. You can revoke access
in your TikTok app settings at any time.
- Telegram — the Service communicates with you through the Telegram Bot API.
4. Data storage and security
Data is stored on a dedicated server located in the European Union (Amsterdam, Netherlands).
Social account tokens are used exclusively to perform actions you explicitly request or schedule.
We apply the following data protection mechanisms to all user data, including sensitive data
obtained through Google APIs:
- Encryption in transit — all connections to the Service, to its web application and
to every third-party API are made over HTTPS/TLS. The Service does not accept plain HTTP
requests for user data.
- Encryption of backups at rest — database backups are encrypted with AES-256-CBC
(PBKDF2 key derivation) before leaving the server, and the encryption key is never stored
alongside the backups.
- Access control on the server — user data and access tokens are stored in files
readable only by the dedicated service account that runs the application (file mode 0600,
non-root user). Administrative access to the server is possible only via SSH public-key
authentication; password authentication is disabled.
- Credential isolation — OAuth access and refresh tokens are held in a dedicated
secrets store, separate from application content, and are never written to logs, never
exposed to the web client and never transmitted to any third party. User-generated code
execution runs under a separate operating-system account that has no access to the
credential store.
- Request authentication — every request from the web application is verified against
a Telegram-signed identity token, and every incoming platform webhook is verified by HMAC
signature; unsigned or incorrectly signed requests are rejected.
- Data minimisation — the Service requests the narrowest scopes sufficient for the
features you use, retrieves only the data required to perform the action you requested,
and does not copy your social media data into any external system. Voice recordings sent
for transcription are processed in memory and are not written to disk.
- Least privilege and accountability — access to production data is limited to the
Service operator (a single named individual); no employees, contractors or subprocessors
other than the providers listed in Section 3 have access to user data.
- Incident handling — application errors and security-relevant events are logged and
reviewed. If a breach affecting your data occurs, we will notify affected users by the
contact channel available to us without undue delay.
Data obtained through Google APIs is never used to develop, improve or train generalized AI
or machine-learning models, and is never sold or transferred to third parties for advertising
or any other purpose outside the features you explicitly request.
5. Data retention and deletion
We retain your data while you use the Service. You may disconnect any social account at any
time (which invalidates its token), and you may request full deletion of your data by contacting
us — we will delete it within 30 days.
6. Changes
We may update this policy; the current version is always available at this address.
7. Contact
Questions and data requests: nikitacuper1994@gmail.com