Telegram Directory Assistant ("TDA", "the service", "we") operates a public directory of real-estate listings sourced from public Telegram channels. This policy explains what we collect, why, and who we share it with.
1. What we collect
From visitors (no account required)
- Page view counts per listing, aggregated (not tied to your identity).
- Session cookiesfor browser-internal state (filter memory, last-viewed listings URL). Stored in your browser's
sessionStorageand cleared when you close the tab. - Standard request logs at the hosting level (IP address, user-agent, URL requested). Retained for 14 days by our host (Railway) for abuse and debugging only.
From signed-in users
- Email address (via Supabase Auth)
- Display name, role, plan tier — stored in our
user_profilestable - Saved listings and saved searches you create
- Reports / removal requests you submit (we store the listing id and your reason; your email is only included if you opt in)
From Telegram (public content only)
Our scraper reads the public preview pages of channels you or other admins add (https://t.me/s/<username>). We do not read private channels, direct messages, or any data tied to individual Telegram users.
2. How we use it
- Operate the directory: search, filters, sort, saved items
- Authenticate and authorize signed-in users
- Track listing popularity (views, saves) for ordering and admin reporting
- Translate listing text on demand using a third-party LLM (Anthropic Claude). Only the listing text is sent — never your account data.
- Detect and respond to abuse
3. Who we share data with
| Processor | What they receive |
|---|---|
| Supabase (DB + Auth) | All user account data and listings. Hosted in AP-Southeast-1. |
| Railway (hosting) | HTTP request logs, app server logs. |
| Anthropic (Claude Haiku) | Telegram post text only — for structured extraction and translation. No user account data. |
| Yandex.Direct (planned) | Standard ad-network cookies + IP. Only loaded for visitors who haven't opted out. We will update this policy when ads launch. |
| Telegram (read-only) | We fetch public channel preview HTML. We don't send any user data to Telegram. |
4. Cookies & local storage
We use the minimum necessary:
- Auth session cookie — set by Supabase when you sign in; lets us identify you on subsequent requests. Expires when you sign out.
- Filter memory —
sessionStoragekey remembering the last/listingsURL you visited. Cleared when you close the tab. - Theme preference — if you choose a dark/light theme, stored in
localStorage.
We do not use analytics cookies, fingerprinting, or third-party trackers today. If we add advertising via Yandex.Direct, the ad network will set its own cookies; this policy will be updated and a banner shown.
5. Your rights
You can request the following at any time by emailing privacy@telegram-directory-assistant.example:
- Access — a copy of the data we hold about you
- Deletion — we remove your account, saved items, and saved searches
- Correction — fix incorrect data
- Export — your saved listings and searches in JSON
We respond within 30 days. Account deletion is irreversible.
6. Children
The service is intended for users 16 and older. We do not knowingly collect data from anyone under 16.
7. Changes to this policy
When we update this policy, the new version replaces this page and the "Last updated" date changes. Material changes (new data sharing, new processors) will be announced via an in-app notice the next time you visit.
8. Contact
Questions or concerns? Email privacy@telegram-directory-assistant.example.
See also our Terms of Service.