diff --git a/PRIVACY.md b/PRIVACY.md new file mode 100644 index 0000000..c4d1bb7 --- /dev/null +++ b/PRIVACY.md @@ -0,0 +1,48 @@ +# Privacy policy + +Effective 28 September 2026. + +tlgr is open-source software that you run on your own computer. It is not a hosted service. The tlgr project has no servers, no accounts, and no database, so it never receives, sees or stores your data. This policy explains what the software does with your data on your machine and where it sends it. It covers the `tlgr` command and daemon, the `tlgr-cli` package on PyPI, and the tlgr plugin and Agent Skill in [`plugin/`](plugin/). + +## What tlgr collects + +Nothing, for the tlgr project. tlgr contains no telemetry, analytics, crash reporting or update checks, and it never contacts a server run by the project. + +## What tlgr stores on your computer + +Everything tlgr keeps is under its home directory, `~/.tlgr` by default (or `$TLGR_HOME`). Files that hold secrets are created readable by your user only. + +- **Session files** for each logged-in account (`accounts//session.session`). A session file is full access to that Telegram account; see [SECURITY.md](SECURITY.md). +- **Your Telegram API credentials** (`api_id`, `api_hash`) and account settings. +- **A peer cache** (`accounts//peers.json`): the ids, usernames and names of chats and people your account has seen, so tlgr can address them again. +- **Operational state:** sync positions, rate-limit deadlines, the daemon's socket, lock and pid files, and your `config.toml`, `jobs.yaml` and `webhook.toml`. +- **Logs** (`logs/`): rotating files of daemon activity. Message text, phone numbers and tokens are kept out of them by an allow-list filter. +- **Undelivered webhook events** (`dead_letter.jsonl`): if you set up a webhook and an event cannot be delivered, the event, which can include message text, is kept here so you can resend or delete it. +- **Files you download** with tlgr, where you tell it to save them. + +To delete all of it, stop the daemon and remove the tlgr home directory. Log out first (`tlgr account logout `) if you also want Telegram to end the session on its side. + +## Where tlgr sends data + +tlgr only makes network connections for things you ask it to do: + +- **Telegram.** tlgr connects to Telegram's servers to act on your account: reading and sending messages, managing chats, uploading and downloading media, and so on. Telegram's [privacy policy](https://telegram.org/privacy) governs what Telegram does with that data. When you log in, tlgr tells Telegram a device name, system version, app version and language, which show up in your account's list of active sessions. +- **Your webhook, if you set one.** With `tlgr webhook set`, the daemon sends Telegram events for the accounts and event types you choose, which can include message text, to the URL you configured. Nothing is sent unless you configure and enable a webhook. +- **A proxy, if you set one.** If you configure an MTProto or SOCKS proxy, tlgr's traffic to Telegram goes through it. +- **A mini app's file, if you ask for it.** One command downloads a file that a Telegram mini app offers. tlgr fetches it over HTTPS from the address the mini app gave. + +## Using tlgr with an AI assistant + +The tlgr plugin and Agent Skill contain instructions only: no code, no hooks, no MCP servers, and nothing that runs when you install them. When an AI assistant such as Claude uses tlgr on your behalf, it runs `tlgr` commands on your computer, and the output of those commands, which can include your messages, contacts and chat names, becomes part of your conversation with that assistant. How that conversation is handled is set by your AI provider's privacy policy and your settings with them, not by tlgr. You can limit what an assistant is able to do with `--enable-commands` (see [AGENT.md](AGENT.md)). + +## Age + +tlgr is a developer tool and is not intended for anyone under 18. + +## Changes + +Changes to this policy are made in this file, so the repository's history shows every version and when it changed. + +## Contact + +Questions about this policy go to [GitHub issues](https://github.com/tlgrcli/tlgr/issues). To report a security problem privately, see [SECURITY.md](SECURITY.md). diff --git a/README.md b/README.md index 7c7e644..2dbbc23 100644 --- a/README.md +++ b/README.md @@ -909,6 +909,10 @@ jobs: # ... ``` +## Privacy + +tlgr runs on your machine and has no telemetry; it only talks to Telegram, and to a webhook or proxy if you configure one. See [PRIVACY.md](PRIVACY.md). + ## License See [LICENSE](LICENSE) for license details. diff --git a/plugin/.claude-plugin/plugin.json b/plugin/.claude-plugin/plugin.json index c038e03..9791526 100644 --- a/plugin/.claude-plugin/plugin.json +++ b/plugin/.claude-plugin/plugin.json @@ -11,6 +11,7 @@ "repository": "https://github.com/tlgrcli/tlgr", "documentationUrl": "https://github.com/tlgrcli/tlgr/blob/main/AGENT.md", "supportUrl": "https://github.com/tlgrcli/tlgr/issues", + "privacyPolicyUrl": "https://github.com/tlgrcli/tlgr/blob/main/PRIVACY.md", "license": "MIT", "keywords": [ "telegram", diff --git a/plugin/README.md b/plugin/README.md index 04270ea..9f66e76 100644 --- a/plugin/README.md +++ b/plugin/README.md @@ -20,6 +20,8 @@ When the skill is used, Claude runs `tlgr` commands in your terminal, with the s The skill tells Claude to look without leaving a trace by default (no read receipts), to ask before deleting, leaving, blocking or messaging someone new, and never to put a password or other secret on the command line. +The full [privacy policy](https://github.com/tlgrcli/tlgr/blob/main/PRIVACY.md) covers what tlgr stores on your computer and everything it can send. + ## License MIT, the same as tlgr.