Privacy Policy
Revision of July 23, 2026 · service "Molnia", bot @molniavoicebot
1. General provisions
1.1. This Privacy Policy sets out how the Molnia service collects, uses, transfers, stores, and deletes data.
1.2. Molnia is a software service inside the Telegram messenger, available through the bot @molniavoicebot (the "Service"). The people who run and administer the Service are jointly referred to as the "Administration."
1.3. This Policy applies to data collected when you use the Service, visit molniabot.online, set up a Subscription, or contact support.
1.4. Processing happens mostly automatically and, depending on the specific operation, may include collecting, recording, organizing, storing, retrieving, using, transferring, restricting, and deleting data.
2. Definitions
2.1. User — anyone interacting with the Service.
2.2. Content — a voice message, audio or video file, video message, forwarded message, or other material sent to the Service.
2.3. Result — a transcript, summary, or other text automatically generated from Content.
2.4. Technical data — identifiers, events, metrics, and other information generated while the Service runs, not including the content of Content or a Result.
3. Categories of data processed
3.1. The Service may process the following categories of data:
- Telegram ID, username, display name, interface language, and the dates of first and last contact;
- Content and the Result while fulfilling a user request;
- chat and file type, recording length, transcript and summary length, processing status, model used, token count, and the date and time of the event;
- the numeric ID of a group chat and the number of minutes used by that group; the group's name and member list are not stored;
- Subscription term, payment or subscription identifiers, and transaction status information;
- email address, when paying by bank card;
- the text of a support request and whatever Telegram information about the sender is available;
- internal administrative markers: an admin's note about a User, a flag restricting access to the Service, a flag showing the User blocked the bot.
3.2. Visiting molniabot.online may cause the web server's and hosting provider's technical logs to record the IP address, browser information, and the time and address of the request. The site also uses Google Analytics, a web analytics service that uses cookies to collect anonymized visit statistics: page views, referral source, on-page interaction events, approximate region, and browser and device information.
3.3. Content and a Result may contain information about the User or third parties. The Service does not pre-screen Content for such information.
3.4. The Service does not use voice or image data to establish identity and does not perform biometric identification.
4. Purposes of processing
4.1. Data is processed for the following purposes:
- speech recognition, generating a Result, and sending it in Telegram;
- tracking free and paid limits, and activating and managing a Subscription;
- processing payments, cancellations, refunds, and disputed transactions;
- forwarding User messages to the configured administrator;
- keeping the Service running and secure, and preventing abuse;
- analyzing quantitative metrics, errors, and load to keep the Service running; processing records are linked to the Telegram ID of the User who triggered them and are not anonymized.
5. How Content is processed
5.1. After receiving a message, the bot creates a temporary local copy of the Content and sends it to the speech recognition service.
5.2. The resulting transcript is passed to the summarization service. Along with the text, the sender's display name may also be passed along, used to pick the correct grammatical gender.
5.3. Telegram ID, username, and phone number are intentionally not added to requests sent to external AI providers. That said, the Content and its text may themselves contain names, voices, and other information present in the original material.
5.4. When a request finishes normally, or after a handled software error, the temporary local copy is deleted in the program's closing block. A hard process kill or an operating system failure can interrupt that block; temporary files live in the Service's isolated temporary directory.
6. External providers
6.1. The following providers may be involved in running the Service:
- Telegram — delivering messages, files, profile data, and Results; processing Telegram Stars payments;
- Groq and Deepgram — processing audio and video material for speech recognition;
- Cerebras, Groq, and OpenRouter — processing transcript text and, when available, the display name, to generate a Result;
- Supabase — storing account, Subscription, and Technical data;
- lava.top — handling email, invoicing, accepting payment, and managing the Subscription for card payments;
- Google Analytics — anonymized visit statistics for molniabot.online (see clause 3.2); has no access to bot data or Content.
6.2. The Service's code never requests or stores a card number, expiration date, or security code. That information is entered on the payment provider's own page; the Service's integration only handles the email address, account and subscription identifiers, amount, currency, and transaction status.
6.3. The list in clause 6.1 matches the Service's code as of the current revision. Changes to integrations require a separate update to this Policy and don't update it automatically.
7. Storage and model training
7.1. The Service's code doesn't write the content of audio, transcripts, or summaries to its own database. Its own logs explicitly record transcript length and error type and status, but not the content of the Content itself; how external libraries' and providers' own logs behave is up to them.
7.2. The original message and the bot's reply stay in Telegram, governed by the chat's settings and Telegram's own rules. External providers may keep technical logs and temporarily store requests under their own terms and settings.
7.3. The Administration doesn't train its own models on Content and doesn't build training datasets out of user recordings. Storage and any use of requests by external providers is governed by their own terms; this Policy therefore can't promise that no external provider retains any data.
7.4. There's no fixed automatic deletion period for account, usage, and Subscription data. Absent a manual deletion request, this data keeps being stored in the Service's database.
8. Cross-border processing
8.1. The Service's technical infrastructure and providers may be located in different countries. Data is transferred to such providers only to the extent needed for the relevant function.
8.2. The User must not send Content if doing so, or having it processed this way, would violate restrictions that are mandatory for them.
9. Third-party content
9.1. Forwarded messages, group chats, and uploaded files may contain data about people who never contacted the Service themselves. The User must have adequate grounds to send such material.
9.2. Don't use the Service to process someone else's passwords, payment details, state or trade secrets, health information, details about someone's intimate life, or other sensitive information.
10. User requests
10.1. The bot has no automatic feature for viewing, correcting, or deleting data. A User can send a manual request to the administrator through the support channel: the /support command in a private chat with the bot @molniavoicebot, or a text message starting with the word "Support" (case-insensitive). The text of the request is saved in the Service's database (clause 3.1).
10.2. To prevent access to someone else's data, the Administration may ask for information confirming that the request is linked to the corresponding Telegram account.
10.3. Once your message has been successfully forwarded, any further action on the request, if taken at all, is handled manually by an administrator. Submitting a request doesn't guarantee it will be carried out and doesn't delete data automatically. The Service's code has no mechanism that, on such a request, deletes data from Telegram's, payment providers', or AI providers' own systems.
10.4. Simply no longer using the Service is not, by itself, a request to delete previously stored data.
11. Data protection
11.1. Access to the database through the public Data API is blocked by Supabase's access rules; the bot reaches the database using a server-side key. Limits on logging content are described in clause 7.1.
11.2. No method of transmitting or storing information guarantees absolute security. The User must not send material whose exposure would be unacceptable to them.
12. Age restrictions
12.1. A paid Subscription may only be set up by Users who are of legal age, or by Users acting with a legal guardian's permission.
13. Publishing and updating this Policy
13.1. The current revision of this Policy is always available on this page.
13.2. This Policy may be updated as features, the set of providers, or data-processing procedures change. The revision date appears at the top of the document.