botnest · version dated 25.08.2026
Personal Data Processing Policy
1. General provisions
This policy explains how personal data is processed when you use the botnest website and service. Data controller: Self-employed Шишкин Геннадий Николаевич.
The data controller's contact details are published on the "Contact and Company Details" page.
2. Data we process
Account data (username and email address, if provided); Telegram identifiers and public profile data; settings for bots and automations; technical logs; IP address and device information; support requests; and payment status. With separate consent, we also process a pseudonymous identifier, approximate country and region derived from the IP address, and product events such as page views, referral sources and UTM tags, registration, bot setup and launch stages, builder and AI feature use, aggregated daily indicators of successful or failed bot operation, and checkout results. Message contents, AI prompts, and secret keys are not sent to product analytics. botnest does not receive card details.
When a user proceeds to registration and while using the authenticated area, botnest also stores minimal first-party analytics in its own database: the landing path, referring domain, UTM tags, the presence of an advertising tag without its value, device category, operating-system and browser families, language, and whether the service is used on the Web or in the Telegram Mini App. This analytics record does not store the full User-Agent, IP address, exact device model, or original advertising identifiers.
3. Purposes and legal bases
We process data for registration and sign-in, performance of the contract, operation of bots and automations, support, security, abuse prevention, payment records, and compliance with legal obligations. The legal bases are consent, entering into and performing the contract, and applicable legal requirements.
First-party analytics is used to administer and improve the service on the basis of the data controller's legitimate interests where that legal basis applies.
4. Recipients and service providers
Data may be shared only to the extent necessary to operate the service: with Google and other integration providers connected by the user, Telegram, Robokassa, LLM providers selected by the user (such as OpenAI or OpenRouter), and hosting and technical monitoring providers. OpenConnector operates as an isolated component of botnest infrastructure and stores connection secrets separately from the main application. If the user explicitly connects blocks from different services, data is sent to the selected recipient solely to execute the configured automation. Google service content is not sent to product analytics. If product analytics is accepted, PostHog, Amplitude, and Yandex Metrica are recipients. Data may be processed outside Russia when required by a selected integration and supported by a lawful basis.
Minimal first-party analytics is stored in the botnest database and is not sent to product analytics providers.
5. Google user data and requested permissions
The categories of Google user data depend exclusively on the service and action selected by the user. They may include the Google Account identifier and email address; Gmail messages, metadata, drafts, and settings; Google Drive files, folders, content, and metadata; documents, spreadsheets, and presentations; calendar events and settings; contacts and profile data; Google Chat spaces and messages; and data from Google Ads, Analytics, BigQuery, Cloud Storage, and other Google services explicitly identified on the consent screen. botnest does not access Google user data until the account is connected and the user has explicitly consented.
Google permissions are requested dynamically for the specific selected action. botnest uses the minimum access declared by that action and does not request a broader permission when a more limited scope is sufficient. A new action that requires additional scopes requires separate user consent.
6. Use of Google user data
Google user data is used only to perform actions that the user configures in an automation: reading, searching, creating, updating, sending, or deleting selected data, displaying the result to the user, and maintaining the security and reliability of the feature. botnest does not sell Google user data or use it for advertising, advertising profiles, creditworthiness determinations, information resale, or any purpose unrelated to the user-requested feature.
Google Workspace API data is not used to develop, improve, or train generalized or non-personalized artificial intelligence or machine learning models. If the user explicitly sends selected data to an LLM block in their automation, the transfer is made solely to generate the result requested by the user; botnest does not use that data to train models.
7. Storage, security, and deletion of Google user data
Google OAuth tokens are stored encrypted in an isolated connection service and are not sent to the user's browser. Data is transmitted over secure HTTPS connections. The main application stores only connection metadata, granted scopes, and technical status. Google service content is stored in botnest only when the user explicitly configures the result to be saved in a log, table, history, or another automation block.
Detailed first-party analytics session records are retained for no more than 90 days. A short summary of the first source and latest device type is stored with the account and is deleted when the account is deleted unless the law requires otherwise.
A connection can be disconnected in the botnest interface. After disconnection, stored tokens are removed from the active connection service and the list of granted scopes is cleared. The user may also revoke access in their Google Account security settings. Automation data is retained while the account exists or while it is needed for the selected feature, performance of the contract, or legal requirements, and is then deleted or anonymized. The user may request deletion of the account and related data using the data controller's contact details.
8. Rights and data controls
Users may request information about processing, correction, restriction, or deletion of data; disconnect an integration; revoke OAuth access; withdraw consent; or object to processing using the data controller's contact details. Some data may continue to be retained after consent is withdrawn when required by law.
9. Data relating to Telegram bot users
The bot creator is responsible for the lawfulness of their flows and notification text, obtaining any required consent from their audience, and configuring retention periods. botnest provides the technical tools and processes this data on the bot creator’s instructions.
10. Cookies and product analytics
The website uses essential session and request-protection cookies. They are required for sign-in, security, and maintaining account state. PostHog, Amplitude, and Yandex Metrica connect only after separate consent; declining does not limit the service. Session recording, Webvisor, and advertising profiling are disabled. Consent can be withdrawn at any time, after which no new analytics events are sent.
First-party analytics does not create a separate analytics cookie, does not track users across other websites, and uses only registration hand-off data and technical characteristics of authenticated requests.
11. Updates
The data controller may update this policy as the service, processing practices, or legal requirements change. A new version will be published on this page and applies to processing after its publication date, unless the law requires notice, separate consent, or another procedure. An update does not remove any statutory rights of data subjects or apply new terms retroactively.