Skip to main content
ChatGetz
Get started

Privacy Policy

Last updated:

This Privacy Policy explains what personal data "ANTONOVICH GROUP" LLC (MCHJ) ("we") processes when you use ChatGetz, why, and what rights you have. We collect only what is needed to run the Service.

1. Data we collect

  • Account data: your name, email address, optional phone number, preferred interface language, and your password stored only as a bcrypt hash (we never store or see your password in plain text).
  • Workspace data you create: campaigns, connected Telegram bots, analytics, and leads and messages received by your bots.
  • Telegram bot keys: encrypted with AES-256-GCM before storage and never shown again after you save them.
  • AI usage: the text you submit to AI features is sent to the selected AI model to generate the answer. We keep usage records (model, amount of usage, cost, time) for billing; we do not keep a history of your AI chats.
  • Billing data: plan, subscription status, payment status and amounts, and the order, customer and subscription identifiers from the payment system or payment provider. Card details are entered on the payment page of the payment system or payment provider and are never received or stored by us.
  • Technical data: security logs of the hosting platform and, for rate limiting, only a one-way SHA-256 hash of your IP address or email (never the raw value), deleted after about a day.
  • Phone number and one-time codes: if you sign in or confirm your number by phone, we store the number in international format and the time it was confirmed. One-time codes are stored only as a keyed hash, expire after 10 minutes (email confirmation links after 24 hours), allow a limited number of attempts and are deleted within about a day after they expire. To receive a code from our Telegram bot you share your own Telegram contact with the bot; we use it only to check that the number matches.
  • Identity verification (optional, only when you start it): with an online verification partner we receive and keep only the result (approved, declined or under review) and the partner's session reference, never document numbers or images. If you choose manual review, the document photo and selfie you upload are encrypted with AES-256-GCM, kept in private storage, visible only to an authorised administrator and deleted right after the decision or, at the latest, after the retention period shown on the verification page (30 days by default).

2. Why we use it (legal bases)

  • to provide the Service and your account (performance of the contract);
  • to process payments and keep accounting records (contract and legal obligations);
  • to protect the Service against abuse and fraud (legitimate interests);
  • to answer your requests (contract / legitimate interests).
  • to confirm your phone number, email address or identity when you ask for it or when a feature (for example selling, safe deals or payouts) requires a verification level (contract, legal obligations and legitimate interests; for identity images, your explicit consent, which you can withdraw before the decision).

3. Cookies

We use only necessary cookies: a signed, encrypted session cookie that keeps you logged in (valid for up to 7 days), security (CSRF) cookies of the sign-in system, and a language cookie that remembers your chosen interface language. We do not use advertising or third-party tracking cookies.

4. Service providers

We share data only with providers that help us run the Service, and only as much as they need:

  • Vercel Inc. - hosting of the website and application;
  • Prisma Postgres (Prisma Data Inc.) - managed database hosting;
  • Vercel AI Gateway and the AI model providers it routes to (for example OpenAI, Anthropic, Google, xAI, DeepSeek, Moonshot AI) - to process AI requests you make;
  • Payment systems - Payme, Click, Uzum and the other enabled Uzbek payment systems (for payments in so'm: order number and amount, and your phone number where the system requires it), and a third-party payment provider acting as Merchant of Record for international card payments; they process your payment details under their own privacy policies;
  • Telegram - when you connect a bot, we call the Telegram Bot API with your bot key;
  • Code delivery providers (only those we have enabled): Telegram (Telegram Gateway and our Telegram bot), SMS providers (Eskiz.uz and Play Mobile for Uzbek numbers; Twilio, Vonage or Google Firebase / Identity Platform for other countries) and email providers (Resend or our SMTP provider) receive your phone number or email address and the code to deliver it; Cloudflare Turnstile checks that sign-up requests come from a person;
  • Identity verification partners (only the one you use): Didit, Sumsub, Veriff or Onfido (Entrust) process your document and face images under their own privacy policies; OneID (id.egov.uz, the state identification system of Uzbekistan) confirms your identity when you sign in there.

5. International transfers

Our providers may process data outside Uzbekistan (for example in the United States or the European Union). We use providers that apply appropriate safeguards, such as encryption in transit and contractual data protection commitments.

Data localization in Uzbekistan: the Law of the Republic of Uzbekistan No. ZRU-547 "On personal data" (as amended by Law No. ZRU-1125 of 26 March 2026) requires certain data of citizens of Uzbekistan, in particular biometric data and telecommunications subscriber data, to be stored in databases located in Uzbekistan, and allows other personal data to be transferred abroad to countries with adequate protection or under appropriate safeguards. We therefore do not keep biometric data ourselves beyond the short, encrypted manual review described above, we send codes to Uzbek numbers through Uzbek SMS providers where they are enabled, and in-country identity options (OneID, MyID) can be offered instead of foreign partners.

6. Security

All traffic uses HTTPS. Passwords are hashed with bcrypt, bot keys are encrypted with AES-256-GCM, access to data is limited to your own account, and sign-in attempts are rate-limited.

7. Retention

We keep your data while your account exists. When you delete your account or ask us to, we delete your account and workspace data, except records we must keep by law (for example payment and accounting records), which are kept only for the required period.

8. Your rights

You can access and update your profile in your account settings. You also have the right to request a copy of your data, correction, deletion, restriction of or objection to processing, and to withdraw consent where processing is based on consent. You may also lodge a complaint with your data protection authority.

To delete your account and data or to exercise other rights, contact us via the Contact page. We respond within 30 days.

9. Children

The Service is not intended for persons under 18, and we do not knowingly collect their data.

10. Changes and contact

We may update this policy and will show the new date at the top of this page; material changes will be announced in advance. The data controller is the company shown on the Contact page.

Privacy Policy | ChatGetz