// privacy
Privacy Policy
Last updated June 7, 2026
1. Summary (Plain English)
- We are a US-based company and the Service is operated under US and Florida law.
- We collect the minimum personal information needed to identify you, bill you, and run your AI agent: your Telegram identity, an optional email address, and billing data handled by our payment processor.
- We deliberately do not store the contents of your conversations, your AI agent's reasoning, the inputs/outputs of the tools your agent uses, or the data inside your connected third-party accounts. Those live in Telegram, on your agent's private storage, and with the third parties you connect — not in our central systems.
- We rely on third-party "subprocessors" (listed in Section 5) to run the Service.
- You can access and delete your account data; see Section 8.
- This section is a summary only. The full Policy below governs.
2. Who We Are and Scope
The "Service" is a paid subscription product that provisions a dedicated AI agent for each user. The agent is reachable through a Telegram bot associated with your account and can take actions on your behalf in third-party tools you choose to connect (for example, email, calendar, messaging, and code-hosting tools, made available through our integration provider, Composio).
This Policy applies to information processed by FTS in operating the Service. It does not cover:
- The independent privacy practices of Telegram, Composio, or any third-party tool you connect (see Section 6).
- Information you choose to share directly with those third parties.
- Any website or service that is not operated by FTS, even if linked from ours.
3. Information We Collect
We practice data minimization: we collect only what we need to operate, secure, and bill the Service.
3.1 Information you provide or that is created at signup
| Category | Examples | Why we collect it |
|---|---|---|
| Telegram identity | Telegram user ID, Telegram username, Telegram display name (received via Telegram Login) | To identify your account; there is no separate password |
| Email address (optional) | Email you provide post-signup | Transactional emails (billing, trial reminders, security and lifecycle notices) |
| Billing data | Handled by Stripe; we store a Stripe customer identifier, plan, subscription status, and renewal/trial dates | To process subscription payments, trials, top-ups, and overage billing |
We do not collect or store full payment card numbers. Card data is collected and processed by Stripe under Stripe's own privacy and security terms.
3.2 Information generated by operating your agent
| Category | Examples | Why we collect it |
|---|---|---|
| Bot credentials | An encrypted token used to operate your Telegram bot | To run your agent's bot on your behalf |
| Operational secrets | Encrypted machine and webhook secrets | To securely operate and authenticate your agent's infrastructure |
| Usage metadata (no content) | Counts and costs only: model used, input/output token counts, tool-call counts, durations, status codes, timestamps, and the dollar amounts billed | To enforce usage limits, prevent abuse, calculate billing, and run analytics |
| Safety/abuse signals (metadata) | Tool name, risk classification, and approval/deny decisions — no arguments or contents | To detect abuse patterns and improve safety controls |
| Schedule shadow data | The timing of agent scheduled tasks (not their contents) | To wake your agent at the right time for scheduled jobs |
| Limited service logs | Request identifiers, user/agent identifiers, error classes, performance data (retained ~30 days) | Debugging, security, and reliability |
3.3 Information we receive from third parties
- Stripe provides us payment and subscription status (e.g., payment succeeded/failed, plan, renewal date).
- Telegram provides your public Telegram profile via the Telegram Login flow and delivers messages to your bot.
- Composio provides metadata about tool executions for usage accounting. We hold only an integration identifier ("entity ID") that maps to your account; we do not receive or store your authenticated sessions for connected tools.
4. What We Deliberately Do NOT Collect or Store
To protect your privacy and reduce risk, the Service is designed so that we never receive or store the following in our central systems:
- Prompt or completion content. Our LLM gateway logs metadata only — never the text of what you ask your agent or what it replies.
- Tool-call arguments or results. The inputs and outputs of the actions your agent takes in your connected tools are processed on your agent's private storage and are not sent to our central systems.
- Conversation contents. Your message history with your bot lives on Telegram's servers, not ours.
- Your authenticated third-party sessions. Your logins and OAuth sessions for connected tools belong to those tools and to our integration provider, Composio; we hold only a mapping identifier.
- LLM provider API keys on a per-user basis. Our model access keys are ours and are used at the gateway; they are never issued per user.
We cannot produce, disclose, or be compelled to hand over content we do not hold.
5. Subprocessors and Service Providers
We use the following third-party service providers ("subprocessors") to operate the Service. Each processes only the data needed for its function and is bound by its own terms and applicable data-protection agreements:
| Subprocessor | Function | Data involved |
|---|---|---|
| Stripe | Payments, subscriptions, billing | Billing identifiers, payment and subscription status (card data handled by Stripe) |
| Fly.io | Cloud infrastructure / agent hosting | Agent runtime storage and operational secrets |
| Supabase | Authentication and database | Account identity, plan/billing metadata, usage metadata, encrypted secrets |
| OpenRouter + Anthropic | Large-language-model (AI) processing | Prompts/completions are routed for processing but are not retained by us; subject to provider terms |
| Composio | Third-party tool integrations | Integration identifier; tool-execution metadata |
| Telegram | Bot messaging interface | Your Telegram identity and message delivery |
| Resend | Transactional email | Your email address and message content of our notices |
We may add, remove, or replace subprocessors as the Service evolves. Material changes will be reflected in this Policy. The use of any subprocessor is also subject to that provider's own privacy policy, which we encourage you to review.
6. Third-Party Services and Connected Tools
The Service is intentionally built on top of third-party platforms. You are responsible for your own use of, and your agent's actions within, any third party you connect. When you authorize your agent to access a tool (for example via Composio), you are granting access under that third party's terms, not ours. We:
- Do not control and are not responsible for the privacy, security, availability, or content of Telegram, Composio, connected tools, or any LLM provider.
- Receive only the limited metadata described above.
Review the privacy policies of each third party you use. Your relationship with those third parties is independent of your relationship with us.
7. How We Use Information
We use the information described above to:
- Provide, operate, maintain, and secure the Service and your agent.
- Authenticate you and manage your account.
- Process trials, subscriptions, top-ups, overages, renewals, and related billing.
- Enforce usage limits and spending caps.
- Detect, prevent, and investigate fraud, abuse, chargebacks, security incidents, and violations of our Terms of Service.
- Send transactional and service communications (billing, trial reminders, security, and lifecycle notices).
- Analyze aggregate, content-free usage to improve reliability, pricing, and product quality.
- Comply with legal obligations and enforce our agreements.
Legal bases (for users to whom such concepts apply): performance of our contract with you (running the Service you paid for); our legitimate interests in securing, improving, and protecting the Service against abuse; and compliance with legal obligations.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
8. Your Rights and Choices
Subject to applicable law and verification of your identity, you may:
- Access the account, usage, and billing information we hold about you, primarily through your dashboard.
- Delete your account and associated data. You may self-serve deletion through the dashboard (effective immediately for our central records), or email us at support@bytfrontier.com. We target same-day handling for online deletion requests and will in any event act within thirty (30) days.
- Correct inaccurate account information you provided.
- Object to or restrict certain processing, where applicable law provides such a right.
- Request portability of your data. Self-serve export is not yet available; we will handle reasonable portability requests on a case-by-case basis via email.
As a courtesy, we honor GDPR-style and US state-privacy-style requests (access, deletion, correction, objection) where we can reasonably verify them, regardless of where you live. Honoring such a request as a courtesy does not constitute an admission that any particular law applies to FTS or the Service.
To exercise any right, contact support@bytfrontier.com. We may need to verify your identity before acting, and we may decline requests that are unfounded, excessive, or that would compromise others' rights, our security, or our legal obligations.
If you believe we have not adequately addressed a concern, you may have the right to lodge a complaint with a data-protection or consumer-protection authority in your jurisdiction.
9. Data Retention and Lifecycle
We retain information only as long as needed for the purposes described, then delete or anonymize it:
- While your subscription is active: we retain your account, agent, and operational data to run the Service.
- After cancellation or lapse (archived state): your agent's stored state is archived for 120 days so you can resubscribe and resume where you left off. During archival we hold the data in cold storage.
- After 120 days archived without resubscription (or upon your explicit deletion request): we delete the archived data, revoke connected-tool integration tokens, hard-delete sensitive fields (such as encrypted bot tokens and operational secrets), and soft-delete user-facing records.
- Reminders before deletion: we send reminder notices (for example, around day 90 and day 105 of archival) before permanent deletion.
- Usage metadata (content-free counts and costs) may be retained on an aggregated/anonymized basis for billing integrity and analytics.
- Safety/abuse metadata is retained on a rolling basis (approximately 12 months) for abuse detection.
- Service logs are retained approximately 30 days.
Deletion is irreversible. We may retain limited records where required to comply with law, resolve disputes, prevent fraud or abuse, or enforce our agreements.
10. Cookies and Analytics
We use only the cookies and similar technologies reasonably necessary to operate the dashboard — primarily to keep you signed in and to maintain session security. We do not use the Service to run third-party advertising trackers. Any analytics we employ are oriented toward content-free operational metrics. You can control cookies through your browser settings; disabling strictly necessary cookies may prevent the dashboard from functioning.
11. Data Security
We use commercially reasonable technical and organizational measures to protect information, including encryption of sensitive credentials at rest, transport encryption (HTTPS), authenticated machine-to-machine communication, scoped access controls, and content-minimized logging.
No method of transmission or storage is perfectly secure. While we work to protect your information, we cannot guarantee absolute security, and you provide information at your own risk. You are responsible for maintaining the security of your Telegram account, which is the credential used to access the Service. Notify us immediately at support@bytfrontier.com if you suspect unauthorized access.
12. Children's Privacy
The Service is intended only for users who are 18 years of age or older. It is not directed to children. We do not knowingly collect personal information from anyone under 18, and in no event from a child under 13 (or under 16 where a higher age applies). If we learn that we have collected information from a person under the applicable minimum age, we will delete it. If you believe a minor has provided us information, contact support@bytfrontier.com.
13. International Users and Data Transfers
FTS is based in the United States, and the Service is operated from and hosted primarily in the United States. The Service is offered to and intended for users in the United States. If you access the Service from outside the United States, you understand and consent that your information will be processed in the United States and other countries where our subprocessors operate, which may have data-protection laws different from those in your country. We do not represent that the Service is appropriate or available for use in all locations.
14. Telegram Bot Privacy Notice
Because the Service is delivered through Telegram bots, the following applies to the bot interface: your conversation history with your bot is stored by Telegram, not by FTS. FTS does not read or store the contents of your bot conversations. Telegram's handling of your messages is governed by Telegram's own privacy policy.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, for material changes, provide additional notice through the Service or by email. Your continued use of the Service after an update takes effect constitutes acceptance of the revised Policy. If you do not agree, stop using the Service and may request deletion of your data.
16. Contact Us
Frontier Tech Solutions LLC
Attn: Privacy
Email: support@bytfrontier.com