Privacy Policy
Effective May 25, 2026 · StashGram · Contact: caio.ricciuti07@gmail.com
What we collect
When you open the Mini App, Telegram gives us a signed payload ("initData") that includes:
- Your Telegram user id, username (if set), first name,
last name, profile photo URL, and language code.
When you create a product, we store:
- The title, description, category, price, image (if
you uploaded one), and the delivery payload (download link, file, token, or text) you provided.
- A SHA-256 hash of any uploaded file, used for moderation and abuse
prevention.
When you make a purchase, we store:
- A purchase id, the product id, your Telegram user id as the
buyer, the status of the purchase, and a download token if the product is a file.
When you write a review, we store:
- The product id, your Telegram user id, the rating (1–5),
the review text, and the timestamp.
When you accept these terms, we store the timestamp of acceptance.
We additionally keep short-lived server access logs (request method, path, status, timing, source IP) for operational debugging and abuse prevention. These logs are rotated and not used for advertising.
We do not receive or store your payment-card data. Telegram Stars payments are processed entirely by Telegram.
What we don't do
- We don't sell your data.
- We don't share your data with third-party advertisers or data brokers.
- We don't use your data to train AI models.
- We don't track you across the web — we have no third-party trackers
embedded in the Mini App.
Who can see what
- Your username, display name, and photo can be seen by other users
when you create a product, leave a review, or are linked-to as a creator.
- Your purchases and wishlist are private to you and to
StashGram. The Creator of a product you bought can see that *someone* bought it (as part of their aggregate sales count and any review you leave), but not your identity unless you also leave a review.
- Reviews are public alongside your username/display name.
- Operators of StashGram can access stored data when
necessary to operate, support, or moderate the Service.
Data retention
We retain your data while your account exists and for a reasonable period afterwards (typically 90 days) for dispute resolution, fraud prevention, and legal compliance, after which it is deleted or anonymized.
You may request deletion of your account and all associated personal data by emailing caio.ricciuti07@gmail.com from the email address associated with your Telegram account (or by providing other reasonable proof of identity). We will respond within 30 days. Note that some data (such as the public review text you authored, or the audit trail of a completed purchase) may remain in anonymized form for the integrity of the marketplace.
Cookies and storage
The Mini App does not set tracking cookies. It uses Telegram's built-in CloudStorage to remember your wishlist across devices; this data lives inside Telegram and is also subject to Telegram's privacy policy.
Children
The Service is not intended for users under 18 (or the age of majority in your jurisdiction). We do not knowingly collect data from children.
Security
We use TLS in transit and store data on a single server in a region of our choosing, with file system permissions restricting access to the operating user. Uploaded files are sniffed for content type and rejected if they match prohibited categories. Despite our efforts, no system is perfectly secure; report any vulnerabilities you find to caio.ricciuti07@gmail.com.
International transfers
Your data may be processed and stored in a country other than your own. By using the Service you consent to such transfers.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the Mini App or via Telegram before they take effect. The "Effective" date below is updated on every change.
Contact
Privacy questions, data-deletion requests, or rights-exercise requests? Email caio.ricciuti07@gmail.com.
Effective: May 25, 2026