Stored so the service works
Encrypted Telegram session and configuration, allowlist, per-chat high-water marks, billing records, and content-free delivery and usage metadata.
Security
Plain details about what crosses the boundary, what remains, and how to leave.
Data boundary
A Digest needs temporary access to the chats you selected. The boundary is narrow by design.
Encrypted Telegram session and configuration, allowlist, per-chat high-water marks, billing records, and content-free delivery and usage metadata.
blablabot does not persist source messages, media, contacts, or generated Digest text. Allowlisted content is sent to the currently configured model provider for generation; provider retention and training follow the selected provider and account terms. Delivered Digest text remains in your Telegram chat.
A deny-by-default guard checks every Telegram API call before it reaches Telegram.
Sending, editing, deleting, reacting, joining, leaving, and marking messages read
Reading allowlisted chats when a Digest runs
auth.LogOut is the sole exception. It runs only when you disconnect your account or delete your data.
Your phone number, verification code, and 2FA password pass through an encrypted HTTPS Mini App form to complete login.
Your phone number and Telegram phone_code_hash stay only in process memory while login is pending, for up to 10 minutes. Verification codes and 2FA passwords are transient. None are requested in chat or logged; pending values are removed when login completes, is replaced, or expires.
One confirmed action halts activity and deletes your records from active blablabot systems. Protected backups expire within 14 days.
Choose Delete my data and confirm once.
We attempt to revoke the Telegram session. If Telegram logout cannot be confirmed, active blablabot data is still deleted and we tell you to revoke it in Telegram Settings > Devices.
Session, configuration, allowlist, high-water marks, billing, delivery, and usage records are deleted from active systems. Protected backups expire within 14 days and deletion records are reconciled before a restore. Delivered messages remain in Telegram; Telegram and model-provider data follow their terms. /start begins as new.
Honest risk
Reading chats through a personal Telegram account via the API is a gray area and is not explicitly sanctioned. Read-only access, narrow selection, no message storage, and immediate deletion reduce risk but cannot eliminate it.
Open blablabot in Telegram. You can disconnect and delete your data at any time.
Open @blabla_tldr_bot