Legal

Privacy

Client Room stores only what the current workflow needs: freelancer identity, project history, invitation and session hashes, Telegram chat ids after /start, and Stars payment identifiers.

Telegram Mini App initData is verified on the server and is not stored raw. Session cookies keep a hashed opaque token. Invoice payloads are signed server-side; logs redact tokens, cookies, initData, invitation URLs, invoice payloads, and charge identifiers.

No advertising SDK, third-party analytics, or payment-card data is collected. Stars payments stay inside Telegram. A formal privacy policy with a legal entity, address, and retention schedule is not published yet and remains a paid-launch blocker.