Privacy Policy
1. Scope
This Policy defines how personal data is processed when using the PromtPress Platform (promtpress.com, panel.promtpress.com, mcp.promtpress.com, and related subdomains), including site visits, registration, connecting Telegram channels, using ad management tools, contacting support, and paying for services via payment providers.
2. What data is processed
The Operator follows the data minimization principle and processes only data necessary to provide services: – Customer registration and contact data (name, e-mail, password hash, Telegram username); – data of connected Telegram channels (name, ID, subscriber and post statistics); – technical data when using the site (IP address, device and browser type, visit time and pages); – payment transaction metadata (amount, currency, transaction ID, payment method) — without storing bank card or payment account details; – support requests and correspondence about services rendered; – data of subscribers of the Customer's Telegram channels acquired via the Platform: public Telegram ID, username, publicly available profile parameters. This data is processed solely for billing and anti-fraud verification. The Platform is intended for persons aged 18 and over.
3. Legal basis for processing
Processing is carried out on the basis of: – performance of the services agreement (use of the Platform); – the Operator's legitimate interests (security, anti-fraud verification, protection against fraud); – consent of the data subject (for analytical cookies and marketing communications, where applicable); – fulfillment of the Operator's legal obligations (issuing receipts, tax accounting).
4. Purposes of processing
Personal data is used solely for: – providing access to Platform features and services; – settlements and issuing receipts via the professional income tax application; – Platform security and traffic anti-fraud verification; – technical support and Customer communications; – improving the Service; – compliance with the legislation of the Republic of Belarus. Personal data is not sold to third parties and is not used for marketing profiling by third-party advertisers.
5. Categories of data recipients
Data is transferred to the following categories of recipients in the scope necessary to render services: – payment providers (for processing payments and refunds via bank cards, cryptocurrency, and bank transfers); – acquiring bank (for non-cash settlements with corporate Customers); – partner ad networks (for ad placement and subscriber acquisition); – hosting provider of the Platform infrastructure; – Telegram (as the platform on which services are rendered, regarding public channel and subscriber data). The specific list of providers and partners constitutes the Operator's trade secret and is provided upon individual request of the data subject within the exercise of their rights under personal data legislation. All recipients are required to ensure confidentiality of transferred data within their obligations under applicable legislation and contracts.
6. Cross-border data transfer
Some data recipients (payment providers, hosting provider, partner ad networks) are located outside the Republic of Belarus. Data transfer is carried out subject to the necessary contractual and technical protection measures set forth in the Law of the Republic of Belarus No. 99-Z of 07.05.2021 «On Personal Data Protection».
7. Cookies and analytics
The promtpress.com site uses only essential technical cookies required for dashboard operation and security (authentication, CSRF protection, interface preferences). Web analytics systems (Google Analytics, Yandex Metrika, and similar) are not currently used.
8. Storage period
– account data — for the duration of Service use and for 1 year after cessation of use (for dispute resolution and tax reporting); – payment data and tax receipts — for the period set by Belarusian accounting and tax law (no less than 5 years); – data of subscribers acquired via the Platform — for 12 months from the last campaign activity, after which it is anonymized; – support requests — 2 years from the date of the request. After these periods, data is deleted or anonymized.
9. Security
The Operator applies organizational and technical information-protection measures: encryption in transit (HTTPS/TLS), password hashing, key-based server access, regular backups. The Customer is responsible for the confidentiality of their credentials and access rights to connected Telegram channels.
10. Data subject rights
Under the Law of the Republic of Belarus No. 99-Z of 07.05.2021 «On Personal Data Protection», the data subject has the right to: – obtain information about the processing of their personal data; – access their personal data and obtain a copy; – request correction, deletion, or restriction of processing; – withdraw previously given consent to processing; – appeal the Operator's actions to the National Personal Data Protection Center of the Republic of Belarus. Requests are sent to hello@promtpress.com. Responses are provided within 15 business days.
11. Third-party resources
The Platform may contain links to third-party resources (Telegram, partner pages, media articles). The Operator is not responsible for personal data processing policies on third-party resources. Before using third-party resources, it is recommended to review their privacy policies.
12. Additional service «AutoContent TG»
The optional automatic content generation service uses third-party language model APIs. When using this service, submitted texts are processed on the API provider's side in accordance with their terms. The Customer independently decides whether to publish generated content and bears responsibility for its compliance with legislation and Telegram rules.
13. Access through an AI assistant (MCP)
You can connect an AI assistant — Claude, ChatGPT, Cursor and others — to your account through the mcp.promtpress.com server. This section explains what data is processed and where it goes.
What we store. The account email address, plus company name and country if you provided them. A fingerprint of the access key, never the key itself: the database holds a one-way hash from which the key cannot be recovered; the key's permissions, issue date and last use are kept. The name and callback address of the application you connected. Records of what the assistant did with campaigns and budgets: which tool was called, when, with which parameters, how it ended and for what amount. One-time confirmation codes and sign-in links, until used or expired. Technical counters of requests to the sign-in pages — the request address and the email address it targeted — needed so the sign-in form cannot be used to send mail on someone else's behalf.
What we do not store. There are no passwords in this circuit at all — access is by one-time email link only. Payment data never passes through the assistant server in any form. The contents of your conversations with the assistant are not sent to us: we receive tool calls only.
What the assistant sees, and where it goes. The assistant receives the data it requests on your behalf: balance, campaign list and statistics, balance movements. That data reaches the service you are using (Anthropic, OpenAI and others) and is handled under its rules, not ours. This is a transfer outside our perimeter, and we ask you to take it into account when choosing an assistant. You can limit the scope in advance: the "view" permission is granted separately from "prepare campaigns" and "spend budget".
Retention. Records of campaign and budget actions — 3 years: they evidence what money was spent on, and they survive account deletion, otherwise a dispute over past spending could not be resolved. Revoked refresh keys — 30 days. One-time codes and used sign-in links — 24 hours. Request counters — 7 days. Other account data follows the general terms in section 8.
Your controls. Revoking any assistant's access, freezing spending or changing limits is done in the dashboard, under Profile, at any time and without contacting us. Revocation takes effect immediately: the key stops working along with the ability to renew it.
Automated decisions. Some decisions are made without a human, under rules set in advance: checking and consuming the granted limit when a campaign launches; refusing categories we do not place; rate-limiting requests to the sign-in pages; revoking granted access if an authorization code is presented twice (a sign of interception). There is no automatic account blocking. Any automated refusal can be raised at hello@promtpress.com and we will review it manually.
When an assistant names someone else's address. An assistant may pass us the email of a person who has never contacted us, in order to invite them. In that case we create an account and send that address a message saying it was named. No access is granted at that point: it appears only after the owner of the address follows the link themselves.
Cookies. The assistant sign-in pages (mcp.promtpress.com) set no cookies: state is kept on the server under a one-time code.
14. Policy changes
The Operator may update this Policy. The current version is published on promtpress.com. The last update date is indicated at the top of the document.
15. Contacts
For all personal data processing inquiries: E-mail: hello@promtpress.com Telegram: @PromtPress_manager