Introduction
Dripl (“we”, “us”) runs a Telegram automation platform. This policy explains what we collect when you use Dripl or visit this site, why we collect it, who else handles it, and the choices you have.
Data we collect
- Your account
- Email address, name, a hash of your password, and your timezone and display preferences.
- Telegram accounts you connect
- The phone number, the session file that lets Dripl act for the account, and the contacts, groups and channels it syncs.
- What you create
- Scheduled messages, forwarding rules, templates, and the logs of what was sent or forwarded.
- Technical data
- IP address, browser details and request logs.
- Billing
- Your plan and invoices, and payment details from Stripe or DePay. Never full card numbers.
- Messages you send us
- The name, email address and message from the contact form.
How we use it
- Run Dripl for you: send your scheduled messages and run your forwarding rules.
- Take payments and manage your plan.
- Send service emails, such as password resets and email-change confirmations.
- Keep Dripl secure: rate limits, sign-in checks and error reports.
- See which public pages people visit, only if they accept analytics cookies.
- Answer the messages you send us.
Storage and security
Your data lives on servers run by our hosting provider. Every connection uses HTTPS, passwords are stored only as salted hashes, and each Telegram session is a separate file that only the Dripl app can read. The security page has the details.
Who processes your data
These services process personal data for us, each only for the purpose listed.
Stripe
When you pay by card
Card payments, subscriptions and invoices, on Stripe’s hosted checkout. Card numbers go to Stripe, never to us; we see only the card brand, the last four digits and the expiry date.
DePay
When you pay with crypto
Crypto payments. DePay handles the payment, and we receive the payment confirmation.
Telegram
For every connected account
Your connected accounts talk to Telegram through its API to send, forward and read the messages you automate.
Google Analytics (Google)
Only if you accept analytics cookies
Counts visits to our public pages and where visitors come from. Google Signals and ad personalisation are off, and no ad cookies are set.
Sentry
When error monitoring is switched on
Error reports from signed-in pages and from our servers, without cookies or authorization headers. Server errors carry your user ID. Screen replays are recorded only around an error.
Our email provider
Sends account emails (password resets, email-change confirmations) and delivers contact-form messages to us.
Our hosting provider
Runs the servers that hold the Dripl app and its database.
We don’t sell your personal data, and Dripl shows no ads.
How long we keep it
- Your account data, for as long as your account exists.
- Sent messages and forwarding logs, for 90 days.
- Audit log entries, for 12 months.
- Invoices, for as long as tax law requires.
To delete your account and its data, email us from the address you sign in with. We act on requests within one month, as the GDPR requires.
Your rights
If you are in the European Economic Area or the UK, you have the right to:
- Access
- Get a copy of your personal data.
- Rectify
- Correct inaccurate or incomplete data.
- Erase
- Have your data deleted.
- Restrict
- Limit how we process your data.
- Port
- Receive your data in a machine-readable format.
- Object
- Object to processing based on our legitimate interests.
To use any of these rights, email us from the address you sign in with. You can also complain to your local data protection authority.
Contact
Questions about this policy or your data? Email info@dripl.ai.