Last updated: 4 September 2026
This Privacy Policy explains how personal data is processed when you use Caivemanator, including the Caivemanator Telegram bot, the Telegram Mini App used to purchase in-service credits (called “stones”), and the landing page at caivemanator.com (together, the “Service”).
Caivemanator is operated by Alina Latypova, an individual based in Poland, who is the controller of the personal data described in this Policy (“Caivemanator”, “we”, “us” or “our”). “Caivemanator” is a service name and not a separate legal entity.
Contact: support@caivemanator.com
The Service operates through Telegram. Telegram processes personal data under its own terms and privacy policy. When you interact with the bot or open the Mini App, Telegram provides us with information needed to operate the Service, such as your Telegram identifiers and the information included in your interaction with the bot or Mini App.
We do not control how Telegram processes data for its own purposes. Please review Telegram’s privacy policy and applicable terms separately.
We process the following categories of personal data:
| Category | Examples |
|---|---|
| Telegram account data | Telegram user ID, chat ID, username and display name |
| User content | Text prompts and images or videos you submit for generation or processing |
| Generated content and history | Generated images, videos and audio; generation request history, status and related metadata |
| Account and service data | Stone balance, features used, request dates, and account activity |
| Telegram Stars transaction data | Telegram transaction ID, number of Stars, purchased package or stones, payment status and date, and refund or chargeback information |
| Technical and security data | Application events, error reports, diagnostic data and activity logs generated when you use the Service |
| Communications | Information you include when you contact support by email |
We do not receive or store your payment card number, card security code or banking credentials when you purchase stones using Telegram Stars.
The landing page and Mini App do not currently use analytics tools or non-essential cookies and do not intentionally collect information beyond the data described above. Like most internet services, infrastructure providers may necessarily process limited connection and security data to transmit requests and protect their systems. If we introduce analytics, advertising technologies or non-essential cookies, we will update this Policy and, where required, request consent before using them.
We obtain personal data:
If the EU General Data Protection Regulation (“GDPR”) applies, we rely on the following legal bases:
| Purpose | Data generally used | GDPR legal basis |
|---|---|---|
| Create and maintain your account and identify you in Telegram | Telegram account data; account data | Performance of a contract (Article 6(1)(b)) |
| Generate, process and deliver requested content | Prompts, uploaded content, Telegram identifiers, generated content and history | Performance of a contract (Article 6(1)(b)) |
| Process Stars purchases, credit stones, and handle refunds or chargebacks | Telegram identifiers, transaction data, stone balance | Performance of a contract (Article 6(1)(b)); compliance with legal obligations where applicable (Article 6(1)(c)) |
| Operate, secure, troubleshoot and prevent misuse of the Service | Technical, security, account and activity data | Our legitimate interests in providing a reliable and secure service and preventing fraud or abuse (Article 6(1)(f)) |
| Respond to support requests and exercise or defend legal claims | Communications and relevant account, content or transaction data | Performance of a contract (Article 6(1)(b)) and our legitimate interests in resolving requests and protecting legal rights (Article 6(1)(f)) |
| Comply with law and valid requests from authorities | Data relevant to the applicable obligation or request | Compliance with a legal obligation (Article 6(1)(c)) |
Where we rely on legitimate interests, we consider the effect of the processing on your rights and use only data reasonably necessary for the stated purpose.
You must provide the Telegram and content data needed to request a generation. You must also provide the required transaction data if you purchase stones. Without that data, we may be unable to provide the relevant feature.
To provide requested features, we send prompts and, where necessary for the selected feature, uploaded images, uploaded videos or other request data to AI service providers. Depending on the feature, these providers include:
The exact data sent depends on the feature you choose. Please do not include personal data that is unnecessary for your request. In particular, do not submit highly sensitive information about yourself or another person unless it is necessary, lawful and you have the right to do so.
We use AI systems to create or transform content at your request. We do not use automated processing to make decisions about you that produce legal or similarly significant effects.
We disclose personal data only where needed to operate the Service, complete a transaction, comply with law, or protect our legal rights. Current recipients and their roles include:
| Recipient | Role / purpose | Data that may be involved |
|---|---|---|
| Telegram | Messaging platform, Mini App environment and Telegram Stars transactions | Telegram account data, bot interactions and transaction data |
| fal.ai | Image and video generation or processing | Prompts, uploaded content, request metadata and generated content |
| OpenAI | Prompt processing, expansion or refinement | Prompt text and related request data |
Amazon Web Services (AWS S3), configured in Frankfurt, Germany (eu-central-1) |
Storage of uploaded and generated media and hosting of landing-page assets | Images, video, audio and related object metadata; landing-page assets do not intentionally contain user personal data |
| Sentry, configured for its EU region in Frankfurt, Germany | Error monitoring and troubleshooting | Error, diagnostic, device/application context and identifiers if included in an error event |
Heroku, with applications configured in its EU region and Heroku Postgres hosted in Ireland (eu-west-1) |
Hosting the bot backend, Mini App and landing page, and providing the Service database | Telegram account data, prompts and generation history, account and transaction records, support data, and technical data as necessary |
| Google Workspace | Receiving and managing messages sent to support@caivemanator.com |
Email address, message content, attachments and support correspondence |
Service providers process data under their own applicable terms and, where they act as our processors, under contractual data-protection obligations. Some providers, including Telegram, may also act as independent controllers for their own purposes.
We may also disclose data if required by law or a valid legal process; to protect users, the Service or others; or in connection with a reorganisation, sale or transfer of the Service, subject to appropriate safeguards.
We do not sell personal data or use it for third-party targeted advertising.
We are based in Poland. Our AWS S3 storage is currently configured in Frankfurt, Germany (eu-central-1); Sentry is configured for its EU region in Frankfurt; our Heroku applications are configured in Heroku's EU region; and the production Heroku Postgres database is hosted in Ireland (eu-west-1). However, Telegram, AI providers and their subprocessors may process personal data outside Poland or the European Economic Area (“EEA”), including in countries whose laws may provide a different level of data protection.
Where the GDPR requires it, transfers outside the EEA will be based on an adequacy decision or appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, together with supplementary measures where required. You may contact us for information about the safeguards relevant to your data.
We retain data only for as long as reasonably necessary for the purposes described above:
The 30-day deletion period stated below applies to active systems that Caivemanator directly controls. Copies held by external providers are governed by the provider-specific periods, settings and deletion mechanisms described in this section. A request to Caivemanator cannot always cause immediate deletion from a provider's systems or backups.
| Data | Retention period |
|---|---|
| Uploaded and generated images, videos and audio stored in our AWS S3 bucket | Up to 22 days, after which they are scheduled for deletion from that bucket |
| fal.ai generated files delivered through fal.ai's CDN | No fixed retention period is currently configured; a copy may remain until deleted by the provider or until we request deletion. This is separate from our 22-day AWS S3 lifecycle. |
| fal.ai request and response payloads shown in provider history | Up to 30 days under the provider's current default retention setting |
| OpenAI API inputs, outputs and abuse-monitoring logs | Up to 30 days under the provider's current API data-retention practices, except where longer retention is required by law. Caivemanator does not currently use Zero Data Retention. |
| Telegram account data, prompts, generation history, stone balance and related account records in active systems directly controlled by Caivemanator | While your account remains active, then deleted from those active systems within 30 days after a valid deletion request or account deletion |
| Heroku Postgres backups | Heroku may maintain limited infrastructure-level recovery or residual copies under its applicable service terms and deletion procedures. |
| Heroku runtime logs | Under the platform's applicable log-history limit, which is typically no more than a few weeks. |
| Sentry error and diagnostic events | Up to 30 days, per Sentry's data retention settings |
| Support communications in Google Workspace | Up to 12 months after the support request is resolved, unless a longer period is necessary for an ongoing dispute, security investigation, legal claim or legal obligation |
| Stars transaction, refund and chargeback records | While your account remains active and, where required, for any longer period imposed by applicable tax, accounting, fraud-prevention or legal-claims rules |
Deletion from Caivemanator-controlled active systems may not immediately remove data from encrypted backups. Backup copies will be isolated from ordinary use and deleted or overwritten according to the applicable backup cycle. Provider-side copies are subject to the periods, settings and deletion mechanisms described above. When responding to a valid deletion request, we will take reasonable steps to delete or request deletion of provider-side data where the provider's tools permit it, but we do not promise that every external provider will complete deletion within Caivemanator's 30-day period.
We may retain particular records for longer where required by law, necessary to establish, exercise or defend legal claims, or needed to investigate fraud or abuse. When possible, we will restrict further use of such records to those purposes.
We use reasonable technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse or alteration. These measures may include access controls, restricted administrative access, encrypted transmission, service monitoring and retention limits. No online service can guarantee absolute security.
You are responsible for keeping your Telegram account secure and for avoiding unnecessary personal or confidential information in prompts and uploads.
Subject to applicable law, you may have the right to:
To exercise a right, email support@caivemanator.com. Please contact us from an address or Telegram account that allows us to reasonably verify that the request relates to you. We may request limited additional information where necessary to verify identity and protect other users’ data. We will respond within the period required by applicable law.
Because the controller is established in Poland, you may lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), or with another competent supervisory authority, particularly in the EEA country where you live or work or where you believe an infringement occurred.
The Service is not intended for anyone under 18, and we do not knowingly offer the Service to or collect personal data from children under 18. If you believe a person under 18 has used the Service or provided personal data, contact support@caivemanator.com so that we can investigate and take appropriate action, including deletion where required.
The landing page, bot or Mini App may link to third-party services. Their handling of personal data is governed by their own privacy notices, and we are not responsible for processing they perform independently of us.
We may update this Policy when the Service, our providers or legal requirements change. We will publish the revised version with a new “Last updated” date. If a change materially affects how we process personal data, we will provide an appropriate additional notice through the Service where required.
Questions, requests and complaints about this Policy or our processing of personal data can be sent to:
Alina Latypova
Caivemanator
Poland
support@caivemanator.com