Privacy policy
This page explains what Kramtage collects, where it is stored, and what you can do about it. It is written to match what the app tells you on its sign-in and setup screens. If anything here reads differently from those screens, treat the screens as the honest description and let us know.
Who runs this service
Kramtage is an independent project operated by Konstantin Savchenko. You can reach the operator at support@kramtage.com for any question about your data, including the requests described at the bottom of this page.
What you sign in with
You sign in with your Telegram account. From that sign-in we store your Telegram account id, username, and the display name on your Telegram profile, so the app knows who you are and can show you your own map, feed, and settings. We also record the time you accepted these terms. We do not receive your Telegram password through the standard sign-in.
Your email, if you add one
An email address is optional. If you add one, it is used only to reach you: to confirm the address, to send security and incident notices, and as the emergency contact for password recovery. You can change it, remove it, or turn off every email the app would send, all from the account panel. We do not use your email for marketing.
The waitlist
If you join the waitlist, we keep the email you enter, the Telegram channel you name (or the city, for signups made before we changed the question), and your language. We use them for one thing: writing to you when the app is live, plus a rare update. Every email has an unsubscribe link, and unsubscribing removes you from the list.
Your secrets: AI keys and Telegram session
To read chats for you, the app holds two kinds of secret: the AI provider credentials you paste in (Groq, Gemini, Mistral, or Cloudflare Workers AI) and your Telegram session, which lets your account read the channels you follow. If you connect Telegram with a login code, the phone number you type is sent to Telegram to request that code, and we do not store it.
The text of the channel messages you follow goes to whichever of those providers your key belongs to, so it can work out the place and the severity. Cloudflare states that it does not use your content to train any AI models.
Both are stored encrypted at rest. They are decrypted only in memory, only while your session is active, using your app password. Your app password passes through the server at sign-in, so this encryption protects you against a leaked database. It does not protect you against a fully compromised server, and we will not promise more than that. This is at-rest encryption, not end-to-end encryption.
Staff who moderate the service can view the messages placed on the map and the account records needed to run it. They do not have your app password and cannot read your stored keys or session while they are locked.
Messages from the channels you follow
The app reads messages from the public Telegram channels your own account already belongs to, and only from the chats you pick. It never posts on your behalf and never joins anything by itself. For each message it keeps the text, the time, and the place and severity it worked out, so the message can appear as a pin on the map.
Placement is automatic and derived by AI, so it can be wrong or incomplete. There is more on that in the terms of service.
While you are online, your connected account also reads those picked chats for other subscribers who follow the same channels, and their accounts read for you in the same way. That shared reading is what keeps the map live. It is passive: nothing is written back to Telegram from your account, so it never posts, joins, or messages anyone. It stops when you go offline, and it stops for good when you revoke access.
Payments
Premium is paid through LiqPay or Betatransfer. Payment happens on the provider's own page. We store the order and its status so we can grant your premium period and answer questions about it. We never see or store card numbers.
Ads on the map
The map can show a rotating sponsor card. For that slot we count how many times an ad was shown and how many times it was clicked, as running totals. These counters are aggregate numbers about the ad, not a profile of you.
Cookies and local storage
The app keeps your sign-in tokens in your browser's local storage so you stay signed in, and sets one cookie that records only whether you are signed in, with no secret in it, so the landing page can send you straight to the app. It also stores small display preferences, such as your saved map views and whether media is shown by default.
If you accept cookies in the banner, we also load Google Analytics 4 to see how people use the site. It sets its own cookies, _ga and _ga_*, and keeps that data for 2 years. It collects page views, an approximate location worked out from your IP, and aggregate device and browser details, never your name, email, or anything else that identifies you. It does not load at all if you decline, and you can change your mind anytime with the cookie settings link below.
How long we keep things
Messages are pruned automatically once they pass the retention window, which is 90 days by default. Your account, your emergency email, and your encrypted secrets stay until you remove them or delete the account. Resetting your app password through emergency recovery wipes your stored Telegram session and AI keys.
Security incidents and reducing your risk
The biggest risk is to your stored Telegram session. If our server were ever breached and your session stolen, that session can read the login codes Telegram sends, and a thief could use a code to sign in as a new device and try to take the account over.
Telegram's two-step verification closes that path, because a new sign-in also needs your cloud password. With it on, a stolen session is a nuisance you fix with one tap by ending the session in Settings, then Devices. Without it, the stakes are your whole account.
We strongly recommend two-step verification, though connecting does not depend on it. Whether you connect by QR code or by login code, the session is kept either way. When Telegram asks for your cloud password during the handshake, we ask you for it too; when it doesn't, we store the session and the account panel keeps recommending two-step verification until you turn it on. You turn it on in Telegram under Settings, Privacy and Security, Two-Step Verification.
Every sign-in to your account sends a notice, but only by email and only if you have a verified emergency address on file; without one, no notice goes out. It names an approximate city, worked out by sending the sign-in's IP address to ip-api.com, or reads as location unavailable when that lookup fails or is turned off on our server, and it gives the time in UTC. The email carries no button or link that acts.
If a sign-in was not you, the remedy is "Sign out everywhere" in the account panel: it ends every session on your account at once. After that, turn on Telegram's two-step verification and end any device you do not recognize under Telegram's own Settings, Devices.
You can revoke the app's access at any time. We delete the encrypted session, and you can end the session itself in Telegram settings under devices. If we ever have to respond to a security incident, we clear every stored key and email you at your emergency address if you have set one.
Your rights
If you are in the EU or another region with data-protection rights, you can ask for a copy of the data we hold about you and ask us to delete it. Write to support@kramtage.com and we will act on the request.
Changes to this policy
If this policy changes in a way that affects what we collect or how we use it, we will update this page. Continued use after a change means you accept the updated policy.