Legal

Privacy policy

This policy explains what Gatekeepah collects, why, and what we deliberately never touch.

Last updated August 26, 2026.

Who we are

Gatekeepah is a member qualification service for Telegram communities, operated by Hypefury, Inc. You can reach us at hello@gatekeepah.com.

Because Gatekeepah is built by the Hypefury team, account, support, and product emails may be sent from a Hypefury address or domain. They are from us.

Two different roles

We handle two kinds of people, and our responsibilities differ for each.

  • Community owners — the customers who sign up, connect a bot, and run a community. For their account data we are the data controller.
  • Applicants— people who apply to join a customer's Telegram group. For their answers we are a data processor acting on the community owner's instructions. That owner decides what to ask, who to accept, and how long to keep records. Applicants with a question about their data should contact the community they applied to first.

What we collect from community owners

  • Your email address, used to sign in with a magic link.
  • Your community name and workspace settings.
  • Your Telegram bot token, encrypted before it is stored.
  • The Telegram groups your bot is in: group ID, title, and whether your bot is an admin.
  • The application flow you build, including your questions.
  • Billing status and plan. Payments are handled by Paddle as merchant of record — we never see or store your card details.
  • Support conversations, if you message us through the in-app chat.

What we process about applicants

When someone applies through a customer's bot, we store what is needed to run the review:

  • Their Telegram user ID, username, and first name as Telegram provides them.
  • Their answers to the questions that community chose to ask.
  • The status of the application, and which moderator decided it.
  • Whether an invite was issued and when it expires.

Applicants choose what to write. Community owners decide the questions, so they are responsible for having a lawful basis for asking them and for telling applicants how their answers will be used.

Photos never leave Telegram

This is the part we care most about. If a community asks applicants for a photo, we store only Telegram's internal file reference for it — a short identifier that lets your moderators view the photo inside Telegram.

  • We never download the image file.
  • We never store image bytes on our servers or in any file storage.
  • We never run facial recognition, identity matching, or any other biometric analysis.
  • The photo stays where the applicant sent it: in Telegram.

This is a hard rule in how the product is built, not a setting that can be switched on.

Invite links

When a moderator accepts an applicant, the bot asks Telegram for a single-use invite link that expires after 24 hours and sends it directly to the applicant. We store only the expiry time and when it was last sent — never the invite URL itself.

What we do not do

  • We do not sell personal data, and we never have.
  • We do not share data between customers. Every community sees only its own applicants.
  • We do not run advertising or analytics trackers on this website.
  • We do not use applicant answers to train machine learning models.

Cookies

We use essential cookies only: they keep you signed in to the dashboard. Our support chat (Crisp) sets its own cookies so a conversation stays continuous. There are no advertising or analytics cookies to opt out of.

Who else processes this data

We use a small number of service providers to run Gatekeepah:

ProviderPurposeLocation
SupabaseApplication database, authentication, and bot runtimeEurope (Zurich, Switzerland)
VercelWebsite and dashboard hostingUnited States / global edge network
PaddlePayments, invoicing, and tax as merchant of recordUnited Kingdom / European Union
CrispIn-app support chatEuropean Union (France)
MailgunSign-in and service emailsEuropean Union
TelegramThe messaging platform your bot, groups, and applicants useOperated by Telegram FZ-LLC

Your application database is hosted in Europe. Some providers operate globally, in which case transfers rely on standard contractual clauses or an equivalent safeguard.

How long we keep things

  • Account data is kept while your account is open.
  • Applicant records are kept until the community owner deletes them or closes the account, since owners often need the history of who they accepted and why.
  • When an account is closed we delete its data within 60 days, except records we must keep for tax or accounting purposes.
  • Ask us to delete something sooner and we will.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict how it is used. Email hello@gatekeepah.com and we will respond within 30 days.

If you applied to a community and want your answers removed, contact that community owner. They control those records. If they ask us to delete them, we do.

If you are in the EU or UK and think we have handled your data badly, you can complain to your local data protection authority.

Security

Bot tokens are encrypted before storage. Access to production data is limited to people who need it to operate the service. No system is perfectly secure, but if a breach affects your data we will tell you and the relevant authority as required by law.

Children

Gatekeepah is not intended for anyone under 16. Do not use the service or apply through it if you are younger than that.

Changes

If we change this policy in a way that matters, we will email account holders before it takes effect. See also our terms of service.