Exact Receipt never asks for seed phrases, private keys, card numbers or online-banking codes.
Information the service handles
- Telegram account data: numeric Telegram identifier, username when present, first name, language code and last interaction time.
- Seller access and invoice data: access-request category and description, Stars amount, purpose, promised buyer result, intended Telegram username when used, order status, delivery reference, dispute status, platform fee, reserve and seller-settlement entries.
- Telegram Stars order data: Exact Receipt order identifier, price, status, timestamps and Telegram payment-charge identifier needed for replay protection and refunds.
- First-party acquisition data: a Telegram-signed non-personal campaign label and one event per account, campaign and stage such as app open, seller request, invoice creation or genuine payment.
Why the information is used
- Authenticate a Telegram Mini App session and isolate each user's records.
- Create, deliver and display Stars invoices, seller orders, payment status, protection periods and payout requests.
- Answer payment support and process an operator-approved refund.
- Detect abuse, enforce rate limits and maintain operational logs.
- Measure the first-party product funnel without advertising identifiers or transaction contents in campaign reports.
What is not used
The public website does not install advertising pixels, third-party analytics SDKs or marketing cookies. Exact Receipt does not sell personal information. Local browser storage may remember the Mini App's selected language and appearance on that device.
Services involved
Telegram supplies the signed Mini App session and Stars payment updates. Infrastructure providers host the application and database. If a user voluntarily opens a GitHub issue or security report, GitHub processes that submission under its own terms.
Retention
No fixed automated deletion schedule is currently configured for service records. Records are retained for service operation, replay protection, support, refunds and legitimate recordkeeping. Contact the operator to request access, correction or deletion; a request may be limited where a record is needed to prevent duplicate credit, document a payment/refund, comply with law or remains public on-chain.
Security boundary
The production site uses HTTPS, validates Telegram's signed launch data server-side, isolates records by the authenticated Telegram user and stores replay keys with the corresponding credit transaction. These controls reduce risk but are not a security audit or a guarantee that every incident is impossible.
Report a suspected vulnerability through the repository's private security-advisory feature. Do not include wallet secrets or private transaction histories.
Your choices and requests
You can avoid the service by not opening the bot or Mini App. Depending on your jurisdiction, you may have rights to access, correct, object to or request deletion of personal data.
Send privacy requests to gudov.igor@gmail.com or @zhudov. Include enough information to identify the relevant Exact Receipt account or order, but never send a seed phrase or private key.
Changes
Material changes will be posted on this page with a new effective date. This privacy disclosure does not override the separate service terms.