Privacy Policy
Last updated: September 30, 2026
TAN (“Telegram AI Agent Network”, “we”, “us”, or “our”) operates the Telegram bot @tan_org_bot and the website tan.org. This Privacy Policy explains how we collect, use, and protect your information when you use our services.
1. Information We Collect
1.1 Telegram Account Data
When you interact with our Telegram bot, we receive your Telegram user ID, first and last name, username, and language setting. This data is provided by Telegram and is necessary to operate the service. If you share your location, we send the coordinates to Google Maps to find your city, save the city and your time zone to your profile, and keep the shared location in your conversation history.
1.2 Messages and Content
We process the messages, voice messages, photos and files you send to the bot to generate AI responses. To give context-aware responses we store:
- your conversation history, including the bot's notifications — for 30 days;
- your messages and the assistant's replies, indexed so the assistant can find them later (very short exchanges are skipped) — for up to 365 days;
- summaries of your conversations — for 180 days;
- facts the assistant saves to its memory about you — until you ask it to forget them or delete your account (forgotten facts about people and things you mentioned are marked as withdrawn and no longer used; they are erased with your account);
- for photos and files you send: the file name, a description and the extracted text — for 90 days; the description and a reference to the file on Telegram's servers, kept as media memory — for up to 365 days.
Voice messages are converted to text, and the text is stored like any other message. We do not keep the audio, except your latest voice message, which is held for up to 30 minutes so it can be used as a melody if you ask for a song.
You can ask the assistant to forget a specific fact or everything it remembers about you. This does not delete your conversation history; to delete it sooner, or to delete your account, contact us (see Section 15).
1.3 Google Account Data
If you choose to connect your Google account, we request access to:
- Google Calendar — to view, create and change events in your primary calendar on your behalf, and to remind you of upcoming events
- Gmail — to read, send and label emails on your behalf, and to notify you of new emails
We store encrypted OAuth tokens (access and refresh tokens) to maintain your connection. We do not store your Google password.
While your Google account is connected, TAN also works in the background, without a request from you:
- Every 5 minutes it checks your Gmail for new unread emails. For each new email it sends the subject and Gmail's preview text to our AI provider (Anthropic) to write a short summary, sends you a notification with the sender, subject, date and summary, and adds the label “TAN/Inbox” to the email thread (TAN creates the labels TAN/Inbox, TAN/Active, TAN/Done and TAN/Skip in your mailbox).
- Every 2 hours it checks email threads you replied to through TAN and reminds you if no answer has arrived after 3 days (you can extend or close the reminder).
- Every 5 minutes it checks your primary calendar for events starting in about 30 minutes and sends you a reminder. To add a helpful note, it sends the event title and location, together with notes from your TAN memory, to our AI provider (Anthropic).
These checks stop when you disconnect Google (see Section 6).
We do not keep a copy of your mailbox or calendar. We keep:
- for each email thread TAN has notified you about or sorted for you: the thread ID, subject, sender, date and the AI summary — until you disconnect Google or delete your TAN account;
- the notifications and reminders described above, and the assistant's replies about your email and calendar, in your conversation history — for 30 days;
- short records of email and calendar actions — for example the sender, subject and preview of emails found in a search, the recipient and subject of an email you sent, or the title, time and place of an event created — for up to 365 days, so the assistant can recall them;
- the text of an email you answer from a notification (up to 2,000 characters), which becomes part of your conversation.
1.4 Payment Information
Payments are processed through Telegram Stars (Telegram's built-in payment system). We do not collect or store credit card numbers or banking details. We only store transaction records (amount, date, description).
1.5 API Keys (BYOK)
If you provide your own API keys (Bring Your Own Key), they are encrypted using AES-256-GCM before storage and are never stored in plain text.
1.6 Health Data (WHOOP)
If you connect a WHOOP account, we request read access to your WHOOP profile, sleep, recovery, cycles, workouts and body measurements. After you connect, TAN imports your available WHOOP history and then checks for new data every 15 minutes. We store the records WHOOP provides — sleep (including naps), daily recovery and strain, workouts, and body measurements (height, weight, maximum heart rate) — with figures such as recovery score, heart-rate variability, resting heart rate, and sleep duration and stages, together with the full record as WHOOP sends it. The assistant uses this data to answer your questions, in your briefings and in a morning recovery message; for this, the relevant figures are sent to our AI provider (see Section 4). We store encrypted WHOOP tokens to maintain the connection.
When you disconnect WHOOP (/disconnect whoop), we revoke TAN's access at WHOOP, delete the tokens, stop importing and delete the health data imported from WHOOP. Messages in which the assistant already used these figures stay in your conversation history for the periods in Section 1.2.
2. How We Use Your Information
We use your information to:
- Provide and operate the AI assistant service
- Process your requests (web search, media generation, reminders)
- Access Google services on your behalf (Calendar, Gmail) when you ask, and in the background to notify you of new emails, unanswered threads and upcoming events (see Section 1.3)
- Use health data from a connected WHOOP account to answer your questions and prepare briefings and recovery messages (see Section 1.6)
- Maintain conversation context and long-term memory
- Process payments and manage your subscription
- Improve the service and fix issues, including automated quality reviews of conversations (see Section 9)
3. Google API Services — Limited Use Disclosure
TAN's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We only access Google user data that is necessary to provide TAN's Gmail and Calendar features: the actions you ask for (viewing and creating calendar events; reading, sending and labeling emails) and the new-email, follow-up and event notifications described in Section 1.3.
- We do not use Google user data for advertising purposes.
- We do not sell Google user data or share it with third parties, except as necessary to provide these features: we send email and calendar content to our AI providers — Anthropic, to answer you and to write email summaries and event notes, and Google Gemini, to index it so the assistant can recall it later and to answer you when Claude is unavailable.
- We do not use Google user data to build user profiles for advertising or marketing.
- We store Google user data only as described in Section 1.3: encrypted OAuth tokens; for each email thread TAN notified you about or sorted, its subject, sender, date and AI summary (until you disconnect Google or delete your account); email and calendar notifications and the assistant's replies about them in your conversation history (30 days); and short records of email and calendar actions (up to 365 days).
- We do not use Google user data to develop, improve or train generalized AI or machine-learning models.
- We do not allow people to read your Google user data, except: with your permission (for example, when you ask us for help with a specific email or event); when necessary for security purposes, such as investigating a bug or abuse — including a problem flagged by the automated review described in Section 9, whose conversation excerpts can include email notifications and the assistant's replies about your email and calendar; or when required by law.
4. Data Sharing and Third Parties
TAN relies on external third-party services to operate. Your data may be shared with these providers as necessary to deliver the service, including but not limited to:
- AI model providers — your messages and the data needed for a task are sent to: Anthropic (Claude: the assistant, summaries, email and calendar notes, memory, automated quality reviews and support replies); Google (Gemini: indexing your messages and memory for search, describing photos and documents, speech, image and music generation, and answering in place of Claude when it is unavailable); Groq (converting voice messages to text); OpenAI (image generation). If you add your own API key for another provider, your conversations with the assistant are sent to that provider.
- Connected services — Google (Gmail, Calendar) and WHOOP, when you connect them; data is exchanged with these services as described in Sections 1.3 and 1.6
- Search, maps and media providers — when you ask for web search, web pages, places and directions, weather or media: Brave and Tavily (web search), Browserless (loading web pages and screenshots), Google Maps, Open-Meteo (weather), fal.ai (video), Mureka (music, including a melody you record), Cartesia and Inworld (speech), Giphy (GIFs)
- Infrastructure providers — Telegram (message delivery and payments), Fly.io (hosting), Supabase (database), Upstash (cache), Amazon Web Services (message queue), Sentry (error monitoring), Amplitude (product analytics)
We do not sell your personal data. However, third-party providers process your data according to their own privacy policies, which are entirely beyond our control. By using TAN, you acknowledge and accept the following:
- Your data will be transmitted to and processed by external services in various jurisdictions worldwide
- TAN has no control over how third-party providers store, process, retain, or protect your data once it leaves our systems
- TAN is not responsible for any data breach, loss, unauthorized access, or misuse of your data by third-party providers
- You assume all risks associated with the transmission of your data to external services
5. Data Security
We take commercially reasonable measures to protect your data, including:
- AES-256-GCM encryption for API keys and OAuth tokens at rest
- TLS encryption for all data in transit
- Isolated virtual machines for each user's AI agent execution
- Regular security audits of our infrastructure
No method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee its absolute security. We are not liable for any unauthorized access, data breach, data loss, or other security incident resulting from factors beyond our reasonable control, including but not limited to attacks on third-party infrastructure, zero-day vulnerabilities, or force majeure events.
6. Data Retention and Deletion
We keep your data for the periods below, and everything else for as long as your account exists:
- conversation history, including the bot's notifications: 30 days;
- messages and replies indexed for search, and records of email and calendar actions: 365 days;
- conversation summaries: 180 days;
- descriptions and extracted text of photos and files you send: 90 days; media memory: 365 days;
- records of images, videos and music you generate (prompts and links): 90 days;
- messages the bot receives in group chats: 7 days; the group search index: 6 months;
- email thread records: until you disconnect Google, ask us to delete them or delete your account;
- health data imported from WHOOP: until you disconnect WHOOP, ask us to delete it or delete your account;
- memory facts and quality-review findings: until deleted at your request or together with your account;
- payment records: as long as needed for accounting and legal obligations.
You can request deletion of your data at any time by contacting us. Upon request, we will:
- Delete your conversation history
- Delete your stored memory
- Revoke and delete your Google OAuth tokens, and delete your email thread records
- Revoke and delete your WHOOP tokens, and delete your health data
- Delete your encrypted API keys
- Remove your account data
Please note that residual copies of your data may persist in backup systems for a limited period after deletion. Data that has already been transmitted to third-party providers is subject to their own retention policies and cannot be deleted by us.
You can disconnect your Google account at any time using the /disconnect command in the Telegram bot. It revokes TAN's access at Google, immediately deletes your stored Google OAuth tokens and your email thread records, and stops the background email and calendar checks. Your conversation history and the records of email and calendar actions are not deleted when you disconnect; ask us if you want them deleted. You can disconnect WHOOP with /disconnect whoop: it revokes TAN's access at WHOOP, deletes your WHOOP tokens and deletes the health data imported from WHOOP.
7. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Revoke Google account access at any time (via
/disconnector through your Google Account permissions) and WHOOP access (via/disconnect whoop) - Ask the assistant to forget specific facts or everything it remembers about you
- Export your data upon request
8. International Data Transfers
Your data may be transferred to, stored in, and processed in countries other than your country of residence, including the United States and other jurisdictions where our third-party service providers operate. These countries may have data protection laws that differ from your jurisdiction. By using TAN, you consent to such transfers. We do not guarantee that data protection standards in recipient countries will be equivalent to those in your jurisdiction.
9. Automated Processing and AI
TAN uses automated AI systems to process your messages and generate responses. To find mistakes in the assistant's answers, an automated AI review (Anthropic Claude) checks conversations with at least three messages from you every day, and more thoroughly once a week; when it flags a possible problem, it saves a short quote from the conversation with its assessment, kept until your account is deleted. Our team may read the flagged part of a conversation — with up to two hours of messages before and after it — and the related memory entries and file descriptions, to investigate and fix the problem. We may also read your data when you ask us for help, for security purposes such as investigating abuse, or when required by law. You acknowledge that:
- AI-generated responses may be inaccurate, incomplete, or inappropriate
- Automated processing is inherent to the service and cannot be opted out of while using TAN
- We are not liable for any decisions you make based on AI-generated content
- Anthropic, Google (Gemini), OpenAI and Groq — the AI model providers listed in Section 4 — process your data under API terms that do not allow them to train their models on it. The other providers listed there process the data they receive under their own terms, and some of them — for example Cartesia and Inworld (speech) and Tavily (web search) — may use it to improve their services and models. If you use your own API key, the terms of your own account with that provider apply.
10. Data Breach Notification
In the event of a data breach that is likely to result in a risk to your rights, we will make reasonable efforts to notify affected users through the Telegram bot within 72 hours of becoming aware of the breach. However, we cannot guarantee that notification will be delivered if your Telegram account is inaccessible, and we bear no liability for delays caused by circumstances beyond our control.
11. Limitation of Liability
To the fullest extent permitted by applicable law:
- TAN shall not be liable for any indirect, incidental, special, consequential, or punitive damages arising from data processing, data loss, unauthorized access, or any other privacy-related incident
- Our total liability for any claim related to privacy or data protection shall not exceed the amount you paid to TAN in the twelve (12) months preceding the claim
- TAN assumes no responsibility for the privacy practices or data security of any third-party services used in connection with the service
- You agree to use the service at your own risk and accept full responsibility for any data you transmit through TAN
12. Cookies and Analytics
The tan.org website may use essential cookies for basic functionality. It does not use analytics, advertising or cross-site tracking cookies. The Telegram bot does not use cookies. To understand how the bot is used, we send usage events — such as which features you use, your plan, language and message counts — linked to your Telegram user ID to our product analytics provider (Amplitude).
13. Children's Privacy
Our service is not directed to children under 13 (or under 16 in the European Economic Area). We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal information, we will take steps to delete such information promptly.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of significant changes through the Telegram bot. Continued use of the service after changes constitutes acceptance of the updated policy.
15. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, contact us at:
- Email: privacy@tan.org
- Telegram: @tan_org_bot
See also: Terms of Service