Privacy Policy
Updated: 2026-07-16
This is the authoritative English version of this document.
Who we are
CoListing is a Telegram bot and Mini App service for creating AI-assisted listing drafts. The CoListing operator processes the data described in this policy to operate, secure, and support the Service. This policy applies to the bot, Mini App, and website. The Service is for users who are 18 or older and is not directed at children. For questions about processing, data-subject rights, or account deletion, use /feedback in the Telegram bot or the email shown in the Operator information box on this page.
What data we process
Telegram and service-use data
- Telegram user ID, username when available, selected language, country if set, last-activity time, and records of acceptance of legal terms (the legal bundle and, in the Mini App, photo-rights confirmations);
- messages, item descriptions, chosen marketplace and country, image technical metadata, and Telegram file identifiers;
- generated listings, including structured output, final text, price indication, moderation results, delivery history, and execution metrics;
- AI instruction and request snapshots and AI responses for reproducibility, diagnostics, and support. These snapshots do not contain original photo bytes: base64 images are removed from stored payloads.
Photos and AI processing
The CoListing bot and Mini App send photos, descriptions, and the necessary context to an AI service to generate a listing draft. CoListing does not persistently store raw user photo files on its own servers.
The Mini App has a narrow exception: downscaled photo bytes are temporarily stored in the database solely as a delivery buffer so the bot can deliver the completed result to the chat. They are deleted immediately after successful or terminally failed delivery. If the result is not sent or delivery does not complete, the delivery window ends 24 hours after the photos were stored: the photos become unusable for further delivery and are removed from the active database by the next automated cleanup cycle. CoListing is not a photo storage or backup service — keep your original photos. This transient store is not part of the 90-day listing history.
We do not use your content to train AI models without your explicit opt-in.
Payments
Payments are available only through Telegram Stars. We retain the data needed to grant credits, provide support, and issue refunds: selected package, number and price of Stars, currency, status, dates, Telegram payment ID, and credit-ledger entries. We do not receive payment-card details, payment-account details, or a Stars balance. Telegram and, depending on how Stars were acquired, its payment provider handle Star purchases and their payment data.
Technical data and logs
We generate limited operational logs: time, request path and method, query string, response status, duration, correlation ID, and error details. The Service is designed not to log descriptions, AI responses, photos, personal data, or secrets. Logs are used for security, abuse prevention, and troubleshooting.
Purposes, legal bases, and retention
The CoListing backend and PostgreSQL database run on server infrastructure administered by CoListing using Easypanel. This database stores the account, listing history, payment records, legal acceptance records, moderation records, and support records needed for the purposes below.
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Providing the Service (drafts, price indications) | Telegram user ID, language, country (if set), item descriptions, photo metadata, generated results | Performance of a contract | Listing history and AI snapshots up to 90 days; bot session drafts up to 7 days; Mini App photo bytes until delivery or the end of the 24-hour delivery window (see Photos and AI processing) |
| Payments and credits | Stars transactions, Telegram payment IDs, credit ledger | Performance of a contract; legal obligations | For the life of the account |
| Legal acceptance records | Acceptance kind (legal bundle or photo rights), Telegram user ID, acceptance timestamp, legal bundle version, acceptance source, interface language | Legitimate interest (demonstrating acceptance of the terms, handling disputes, and defending legal claims) | Lifetime of the account plus 3 years after its closure; longer only for individual records needed for an active dispute (see below) |
| Moderation and security | Submitted text, moderation verdicts, minimal security logs | Legitimate interest (abuse prevention) | Up to 90 days |
| Support and complaints | Messages you send to support or via Report | Legitimate interest (handling requests) | 12 months |
| Analytics and marketing (website only) | See Analytics / Marketing below | Consent | Consent stored 12 months |
Legal acceptance records do not include IP addresses. After the account is deleted, legal acceptance records — including the stored Telegram user ID — are automatically deleted once the 3-year period ends. An individual record is kept longer only while it is needed for an active complaint, claim, regulatory proceeding, or court case, under a time-bound legal hold, until the matter is finally resolved; after that the record is deleted or irreversibly anonymized. Operational logs are not sent to centralized storage. They rotate locally with a 200 MB per-container cap, so the retention window depends on service activity rather than a fixed number of days. The functional key tcl-lang stores the selected language in your browser with no expiry until you clear the site’s browser data.
Third parties and international transfers
We disclose only the data necessary for the relevant function. Data is processed by the named providers under their data-processing agreements and standard contractual clauses where applicable. Processing may occur outside your country of residence.
- Telegram Messenger Inc. - bot and Mini App messaging, Telegram ID, result delivery, and Telegram Stars (policy: https://telegram.org/privacy; Stars terms: https://telegram.org/tos/stars/).
- Nebius AI - the current AI-generation provider; receives the photos, description, and generated prompt needed to produce a listing (policy: https://docs.nebius.com/legal/privacy).
- OpenAI, L.L.C. - used only when the OpenAI configuration is enabled: for AI generation and the built-in web-search tool used for price estimation. In that mode it receives the request data needed for the function (policy: https://openai.com/policies/privacy-policy/).
- Google LLC - Google Tag Manager and Google Analytics 4 (policy: https://policies.google.com/privacy).
- Meta Platforms Inc. - Facebook Pixel (policy: https://www.facebook.com/policy.php).
- Yandex LLC - Yandex Metrika and Yandex Forms (policy: https://yandex.ru/legal/confidential).
We do not sell personal data or use listing content to target advertising.
Analytics, marketing, and forms
Analytics
- Google Tag Manager may deliver the configured Google Analytics 4 tags. Google Analytics 4 and Yandex Metrika help us understand website traffic, button clicks, FAQ opens, and plan selections. These analytics-only trackers are enabled only after consent to analytics.
Marketing
- Facebook Pixel helps us evaluate advertising campaigns and marketing referrals. This tracker is enabled only after consent to marketing.
Forms
- Data submitted through Yandex Forms or Google Forms is processed by the form providers and used to respond to the user’s request. The providers’ policies and the relevant form’s settings govern their retention periods.
When trackers are enabled
Before a choice is made in the consent banner, the website does not load Google Tag Manager, Google Analytics 4, Yandex Metrika, or Facebook Pixel. If consent is declined, the trackers remain disabled. If previously granted consent is withdrawn, the page reloads to stop scripts that have already loaded. The Google Tag Manager container is restricted to analytics tags; marketing tags are not placed in it.
Your rights and contact
You may request access, correction, erasure, restriction of processing, or withdraw consent for optional trackers. To protect the account, we may ask you to verify the request through the relevant Telegram account. Erasure requests can be sent via /feedback in the bot or the Operator email shown on this page and are handled manually within 30 days during the pilot. After erasure, a limited set of legal acceptance evidence may be temporarily retained where needed to establish, exercise, or defend legal claims, within the retention limits described above. You can also clear browser data or update your tracker selection through the Privacy settings link in the website footer.