Your data is processed by us — reLynth. The Service is run by a private individual; we provide their name and postal address on a well-founded request — to you, to a supervisory authority or to a court.
For anything about your data: [email protected].
This document sets out what the Service collects, why, on what legal basis, how long it keeps it and how to have it deleted.
What we collect
1.1. What Telegram passes to us
When you interact with the bot, Telegram gives us:
- your Telegram ID, first name, last name and username, where you have them;
- your Telegram interface language;
- whether you have Telegram Premium (Telegram's subscription, not our reLynth Premium);
- for groups, the id, type and title of the chat the message came from.
We store the identifier of your Telegram profile photo, and keep a copy of the image for up to 7 days, so it can be shown to you in the app and in our internal panel without asking Telegram for it again on every open. The copy expires by itself.
1.2. What you do in the Service
- the links you send and the outcome: platform, kind of material, chosen quality, the platform's identifier for that material, success or error;
- your settings: language, bot mode, caption signature;
- in groups, the chat settings configured by its administrators;
- correspondence with support — it takes place in our separate support account in Telegram, not through the bot;
- where you came from: a referral link or a promotional parameter.
We do not read or store the content of your messages to the bot — other than the links you send to it as a command.
1.3. Payment
Payment happens entirely on Telegram's side. We never receive or store card numbers, payment credentials or details of your payment method. From Telegram we receive: that payment happened, the plan, the number of Stars, the charge identifier (needed to issue a refund) and the period end date.
1.4. Technical data
IP address and browser headers when you open the mini app, in server logs, as on any network. We do not build a profile from them and do not connect them to advertising.
There are no advertising trackers, pixels or third-party analytics in the Service. The mini app stores only your chosen language and interface flags on your device.
1.5. Public data of checked TikTok videos
When a TikTok video or account is checked in the bot, we keep what TikTok publicly shows about the video and its author at that moment:
- the video's statistics — views, likes, comments, shares, saves — and its visibility signals, including what the Service shows as a "shadowban";
- the video's characteristics: duration, region, quality, how it was made;
- the author's public profile: username, display name, bio, follower and video counts, account creation date;
- the full platform response all of this is taken from.
This is data about the video and its author, not about you. It is stored without your Telegram ID and without any record of who asked for the check. The Service may ask TikTok again for the statistics of a video already checked, to see how they change over time.
Why, and on what basis
| What we do | Why | Basis (GDPR) |
|---|---|---|
| Process a link and deliver the file | This is the service itself | Contract, Art. 6(1)(b) |
| Keep your account and settings | So the bot remembers your choices | Contract |
| Run subscriptions and payment records | To grant access and issue refunds | Contract |
| Keep payment records after a refund | Accounting and tax | Legal obligation, Art. 6(1)(c) |
| Keep a log of requests | Error diagnostics, the stats in your profile, abuse prevention | Legitimate interest, Art. 6(1)(f) |
| Keep public data of checked TikTok videos (see 1.5) | Statistics and comparisons in video checks, tracking videos' visibility, training the checker's models | Legitimate interest, Art. 6(1)(f) |
| Block abusers | Keeping the Service working and safe | Legitimate interest |
| Answer support requests | To resolve your issue | Contract |
| Confirm your sign-in to a partner service (see 3) | You came to the bot through its sign-in link yourself | Contract, Art. 6(1)(b) |
| Make encrypted backups of the database | Not to lose data in a failure | Legitimate interest, Art. 6(1)(f) |
| Send operational messages | Changes to terms, outages, subscription ending | Contract |
| Show advertising on the free tier | Advertising pays for the free part of the Service | Legitimate interest, Art. 6(1)(f). Ads are not selected for you and are removed by a reLynth Premium subscription |
| Tell you what is new in the Service | To announce new features | Legitimate interest, Art. 6(1)(f), opt-out at any time |
The Service makes no automated decisions producing legal effects for you. There is no profiling for advertising.
2.1. Messages and advertising
Messages from the bot fall into two kinds, and the distinction determines your rights.
Operational messages — changes to the terms, an outage, your subscription ending, a reply from support. They are part of the service, they go to everyone, and they cannot be turned off: without them you would not learn about things that affect your agreement with us. The only way to stop them is to stop using the Service.
Advertising — it pays for the free part of the Service. Using the bot for free is possible precisely because advertising covers the cost of running it. Ads are labelled as ads. They are removed by a reLynth Premium subscription: subscribers get no advertising messages.
The things worth knowing about how ours works:
- Ads are not selected for you. We do not use your link history, the platforms you use, your interests or anything else to decide what to show you. Everyone gets the same thing.
- Advertisers receive none of your data — no identifier, no name, no activity history. We send the message ourselves, from our side; the advertiser gets only the total number of recipients.
- There are no third-party counters or trackers in the Service. Nobody but us sees what you do in the bot.
Separately from advertising, we occasionally announce what is new in the Service itself. You can opt out of those with the "reLynth news" switch in your mini app profile; this affects neither operational messages nor advertising on the free tier.
Who we share data with
We do not sell data and do not pass it to advertisers, data brokers or anyone else for their own purposes. Sharing happens in four cases only:
Telegram. The Service runs inside Telegram, and nothing works without exchanging data with it. Telegram processes your data under its own rules, which we do not control.
Our contractors — only as far as running the Service requires, and only on our instructions: the hosting provider (servers and database); the network provider through which the website and the mini app are reached and which protects them from attacks (Cloudflare) — it sees the IP address and the request itself; and network proxy providers (our requests to source platforms go through them). They may not use the data for their own purposes.
Partner subscription checks. If you receive access through a partner programme, your Telegram ID is passed to the partner service so it can confirm your subscription to the relevant channels. Only the identifier and the result of the check are exchanged.
Signing in to partner services. Some partner services — for example, the Editing News browser extension — let you sign in to them through our bot. If you came to the bot through such a sign-in link, we pass that service your Telegram ID, username and first name so it can recognise you. This happens only when you follow the link yourself; from then on the partner processes the data under its own rules. Partner services are not reLynth: a reLynth Premium subscription does not include their paid features, and their subscriptions do not include ours.
We will also disclose data where required by law, a court or a competent authority — and, where not prohibited, we will tell you about the demand.
Servers and contractors may be located outside your country. For transfers out of the EEA we rely on adequacy decisions or on the European Commission's standard contractual clauses.
The files you download
This section is precise because intuition usually gets it wrong.
We do not keep the files. A file is downloaded to temporary storage for as long as processing takes and is deleted as soon as it has been sent. After that the file lives on Telegram's servers — like any attachment you have ever sent or received in a messenger — and is governed by Telegram's rules, not ours.
We do keep the identifier Telegram assigns to that file (file_id), so that the next
person who asks for the same clip gets it instantly instead of making the source
platform serve it again. That table is keyed to the material, not to the user: it
holds no identifier of yours, and it cannot be used to find out who downloaded what.
The identifiers are kept indefinitely — that is the entire point of a cache.
Separately from the cache we keep a log of requests (see 1.2), and that one is linked to you. Its retention is in the next section.
How long we keep it
| Data | Retention |
|---|---|
| Account and settings | For as long as you use the Service |
| Account with no activity at all (bot blocked, no requests) | 24 months, then deleted |
| Request log: links, platform, outcome | For as long as your account exists; anonymised when the account is deleted (see below) |
| Anonymised statistics: daily counters and the log entries of deleted accounts | Indefinitely (the link to you is removed) |
| Support correspondence | 12 months after the last message; 3 years if it concerned a payment or a refund |
| Payment records | The period required by accounting law, typically up to 7 years |
| File identifier cache | Indefinitely; contains no personal data |
| Data of checked TikTok videos (see 1.5): the videos' statistics and characteristics, their authors' public data, and the full TikTok responses all of this is taken from | Indefinitely; not linked to whoever ran the check; deleted at the author's request (see 6) |
| Server logs | 30 days |
| Database backups, encrypted | On the server — up to 6 months; the off-site copy — indefinitely (see below) |
The request log is not aged out on a timer: the stats in your profile, our error diagnostics and the Service's statistics rest on it. When you delete your account — on your request, at any time, without giving reasons (how to ask is in the next section) — its entries lose their link to you: your Telegram ID, name and username are removed from them. What remains is anonymised statistics — which links the Service processed and when — from which nobody can tell what you in particular sent.
Payment records are the only thing we cannot delete on request before their period expires: keeping them is required by law. Everything else is deleted from the working database at once.
Backups. We copy the database so as not to lose it in a failure. The copies are encrypted, and the key is held only by us and never kept on the server. One copy is on the server, the off-site one in a private Telegram group: to Telegram these are encrypted files. A single record cannot be removed from a copy, so the data of a deleted account stays in copies made before the deletion: on the server for up to 6 months, in the off-site copy for as long as it exists. The copies are not used to run the Service. If we ever have to restore the database from a copy, we delete the deleted accounts again before the Service goes back online.
Your rights
You may:
- access the data we hold about you and receive a copy;
- rectify inaccurate data;
- erase your account and the records linked to it;
- restrict processing, or object to processing based on legitimate interest — including opting out of announcements;
- port your data in a machine-readable format;
- withdraw consent where processing rests on it, without affecting the lawfulness of processing before withdrawal.
How to exercise them. Write to [email protected], or tap "Support" in the app — it opens a chat with us in Telegram.
So as not to hand your data to someone else, we need to tie the request to your Telegram account. In the support chat that is visible straight away. If you write by email, include your @username or numeric ID. We do not ask for documents.
We respond within 30 days; for a complex request we may extend by up to 60 days, telling you first.
If you are a TikTok creator. The data in 1.5 concerns the authors of videos, including people who never use the bot, and these rights are theirs too. To have the data about your account and videos deleted, or to stop us processing it, write to [email protected] and name your TikTok profile. To make sure the profile is yours, we may ask you to add a line we send you to its bio for a while. So that your data is not collected again the next time one of your videos is checked, we keep the numeric id of your TikTok account on a list of those whose data is not processed — and nothing else about you.
If you believe we are infringing your rights, you may complain to the data protection authority where you live or work. We would appreciate hearing from you first.
Security
Access to the database and the internal panel is restricted, connections are encrypted, backups are kept only in encrypted form, and administrator actions are written to a separate audit log. Absolute security does not exist; if a breach affecting your data occurs, we will notify the supervisory authority within 72 hours and notify you where the risk to you is high.
Children
The Service is not intended for anyone under 16 (see clause 2 of the Terms of Use) and does not knowingly collect their data. If an account turns out to belong to a child below the applicable age, we delete it. Enquiries from parents and guardians go to [email protected] and are handled as a priority.
Changes
The current version is always at https://relynth.com/privacy. We announce material
changes in the bot at least 14 days before they take effect. The date in the header is
the date from which the current version applies.
reLynth [email protected] · https://relynth.com