Privacy Policy
Review version: review-draft. This Policy explains how StickerKit handles personal data.
Who we are
StickerKit operates the @stickerkit_bot Telegram bot and the StickerKit Mini App at app.stickerkit.app.
- Data controller
- Not published in this review build.
- Seller
- Not published in this review build.
- Postal address
- Not published in this review build.
- Not published in this review build.
What we process, and why
- Your photo. We use the photo you send to make the stickers you asked for, and we delete it on the schedule below. It is not kept as part of your account. What we do with the metadata inside the file is stated in the processing facts below. We never use your photo to build a database of faces or to train a model.
- A record of your upload. We keep a short record of the photo you sent so the bot and the Mini App can carry on with the same order, or start it again if it was interrupted. It points at the file we already have rather than being a second copy of it, and it is deleted with the photo.
- The stickers we make. Previews, sticker images and the pack we publish are kept in private storage so we can show them to you, publish them, and restore them if something goes wrong. They are deleted on the schedule below.
- Error reports. If error reporting is switched on, the processing facts below name who receives it and what it contains. We keep it for the period set out below.
- Account and usage data, stored in our database: we store an internal account UUID and your Telegram provider user ID and may store fields Telegram makes available: display name, username, language code, premium-account flag, and last-seen time. We also store account locale, timezone, status, deletion state, and limited allowlisted integration metadata; whether your one-time free preview is available, temporarily reserved, or consumed; delivered-pack counters and set names; referral relationships; permission for the bot to message you; and which website link brought you to the bot. Product-event records contain the internal account UUID, an optional workflow ID, event time, bounded event name, schema version, allowlisted redacted properties, and expiry time. The product does not ask for your phone number or personal email address.
- Age and Terms confirmation. Before product access, we store the account linked to your Telegram user ID, the legal-bundle version you confirmed, the confirmation timestamp and source, and your adult self-attestation. We use this record to enforce the 18+ gate, know which Terms version you accepted and Privacy notice you acknowledged, and document the confirmation for compliance and dispute handling. It is a self-attestation, not age or identity verification: we do not ask for or store your date of birth or identity document.
- Provider-cost records. Provider-call, usage, allocation, revenue, and reconciliation records use an internal account UUID linked to your account rather than repeating the raw Telegram provider ID. They may include internal job, generation-attempt, order, product and budget identifiers; flow, funding source, product SKU, attributed or refunded Stars; provider and provider-account digest, endpoint, model, location, operation and consumption or quality class; bounded request identifiers, outcome, status, HTTP or provider code, failure class or code, timestamps and latency; numeric usage by direction, modality, quantity, unit, rate tier and source, including video duration or resolution; and price-book snapshot, currency, estimate, reservation, final cost and reconciliation values. They contain no source photo, prompt text, generated image, caption, Telegram initData or file ID, provider result URL, response body, or raw exception text. Management reports expose aggregates rather than those operational identifiers.
- Payments. Purchases are made with Telegram Stars. Telegram processes the transaction — we never see or store your card, bank, or wallet details.
Our legal basis for processing (GDPR)
- Performance of the service at your request (Art. 6(1)(b)) to stylize the photo you choose and deliver previews and paid packs. StickerKit does not use the photo to uniquely identify or authenticate you and does not build a biometric template.
- Purpose limitation. The adult and Terms confirmation records contract acceptance and an age statement; it is not treated as permission for unrelated uses of your photo. StickerKit does not use the photo for advertising, unique identification, authentication, or training its own model.
- Legitimate interest (Art. 6(1)(f)) to prevent abuse, diagnose product errors through the diagnostics described below, and understand product usage through the bounded event log.
- Contract, compliance and record-keeping to apply the current access terms and retain evidence of the versioned confirmation. Depending on the applicable law, the basis may be steps to enter or perform a contract, compliance with a legal obligation, or a legitimate interest in demonstrating compliance and resolving claims.
Where your data is processed
Telegram handles messaging and Stars payments under its own terms. Enabled infrastructure and processors, their processing scope, and their retention or logging settings are identified below. StickerKit does not sell personal data or use it for third-party advertising.
- Application hosting
- Not published in this review build.; region: Not published in this review build.
- Database
- Not published in this review build.; region: Not published in this review build.
- Object storage
- Not published in this review build.; region: Not published in this review build.
- AI generation provider
- Not published in this review build.
- AI processing locations or scope
- Not published in this review build.
- AI provider retention
- Not published in this review build.
- AI request-response logging
- Not published in this review build.
- AI provider training use
- Not published in this review build.
- Edge, CDN, and DNS provider
- Not published in this review build.
- Edge processing scope
- Not published in this review build.
- Diagnostics provider
- Not published in this review build.
- Diagnostics data scope
- Not published in this review build.
- Source-media metadata handling
- Not published in this review build.
- Subprocessor register
- Not published in this review build.
- Register version
- Not published in this review build.
- Register SHA-256
Not published in this review build.- Transfer safeguards
- Not published in this review build.
How long we keep things
The schedule below applies by data category rather than by a particular runtime, filesystem, or database implementation.
- Retention policy version
- Not published in this review build.
- Source uploads and generation inputs
- Not published in this review build.
- Generated previews, stickers, and share assets
- Not published in this review build.
- Account, entitlement, consent, and usage records
- Not published in this review build.
- Orders, payments, refunds, gifts, and subscriptions
- Not published in this review build.
- Provider usage and cost records
- Not published in this review build.
- Diagnostics and security events
- Not published in this review build.
- Disaster-recovery backups
- Not published in this review build.
Your rights
If GDPR applies to you, you can ask us to access, correct, delete, or export your data, or to restrict or object to processing, and you can complain to the data protection authority in your country. StickerKit does not treat source photos as permanent account content; temporary source, upload, and generation assets follow the schedule above, while the original Telegram message remains subject to Telegram’s retention and your chat history. Other records are primarily identifiers, entitlements, commerce records, and counters tied to your Telegram ID. Equivalent rights may apply under the LGPD in Brazil and other applicable laws. Start a request through privacy support in the bot or use the contact details below. Support may need to verify that the account is yours and will explain the next steps; opening the chat does not delete data automatically or immediately.
Age and other people in your photo
StickerKit is for users aged 18 or older. The required confirmation is your own statement and does not verify a birth date or identity. Only upload a photo of another person — or of a minor — if you have their consent, or a parent's or guardian's consent, to turn it into a sticker pack. Don't upload photos of people who haven't agreed to this.
Security
- Production technical and organizational measures
- Not published in this review build.
No system is perfectly secure. If StickerKit learns of a personal-data breach, it will notify affected people and the relevant authority where applicable law requires notification.
Changes to this policy
We'll update the date above whenever we make changes, and flag significant ones in the bot.
Contact
Questions, privacy requests, and notices can be sent by email or through bot support.
Not published in this review build. · Open support in @stickerkit_bot