Your data is yours. We use it only to provide the service, and we protect it.
1General provisions
This policy explains how Sayohatchi Portal (the website and Telegram bot) collects, uses, and protects your personal data.
We only collect the information necessary to provide the service, we do not sell it, and we do not share it with others for advertising purposes.
2What data we collect
Account data:
- Name, email, phone (optional), profile photo;
- Password — only as an irreversible hash (the password itself is never stored);
- Language, time zone, home country, city, and currency;
- Two-factor authentication settings (secret key encrypted, recovery codes hashed).
Via Telegram:
- Telegram ID, username, and your name;
- Messages you send to the bot: text, photos, videos, voice messages, documents, locations, and contacts;
- Messages in groups where the bot has been added and activated — according to the group settings.
Media and location:
- Uploaded files and their metadata (for example, when a photo was taken and its GPS coordinates);
- Locations you send in messages;
- Browser location for the "current location" clock in the top bar — used only with your permission to find the nearest city and time zone, and never stored on the server (the result is remembered only in your browser).
Technical data:
- IP address, browser and device name, sign-in and security event history;
- Only essential cookies: session, security (CSRF), language choice, and Telegram sign-in confirmation.
Plans and payments: history of orders, plans, amounts, promo codes, and bonuses. We don't store bank card details.
Voice interpreter and SOS:
- text spoken or typed in the interpreter, its translation, your voice recording and the spoken translation — stored for service quality, abuse prevention and dispute resolution; only the Portal administration can see them;
- medical card — stored encrypted and visible only to you; when you tap “share my location”, coordinates are sent only to your trip members.
3How we use your data
- Providing the service: storing, organizing, searching, and showing entries on the map;
- Analysis, translation, and summaries using AI;
- Protecting your account: detecting suspicious sign-ins and alerting you to sign-ins from new devices;
- Notifications: sign-in codes, plan expiry, important changes;
- Keeping track of plans and payments;
- Improving the Portal — based on aggregated statistics that can't identify you.
4Artificial intelligence (Google Gemini) processing
The text of your messages, photos, and voice messages are sent to the Google Gemini API for analysis, transcription, translation, and search. Only the part needed for the task is sent.
Google processes this data in accordance with its API Terms of Service and Privacy Policy. The analysis results are stored within your entries on the Portal.
If AI processing is disabled, messages are sorted based on simple rules (without AI).
5Third parties
Data is shared only with partners needed to provide the service:
- Telegram — messaging via the bot and sign-in;
- Google — Gemini AI and (if enabled) Google sign-in;
- Map providers (OpenStreetMap, Amap) — map layers are loaded directly by your browser, so these providers may see your IP address;
- Email delivery service — for recovery codes and notifications;
- Hosting (server) provider — for storing data.
In cases provided for by law, data may be disclosed upon an official request from competent authorities.
6Who can see your entries
You control the visibility of each entry:
- "Private" — only you;
- "Trip members" — people added to the trip;
- "Team" — members of the Portal team;
- "Public" — everyone, including people not signed in to the Portal.
Anyone you give a trip share link to can also see the public part of that trip. You can turn off the link at any time.
Portal administrators may view data only for technical support, security, and investigating violations.
7Retention period
- Account and entries — kept as long as your account is active;
- Raw technical updates from Telegram — 30 days;
- One-time sign-in and verification codes — deleted within 24 hours after they expire;
- Backups — up to 14 days, then deleted automatically;
- Payment records — for as long as required by law.
8Data security
All connections are encrypted via HTTPS. Keys and secret settings are stored encrypted, passwords are hashed, and files are served only after permission checks.
Two-factor authentication, device management, and sign-in history are available in the Security center.
9Your rights
- View and correct your data — on the Profile and entry pages;
- Export (depending on your plan) and delete your entries;
- Disconnect your Telegram or Google account at any time;
- Ask to opt out of notifications and AI processing;
- Request complete deletion of your account and all data.
10Data deletion
To delete your account, send a request to the Portal administrator (or via the Telegram bot). Once the request is approved, your account, entries, and files will be deleted within 30 days.
Deleted data is also removed from backups within 14 days. Payment records that the law requires us to keep are an exception.
Messages sent by other members in groups are considered their data and will not be deleted along with your account.
11Children
The Portal is not intended for children under 16. If you learn that your child signed up without parental consent, let us know — the account will be deleted.
12International data transfers
Portal servers and our partners (for example, Google) may be located in other countries. When data is transferred, the safeguards described in this policy still apply.
13Changes and contact
When the policy is updated, the date on this page changes; we'll notify you of important changes in advance.
For privacy questions, contact the Portal administrator.
Via Telegram: message the bot — @SayohatchiUZ_bot
Last updated: 28 September 2026