मुख्य सामग्री पर जाएँ
Legal

Privacy Policy

This policy explains what KROOZ collects, why, and the choices you have. We aim to collect the minimum we need to run the service.

Last updated 2026-05-31

1. Who is responsible

For your dashboard account, KROOZ is the data controller. For your subscribers' data inside your bot, you are the controller and KROOZ processes that data on your behalf.

2. What we collect

Account data: your email, name, and authentication credentials (passwords are hashed; we never store them in plain text).

Operational data: bot tokens and payment-provider keys, which are encrypted at rest and never logged in full.

Subscriber data on your behalf: Telegram user IDs, usernames, language, and subscription state — the minimum needed to grant and revoke access.

Usage and analytics needed to operate and improve the product.

3. How we use it

To provide the service, process your platform-fee billing, secure accounts, prevent abuse, and meet legal obligations. We do not sell personal data.

4. Security

Secrets (bot tokens, provider keys, webhook secrets) are encrypted at rest. Webhook payloads are signature-verified. Payment writes are idempotent. Access is least-privilege via role-based permissions.

5. Your rights

Subject to applicable law, you may request access to, correction of, or deletion of your data. Data export and deletion tooling is available for subscriber data so you can meet your own obligations to your members.

6. Retention

We keep data for as long as your account is active and as needed for legal and operational purposes, then delete or anonymize it.

7. Contact

Privacy questions or requests? Use the contact page.

This document is provided for general information and is not legal advice. KROOZ is a tool; you are the merchant of record for transactions with your subscribers.