Legal
Privacy Policy
This Privacy Policy governs the hosted Telegram bot @zap_gram_bot and the website zapgram.mozharov.me (together, “ZapGram”, “we”, “us”). By using ZapGram you agree to this policy. It describes how we collect, use, store, and share personal data for this service and is the privacy policy published for the bot (including for Telegram BotFather). Telegram’s own Privacy Policy still applies to data Telegram processes as the platform.
Who operates this
The hosted service is operated by the bot author (@vmozharov). Self-hosted copies of the open-source code are run by whoever deploys them and are not covered by this policy — only @zap_gram_bot and zapgram.mozharov.me are.
What we collect
We collect and process the following data to run ZapGram:
- Telegram profile — user id, username (if any), display name, and language preference Telegram sends to the bot.
- Messages you send the bot — commands, button presses, and text you type (invoice memos, feature ideas, chat setup, and similar). In groups and channels the bot only receives what Telegram’s bot privacy mode allows (typically commands, replies to the bot, and service events it needs).
- Built-in Lightning wallet — a custodial wallet is created for your Telegram id (via LNbits). Balances, invoices, and payment status are processed on that infrastructure so send and receive work.
- Payment records — amounts in sats, BOLT11 payment requests and hashes, subscription and join attempts, refunds, platform-fee transfers, donation ledger entries when you support the project, and related timestamps. Required for access grants, renewals, refunds, and idempotent payouts.
- Paid chats you own or join — chat id, title, price, payment mode (one-time / monthly), custom join text, subscription status, and access state.
-
On-chain pay (when a chat owner enables it) — the
zpub/xpubthe owner pastes (watch-only; not private keys), deposit addresses, amounts, expiry, and on-chain txids when a payment is detected. - NWC (when you connect it) — the Nostr Wallet Connect URL you provide and your tip-wallet preference, so the bot can request payments you authorize. Disconnect anytime in the bot.
- Support settings — voluntary % tip settings, monthly donate schedule when you enable them, and successful donation amounts for your totals and community stats.
- Operational data — for example that you blocked the bot (so we skip broadcasts), temporary multi-step flow state, and short-lived broadcast delivery state.
-
Website analytics — visitor id (local storage / cookie), page views,
and clicks on bot CTAs via PostHog. Session replay is not used on the landing. Deep
links may carry the visitor id so a later bot
/startcan attribute “came from the site.” - Product analytics — events such as starts, payments, errors, and feature requests, keyed by Telegram user id, via PostHog — to operate, understand, and improve the product. Feature-request text you submit is included in those events. We do not sell this data or build advertising profiles from it.
We do not ask for phone numbers, email addresses, government IDs, or bank/card details. We do not run KYC.
Why we use it
- Provide the wallet, tips, invoices, paid-chat access, renewals, and donations.
- Pay chat owners, collect the hosted platform fee where applicable, and refund duplicate Lightning payments safely.
- Show the right language and keep settings (NWC, support %, auto-renew).
- Secure the service, prevent abuse, and debug failures.
- Measure product and website usage (PostHog).
Who processes data with us
- Telegram — delivers bot messages and updates; see Telegram’s policies.
- LNbits (and the Lightning node behind it) — custodial wallets, invoices, payments, webhooks; Watch-Only / SatsPay for on-chain chat charges when enabled.
- Lightning Network / Bitcoin — payments you make or receive on the public networks. On-chain transactions and addresses are public by design.
- Your NWC wallet provider (only if you connect one) — e.g. Alby, Coinos; they process payments you authorize from that wallet.
- PostHog — product and website analytics for the hosted service.
We do not sell your personal data. We do not use it for third-party advertising. Feature ideas you send are forwarded to the operator’s Telegram admin chats for review and recorded in product analytics as described above.
How long we keep it
- Account and wallet data while you use the service.
- NWC connection until you disconnect it (or ask us to clear it).
- Pending receive invoices are dropped after a short TTL (on the order of days).
- Payment and subscription records are kept as long as needed for access control, refunds, payouts, and basic audit of money movements.
- In-flight broadcast recipient lists are removed when a campaign finishes.
- Blockchain history is public and cannot be deleted by us.
Your choices
- Stop using the bot anytime; blocking it stops new private messages from us.
- Disconnect NWC in the bot to stop using an external wallet connection.
- Turn off or change voluntary support % in settings; cancel monthly donate.
- Ask for a copy of data we hold about you, or deletion where we can, by messaging @vmozharov from the same Telegram account (we may need to verify it’s you). We aim to respond within 30 days.
Deletion has limits: we may keep payment-related rows needed for refunds, fraud prevention, or legal/tax obligations where they apply; public chain data stays public; messages already delivered in Telegram are outside our database.
Security
Access to production systems is limited. NWC connection strings are sensitive credentials — treat them like a password and only connect wallets you trust. The built-in wallet is custodial convenience; prefer NWC if you want keys on your side. Open source code: github.com/mozharov/zapgram.
Children
ZapGram is not directed at children. Use only if you may use Telegram and Bitcoin services under the laws that apply to you.
Changes
We may update this page when the product or processors change. The “Last updated” date above will change. Continued use of the hosted bot after an update means you accept the revised policy for that service.
Contact
Privacy and data requests: @vmozharov on Telegram. Product: @zap_gram_bot.