Personal Data Processing Policy
Version of 7 October 2026
This is a translation. The Russian version of this document is binding and prevails in case of any discrepancy.
1. General provisions
1.1. This policy describes how the administration of the AstraGPT service (the “Operator”, “we”) processes the personal data of users of the AstraGPT website at its main address https://astragpt.net and its additional address https://astragpt.org (the “Website”).
1.2. The policy has been drawn up in accordance with Federal Law No. 152-FZ of 27 July 2006 “On Personal Data” (the “Law”) and is published under Part 2 of Article 18.1 of the Law. It applies to the Website only.
1.3. Terms are used in the meanings given to them in the Law and the Terms of Service. Processing means the collection, recording, systematisation, accumulation, storage, clarification, retrieval, use, transfer, depersonalisation, blocking, deletion and destruction of data. We process data using automated means.
2. What data we process
2.1. Telegram login data: your numeric Telegram ID, first and last name (if provided), username (if set) and a link to your profile photo. On the server, we store the ID, username, photo link and the language you have chosen. Your first and last name remain only in the login data in your browser.
2.2. What you send: messages and requests to models, prompts for generations, attached and uploaded files (images, video, audio, documents), voice recordings for dictation, voice samples for cloning, games you create and publication descriptions.
2.3. Results: model responses, generated images, video, voice-overs, music and games, and chat history.
2.4. Payment information: order number, what was bought, amount, payment method, status and time, and the Platega transaction number or Telegram payment number. We do not receive card, bank account or crypto wallet details.
2.5. Usage information: time of requests, the model selected, the volume and cost of processing, limit counters, credit movements, completed tasks, who invited you and whom you invited, likes in the games feed, and ratings of model responses (“like” or “dislike” together with the model, the time and the beginning of the response, up to 500 characters). The history of credit charges stores a short description of each generation, including the request text. For each request to a model we also store the part of the service (website, Mini App, connected app), the processing time, the error code and a technical request identifier. The request text is not included in these records. If a model in the chat uses tools (web search, reading pages, running code), we record each call: the time, the tool, the result, the duration and the cost, plus the search query (up to 200 characters), the domain of a page that was read or the beginning of the code (up to 500 characters). Code runs in an isolated sandbox whose security log stores the beginning of the code of each run (up to 500 characters) and its checksum. Files created by the code are available via links that cannot be guessed.
2.6. Technical data: IP address, browser information (User-Agent), and the time and address of the request, recorded in server logs. Error log: time, account identifier (if you are signed in), part of the service, page or method address without parameters, error code and description without the content of your requests, application version and browser type; IP addresses are not written to the error log. Depersonalised visit statistics: page, language, referring domain, utm tags and device type, without cookies, IP addresses or identifiers.
2.7. Correspondence with support.
2.8. We do not ask for passport details, your address or your phone number. We do not process special categories of personal data (Article 10 of the Law) or biometric personal data (Article 11 of the Law): a voice sample is used only for voice-over and does not serve to identify a person.
2.9. Unless necessary, do not include information about your health, beliefs or other sensitive data in your requests, and do not include the personal data of other people without their consent: the model will process such data as ordinary text.
3. Purposes and legal grounds
3.1. To provide the services under the Terms of Service: login, sending requests to models, displaying and storing results, chat history and the media library, keeping track of the plan, credits and limits, the games feed, tasks and invitations. Legal ground: performance of a contract to which you are a party (Clause 5 of Part 1 of Article 6 of the Law).
3.2. To accept payments, grant purchases, make refunds, keep records of income and issue receipts. Legal grounds: performance of the contract and obligations imposed on us by law, including tax law (Clauses 2 and 5 of Part 1 of Article 6 of the Law).
3.3. To respond to support requests, claims and requests concerning personal data. Legal grounds: the same.
3.4. To send you messages in Telegram: payment confirmations, reminders that your plan is about to expire and messages about the operation of the Website. Legal ground: performance of the contract.
3.5. To protect the Website from abuse and attacks, investigate failures, calculate load and costs, and use response ratings to identify models that perform worse. Legal ground: our legitimate interests, provided that your rights and freedoms are not violated (Clause 7 of Part 1 of Article 6 of the Law). For these purposes we keep a history of model requests (without request texts), an error log and depersonalised statistics.
3.6. We do not sell personal data or transfer it for advertising purposes.
3.7. We do not make decisions that produce legal consequences for you solely on the basis of automated processing (Article 16 of the Law). An automatic check may reject an individual request or publication description; you can challenge this through support.
4. Transfer of data, including cross-border transfer
4.1. Models. To obtain a response, we transfer the content of the request (text, attached files, a voice recording or a voice sample) to the OpenRouter service (OpenRouter, Inc., USA), which passes it on to the developer of the model you selected. Developers are located in the USA, China and other countries. Your Telegram ID, username and photo are not transferred together with the request.
4.2. This is a cross-border transfer of personal data, including to countries that do not ensure adequate protection of the rights of personal data subjects. We carry it out under Article 12 of the Law in order to perform the contract with you: without it, the model cannot process your request. By logging in to the Website, you confirm that you are aware of this transfer and consent to it.
4.3. OpenRouter and model developers process data under their own rules and may store it on their side. We do not control their servers or retention periods. Therefore, do not send passwords, bank card details or trade secrets in your requests.
4.4. Platega is a payment service for payments via SBP (the Russian Faster Payments System) and in cryptocurrency. We transfer to it the order number, the amount and a description of the purchase. You enter your payment details on its page.
4.5. Telegram confirms login, delivers our messages and accepts payments in Stars. Telegram processes data under its own privacy policy.
4.6. The Website and the database run on a rented server.
4.7. Third-party resources in the browser. The login widget is loaded from telegram.org. In the process, your browser discloses its IP address and browser information to Telegram. The Website serves its fonts and the libraries for formatting responses itself.
4.8. To analyse how the service works, we may process statistics exports with external data analysis tools. The exports contain no names, usernames or Telegram identifiers: an account is represented by a random pseudonym, and request texts are not included.
4.9. We transfer data to government authorities only in cases provided for by law. Data is not transferred to any other persons.
5. What other users see
5.1. A published game is visible to other users together with your username and profile photo and the number of likes and plays.
5.2. The user who invited you sees your username and photo in their list of invited users. You see who invited you.
5.3. Your chats, files, results and balance are not visible to other users.
6. Retention periods and deletion
6.1. Retention periods:
- account (ID, username, photo, language), plan and balance — for as long as the account exists;
- chat history — until you delete the chat or the account;
- files attached to chat messages — 48 hours;
- media library files and generation results — until you delete them or delete the account;
- temporary copies of reference files that are not in the media library — up to 30 days;
- voice recordings for dictation — not kept after recognition;
- response ratings, credit history and other usage information (limit counters, tasks, invitations) — for as long as the account exists;
- the history of model requests (metadata, without request texts) and the error log — 90 days;
- records of chat tool calls (search query, domain of a page that was read, beginning of the code) — 30 days;
- the sandbox security log with the code of runs — 14 days;
- files created by code in the sandbox — 30 days;
- statistics files in which an account is represented by a random pseudonym — 365 days;
- daily totals without identifiers — indefinitely;
- payment information — for the period established by tax law;
- server logs with IP addresses — 14 days;
- database backups — made daily in encrypted form and kept for 14 days.
6.2. You can delete an individual chat, media library file or result yourself in the Website interface.
6.3. To delete your account, write to support in Telegram (section 13). We will delete the account, chats, media library, results, games and publications no later than 30 days from the date of the request. After that, payment records and credit history are kept in pseudonymised form (without your Telegram ID in plain form and without request texts), and usage information is depersonalised. Deleted data disappears from backups within 14 days. After the account is deleted, the pseudonym in the statistics files is no longer linked to anyone (in encrypted database backups the link remains until they are deleted, no longer than 14 days).
6.4. When the purpose of processing has been achieved or you have withdrawn your consent, we stop processing and destroy the data within 30 days, unless the law requires it to be kept longer (Article 21 of the Law).
7. How we protect data
7.1. The connection to the Website is encrypted (HTTPS). Database backups are stored in encrypted form.
7.2. Login is confirmed by Telegram’s signature. Login data for the Website is valid for 30 days.
7.3. The database cannot be accessed directly from the internet. Only a limited number of people have access to the administration of the Website.
7.4. In the event of a personal data breach, we will notify Roskomnadzor (the Russian data protection authority) within the time limits set by Part 3.1 of Article 21 of the Law and inform the affected users.
8. Cookies and browser storage
8.1. The Website does not use third-party cookies, web analytics services or advertising counters. A service cookie is set only for the Operator’s staff when they sign in to the administrator panel.
8.2. The Website stores the following in your browser (localStorage and sessionStorage):
- login data — a signed string containing your ID, name, username and photo link;
- the language you have chosen and interface settings;
- a copy of your chats so that they open faster — the main history is stored on the server;
- request drafts — until the tab is closed;
- the order number while a payment is pending;
- the “Don’t show again” flag of the expensive model warning;
- your choice in the cookie notice;
- for the Operator’s staff: a service key for the administrator panel session (tab storage, erased when the tab is closed).
8.3. This data stays on your device and is not transferred to third parties. The “Sign out” button deletes the login data. You can delete the copy of your chats and the settings by clearing the Website’s data in your browser settings.
8.4. The login widget runs on the telegram.org domain and may use its own cookies under Telegram’s rules.
8.5. Cookie notice. Necessary data (sign-in, security, payments, usage limits and the error log) is processed without separate consent: without it the Website cannot perform the contract or protect itself from abuse. The “Accept” and “Decline” buttons control only optional analytics and marketing, which the Website does not currently use. You can change your choice with the “Cookie settings” link at the bottom of the page.
9. Your rights
9.1. Under Articles 14–17 of the Law, you have the right to:
- obtain information about how we process your data;
- access your data;
- demand that your data be clarified, blocked or destroyed if it is incomplete, outdated, inaccurate, unlawfully obtained or not necessary for the stated purpose;
- withdraw your consent to processing;
- object to a decision made solely on the basis of automated processing;
- appeal against our actions to Roskomnadzor or in court.
9.2. How to send a request: write to support in Telegram at @AstraAgentsSUP_bot. State your Telegram username or ID and the substance of the request. To avoid disclosing data to an unauthorised person, we may ask you to confirm that the Telegram account belongs to you.
9.3. We respond within 10 working days of receiving the request. This period may be extended by no more than 5 working days if we inform you of the reason (Articles 14 and 20 of the Law).
9.4. The services cannot be provided without processing data. Therefore, withdrawal of consent or a demand to delete all data means deletion of the account.
10. Age
10.1. The Website may be used from the age of 14. Users aged 14 to 18 may use it only with the consent of a parent or other legal representative. Only adults may pay for the services.
10.2. If you learn that a child under 14 is using the Website, write to us and we will delete the child’s account.
11. Changes to the policy
11.1. A new version of the policy is published on this page with its date and takes effect on the day of publication.
12. Connected apps (MCP and plugins)
12.1. This section applies if you have connected your account to an AI app made by another developer — Claude, ChatGPT, Claude Code, Codex, Cursor, Visual Studio Code or another program that supports the MCP protocol (the “Connected App”), as described in section 12 of the Terms of Service.
12.2. What we additionally process:
- information the app provided when connecting: its name, the address to return to after sign-in and the address of its description;
- the connection record: when it was created, which permissions were granted, when the app last contacted the Website and how many credits were spent through it;
- the content of calls: generation prompts, parameters, file identifiers, and files the app passed to us at your request;
- the IP address and information about the program that sent the request (usually the app developer’s servers or a program on your computer).
12.3. We do not receive your conversation in the Connected App beyond what the app itself passes in a call, and we do not receive your account data held by the app developer (email address, name, chat history).
12.4. Access keys. After you allow access, the Connected App receives access keys from us. We store only their hashes (SHA-256), so a key cannot be restored from our data. Keys are valid for a limited time and stop working immediately after the app is disconnected. The confirmation page does not set cookies: it uses the same sign-in data in your browser as the rest of the Website (section 8).
12.5. What the app receives. In our responses we pass the Connected App the generation results (links to files and their reduced copies), prices, your credit balance and its history, and, with the library permission, information about your files: generation prompts, models, dates and links. This data is received by the app developer (for example, Anthropic PBC or OpenAI — USA) and processed under its privacy policy. We pass it only on your instruction: you connected the app and send it requests. This is a cross-border transfer of personal data, including to countries that do not ensure adequate protection of the rights of personal data subjects. We carry it out under Article 12 of the Law in order to perform the contract with you; by pressing “Allow”, you confirm that you are aware of it and consent to it.
12.6. Purposes: to connect the app, carry out its requests on your behalf, charge credits, show you the list of connections and protect the account against abuse.
12.7. Retention: the connection record — as long as the account exists, so that the credit history shows which app a generation came from; key hashes — until they expire or the app is disconnected, plus no more than 30 days; call content — as part of the generation history and media library under section 6; server logs — 14 days.
12.8. You can disconnect an app on the “MCP · Plugins” page of the Website, in the “Connected apps” section. Deleting the account (section 6) also deletes all connections.
13. Contacts
- Operator
- Administration of the AstraGPT service
- Support in Telegram
- @AstraAgentsSUP_bot
- Website
- https://astragpt.net