Kramtage

Privacy policy

This page explains what Kramtage collects, where it is stored, and what you can do about it. It is written to match what the app tells you on its sign-in and setup screens. If anything here reads differently from those screens, treat the screens as the honest description and let us know.

Who runs this service

Kramtage is an independent project operated by Konstantin Savchenko. You can reach the operator at support@kramtage.com for any question about your data, including the requests described at the bottom of this page.

What you sign in with

You sign in with your Telegram account. From that sign-in we store your Telegram account id and username so the app knows who you are and can show you your own map, feed, and settings. We do not receive your Telegram password through the standard sign-in.

Your email, if you add one

An email address is optional. If you add one, it is used only to reach you: to confirm the address, to send security and incident notices, and as the emergency contact for password recovery. You can change it, remove it, or turn off every email the app would send, all from the account panel. We do not use your email for marketing.

The waitlist

If you join the waitlist, we keep the email you enter, the city you name, and your language. We use them for one thing: writing to you when the app is live, plus a rare update. Every email has an unsubscribe link, and unsubscribing removes you from the list.

Your secrets: AI keys and Telegram session

To read chats for you, the app holds two kinds of secret: the AI provider keys you paste in (Cerebras, Groq, Gemini, or Mistral) and your Telegram session, which lets your account read the channels you follow.

Both are stored encrypted at rest. They are decrypted only in memory, only while your session is active, using your app password. Your app password passes through the server at sign-in, so this encryption protects you against a leaked database. It does not protect you against a fully compromised server, and we will not promise more than that. This is at-rest encryption, not end-to-end encryption.

Staff who moderate the service can view the messages placed on the map and the account records needed to run it. They do not have your app password and cannot read your stored keys or session while they are locked.

Messages from the channels you follow

The app reads messages from the public Telegram channels your own account already belongs to, and only from the chats you pick. It never posts on your behalf and never joins anything by itself. For each message it keeps the text, the time, and the place and severity it worked out, so the message can appear as a pin on the map.

Placement is automatic and derived by AI, so it can be wrong or incomplete. There is more on that in the terms of service.

Payments

Premium is paid through LiqPay, Betatransfer, or Telegram Stars. Payment happens on the provider's own page or inside Telegram. We store the order and its status so we can grant your premium period and answer questions about it. We never see or store card numbers.

Ads on the map

The map can show a rotating sponsor card. For that slot we count how many times an ad was shown and how many times it was clicked, as running totals. These counters are aggregate numbers about the ad, not a profile of you.

Cookies and local storage

The app keeps your sign-in tokens in your browser's local storage so you stay signed in, and sets one cookie that records only whether you are signed in, with no secret in it, so the landing page can send you straight to the app. It also stores small display preferences, such as your saved map views and whether media is shown by default.

If you accept cookies in the banner, we also load Google Analytics 4 to see how people use the site. It sets its own cookies, _ga and _ga_*, and keeps that data for 2 years. It collects page views, an approximate location worked out from your IP, and aggregate device and browser details, never your name, email, or anything else that identifies you. It does not load at all if you decline, and you can change your mind anytime with the cookie settings link below.

How long we keep things

Messages are pruned automatically once they pass the retention window, which is 90 days by default. Your account, your emergency email, and your encrypted secrets stay until you remove them or delete the account. Resetting your app password through emergency recovery wipes your stored Telegram session and AI keys.

Security incidents and reducing your risk

The biggest risk is to your stored Telegram session. If our server were ever breached and your session stolen, that session can read the login codes Telegram sends, and a thief could use a code to sign in as a new device and try to take the account over.

Telegram's two-step verification closes that path, because a new sign-in also needs your cloud password. With it on, a stolen session is a nuisance you fix with one tap by ending the session in Settings, then Devices. Without it, the stakes are your whole account.

Because of that, two-step verification is required to connect a Telegram session to the app at all. When you connect through the QR flow, we only keep the session if Telegram itself asks for your cloud password during that handshake. If it doesn't, your account has no two-step verification yet, and we disconnect and drop the session instead of storing it. Turn it on in Telegram under Settings, Privacy and Security, Two-Step Verification, then connect again.

Every sign-in to your account also sends you a message in your chat with our Telegram bot. It names an approximate city worked out from the sign-in's IP address, or says the location is unavailable when that lookup fails or is turned off on our server. The message includes a button that signs every session on your account out at once, and sending it never waits on the city lookup, so a slow or failing lookup can't delay or block your sign-in.

If you press that button because a sign-in wasn't you, we sign out every session immediately, then send you steps for turning on Telegram's two-step verification and clearing any session you don't recognize. Anything you type back to the bot after that, for up to a day, gets forwarded to the person who runs this service, by email and to their own Telegram, so they can help you work out what happened. Either of you can close that conversation early. If you have an emergency email on file, we also set it as the reply-to address on that email, so the operator can write back to you directly.

You can revoke the app's access at any time. We delete the encrypted session, and you can end the session itself in Telegram settings under devices. If we ever have to respond to a security incident, we clear every stored key and email you at your emergency address if you have set one.

Your rights

If you are in the EU or another region with data-protection rights, you can ask for a copy of the data we hold about you and ask us to delete it. Write to support@kramtage.com and we will act on the request.

Changes to this policy

If this policy changes in a way that affects what we collect or how we use it, we will update this page. Continued use after a change means you accept the updated policy.