Legal
Privacy Policy
Last updated: August 21, 2026
Scope
This policy covers the Do not remind me Telegram bot and this website. It explains what personal data is processed, why it is needed, where it goes, how long it is kept, and the choices and rights available to you.
Controller
Do not remind me is operated by Maksim Sovenkov, an independent developer. Privacy questions and requests can be sent to luckyfoxinthebox@gmail.com and are normally answered within one month.
Data the bot processes
The bot processes the following categories of data:
- Telegram account data: your numeric Telegram user ID and Telegram interface language. The ID links your bot account, short-lived session, and Google authorization. We do not receive your telephone number from Telegram.
- Bot account data: your selected timezone, plan tier, and the date the account record was created.
- Google account data: the email address of the connected Google account and its Calendar timezone.
- Google authorization data: an encrypted OAuth refresh token, the permissions granted, the connection status, and authorization timestamps. Access tokens exist only temporarily while a Google API request is made and are not stored in the database.
- Scheduling content: text or a voice note you send, its transcript, and the proposed event title, description, date, and time. This content can include personal data about you or another person if you put it in a message.
- Support and privacy correspondence: the email address and content you choose to send when you contact us.
Application logs record technical event names and error types. They are deliberately designed not to contain message content, voice notes, Google tokens, OAuth codes, Google email addresses, or Telegram user IDs. The web server’s application-level access log is disabled.
How the bot uses data
The data above is used only to:
- provide the bot, remember its language and timezone, and maintain the Google connection;
- transcribe a voice note and extract a proposed calendar event;
- show the proposed event for review and create it only after confirmation;
- revoke a Google authorization and erase the bot account when requested;
- respond to support, privacy, security, and legal requests; and
- protect and troubleshoot the service using data-minimised technical logs.
The bot does not sell personal data, use it for advertising, create marketing profiles, or make decisions that have legal or similarly significant effects.
Legal bases
For people covered by the GDPR, the legal bases are:
- Performance of a contract (Art. 6(1)(b)): the account record, message processing, Google authorization, and creation of events are necessary to provide the bot feature you request. The choice made on Google’s OAuth screen authorizes technical access; it is not treated as a separate GDPR consent where that access is necessary to provide the service.
- Consent (Art. 6(1)(a)): optional website analytics only. Refusing analytics has no effect on access to the website or the bot.
- Legitimate interests (Art. 6(1)(f)): proportionate security, abuse prevention, troubleshooting, support, and the establishment or defence of legal claims. Logs are minimised so these purposes do not require account identifiers or user content.
- Legal obligation (Art. 6(1)(c)): responding where applicable law requires disclosure or preservation of specific data.
Service providers and platforms
Data is handled by the following recipients for the stated purpose:
- Telegram delivers messages and operates the chat. Telegram processes its own copy of the chat under its terms and privacy policy and acts independently from the bot operator for that service.
- Anthropic (Claude API) receives message text or a voice transcript to extract a proposed event. It does not receive your Google token, Google email address, or existing Calendar events.
- OpenAI (audio transcription API) receives the voice-note audio to create a transcript. It does not receive your Google token, Google email address, or Calendar data.
- Google APIs receive the authorization request and the event details you confirm. Google also supplies the connected account email and Calendar timezone.
- Hetzner hosts the bot and its database in the EU on infrastructure controlled by the operator.
- Google/Gmail receives correspondence you send to the privacy contact address.
- Google Analytics receives website measurement data only when analytics is enabled and you have accepted it as described below.
Processor terms and data-processing addenda, including applicable transfer safeguards, are part of the operator’s contracts with service providers. Telegram and Google may also act as independent controllers for their direct relationship with their account holders.
AI processing and retention
Claude and OpenAI are used only for the user-facing scheduling flow. The operator does not opt in bot inputs or outputs for general model training.
Anthropic states that standard API inputs and outputs are normally deleted from its backend within 30 days. Its published policy permits longer retention where required by law or to enforce its usage policy, including longer periods for content flagged by safety systems. OpenAI publishes endpoint-specific retention controls and currently lists no customer-content application-state or abuse-monitoring retention for the audio transcription endpoint used by the bot. Provider-side service and security metadata may still be processed under the applicable agreements.
These provider periods are separate from the bot’s own three-hour in-memory period below. They may change when provider terms or the configured API product changes; any material change is reviewed before the bot adopts it and this policy is updated where necessary.
International transfers
The database is hosted in the EU. Telegram, Google, Anthropic, and OpenAI operate internationally, so data sent to them may be processed outside the EEA. Where GDPR transfer rules apply, the relevant provider terms use an adequacy decision such as the EU–US Data Privacy Framework where available and/or the European Commission’s Standard Contractual Clauses. The exact contracting entity and safeguard are maintained in the operator’s internal processing register rather than being inferred solely from a provider’s brand name.
Google permissions and Limited Use
The bot requests these Google permissions:
calendar.events.owned, which technically allows it to see, create, change, and delete events on Google calendars you own;calendar.settings.readonly, to read the Calendar timezone; andopenidanduserinfo.email, to identify the connected Google account.
The current bot code uses the event permission only to create an event on the primary calendar after you confirm the preview. It does not read, change, or delete existing events. The wider technical capability of the permission is disclosed because a compromised token would carry that capability even though the product does not use it.
Use of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not transferred to Anthropic or OpenAI and is not used to develop, improve, or train a generalised AI model.
Retention and deletion
- Scheduling content: voice bytes exist in process only while transcription is performed. Message text, transcript, clarifying question, and draft event are held in the bot’s in-memory session while the bot waits for an answer. The bot reminds you after one and two hours and clears the state after three hours of inactivity. A restart, cancellation, confirmation, or account deletion clears it earlier.
- Bot account and Google authorization: kept until you use
/delete_data. The OAuth record is deleted earlier if you use/disconnect. - Support and privacy correspondence: normally deleted within 12 months after the request is closed, unless it must be kept longer for a legal obligation or an active legal claim.
- Maintenance backups: created only while the bot is stopped for a deployment or migration, used only for rollback in that same maintenance window, and deleted within 24 hours. They are not kept as a historical archive.
- Consent choice: kept in your browser for 12 months unless you clear site data earlier.
- Analytics: when enabled, event-level data is retained for 2 months. User-level data has a 14-month rolling retention period: each new activity resets that period for the relevant user identifier, so data associated with a regularly active identifier may be retained for longer than 14 months from its original collection. Aggregated reports that no longer contain user-level or event-level data may remain longer.
/disconnect asks Google to revoke access and deletes the local OAuth record, but leaves the bot
account, email, timezone, and language in place. /delete_data revokes access on a best-effort
basis, deletes the account and OAuth rows, and clears the current in-memory flow. It does not delete
messages from your Telegram account or events already created in your Google Calendar.
Website analytics and device storage
Analytics is disabled unless a Google Analytics measurement ID is configured. When it is disabled, the site renders no analytics banner, loader, or Cookie settings control.
When analytics is enabled, nothing is sent to Google Analytics until you press Accept. If you accept, Google Analytics processes the pages viewed, referrer, browser, operating system, device type, a browser identifier, and approximate location derived from the IP address. Google states that GA4 discards the IP address before it is logged. Advertising storage, Google signals, and ad personalisation are disabled for this site, and no bot account identifier is sent to analytics.
The analytics cookies are host-scoped to this website:
| Cookie | Maximum lifetime | Purpose |
|---|---|---|
_ga |
2 years | Distinguishes one browser from another for measurement. |
_ga_<measurement-id> |
2 years | Maintains the state of a visit for this analytics property. |
The consent record is stored locally in your browser as dnrm.consent.v1. It contains the policy
version, your choice, and the time of the choice; it is not sent to the server. The record is
strictly necessary to remember and honour the decision.
Accept and Decline are offered at the same level. You can reopen Cookie settings from the footer. Declining after an earlier acceptance immediately disables further analytics calls on the current page and clears analytics cookies. A Global Privacy Control signal is treated as a refusal when no explicit choice has been stored.
Google Analytics uses its browser identifier to recognise repeat visits. The operator does not send a Telegram ID, Google email, or other account identifier to Analytics and normally cannot connect an analytics identifier to a named bot user. Analytics data is nevertheless treated as pseudonymous personal data; rights that require identification may be limited where the operator cannot identify the relevant record without collecting additional data solely for that purpose.
Security
- Network traffic uses HTTPS/TLS.
- Google refresh tokens are encrypted at rest, and the encryption-key set is stored separately from the database and supports rotation.
- Raw messages and voice notes are not written to the bot database or application logs.
- Production database and server access is restricted to the operator.
- OAuth codes, state values, access tokens, refresh tokens, and encryption keys are never logged.
- Security measures and service-provider terms are reviewed when the processing changes.
No online service can guarantee absolute security. A personal-data breach is assessed and documented. The competent supervisory authority is notified without undue delay and, where feasible, within 72 hours when the breach is likely to create a risk to people’s rights and freedoms. Affected people are also told without undue delay when the likely risk is high, subject to the exceptions in the GDPR.
Your rights
Subject to the conditions in applicable law, you may ask to:
- access personal data held about you and receive a copy;
- correct inaccurate account data;
- erase data, including directly through
/delete_data; - restrict processing while a qualifying dispute is resolved;
- receive data you provided in a structured, commonly used, machine-readable format where the portability conditions apply;
- object, on grounds relating to your situation, to processing based on legitimate interests; and
- withdraw analytics consent at any time through Cookie settings without affecting earlier lawful processing.
You may complain to the competent data-protection supervisory authority, including the authority where you live or work or where you believe an infringement occurred.
Send a request to luckyfoxinthebox@gmail.com. Identity is verified using the minimum information reasonably necessary, normally by asking you to contact the bot from the relevant Telegram account. The operator will not collect additional information just to identify an otherwise unidentifiable analytics record.
Data outside the bot’s control
- Your Telegram chat is held by Telegram. Delete it through Telegram if you want your copy removed.
- A confirmed event belongs to your Google Calendar and must be deleted there.
- Processor-side copies expire under the provider periods described above and may be subject to legal or safety exceptions in the applicable provider terms.
Children
The service is for people aged 18 or older. Telegram currently requires users in EU countries to be at least 18 to sign up. If the operator learns that a child used the bot, the associated bot record will be deleted and the Google authorization revoked where possible.
Changes
The date at the top is updated when this policy changes. A material change to bot data processing is announced through the bot before it takes effect where reasonably possible. A new analytics purpose, provider, or materially different storage practice invalidates the saved analytics choice and requires a new decision.
Contact
Privacy questions and requests: luckyfoxinthebox@gmail.com.