Privacy Policy
This policy describes which personal data the CypherGuard bot processes, for what purpose, with whom it is shared and how long it is stored.
1. Controller
The controller responsible for data processing under the GDPR is:
Satyr Labs
Stefan Hiemer
Am Lugenbach 15a, 87653 Eggenthal
E-Mail: satyr@CypherGuardBot.com
Telegram: @SatyrCypher
2. What data is processed & why
The bot only processes data required for its function as a moderation and community bot:
| Data category | Purpose |
|---|---|
| Telegram user ID, username | Identification for moderation, rank system, Pro management |
| First/last name (in moderation logs) | Traceability of admin actions in the log channel |
| Name-change history | Detection of fake admins and scam attempts |
| Message content (only with AI feature active — opt-in, available to all Pro groups, off by default) | Context for AI replies, group reviews and welcome messages |
| Contact-form entries (name, e-mail, message) | Processing your enquiry; sent directly to the controller, not stored separately |
| Activity & XP data | Rank system, karma, statistics |
| Group memberships, last activity | Group management, statistics, analytics dashboard (Pro) |
| Posted contract addresses & stock tickers (e.g. /pnl, /stock, contract auto-reply buttons) | Crypto/stock tracking, automatic reply buttons, traceability of who queried what and when |
| Ban entries (ID + reason) | Protection against known scammers (also cross-group) |
| Payment references (Telegram Stars) | Management of Pro subscriptions and purchases |
| Settings-change log (admin ID + change) | Audit log: traceability of who changed which setting |
| Tag-notification opt-out status | Respecting the user's choice to disable mention DMs |
3. Legal basis
Processing is based on different legal grounds depending on the purpose:
- Moderation, rank system, group administration: Art. 6(1)(b) GDPR (performance of a contract — providing the bot's function) and Art. 6(1)(f) GDPR (legitimate interest in spam/scam protection).
- AI features: Art. 6(1)(a) GDPR (consent) — the feature is off by default and must be actively opted into from the menu.
- Pro subscriptions & payment processing: Art. 6(1)(b) GDPR (performance of a contract); purchase receipts additionally rest on Art. 6(1)(c) GDPR in conjunction with the statutory retention duties under § 147 AO / § 257 HGB.
- Scam-/ban-list entries: Art. 6(1)(f) GDPR (legitimate interest in protecting the community), with the exception from erasure resting on Art. 17(3)(e) GDPR.
4. Sharing with third parties
Personal data is only transmitted to third parties in the following cases:
- Hosting (ZAP-Hosting GmbH & Co. KG, Münster, Germany): Bot and website run on a server located in Frankfurt am Main, Germany. A data processing agreement (Art. 28 GDPR) is in place with the provider.
- Telegram (Telegram FZ-LLC): All message transport and payment processing run through Telegram. Telegram's privacy policy applies additionally.
- Google (Gemini AI): Only in groups where the AI feature has been actively opted into (available to all Pro groups, off by default): message content and a pseudonymised user reference are transmitted to Google for processing. This may involve a transfer to the USA; Google's privacy policy applies additionally. You can opt out at any time via
/optoutin a direct message to the bot. - Payment processing: Payments are made via Telegram Stars. Telegram does not store order data and forwards it to the payment provider; please direct payment enquiries to the controller named above.
Crypto and financial-data services (incl. CoinGecko, DexScreener, Yahoo Finance, Etherscan, GoPlus/honeypot check, NewsAPI) are used for market and stock queries — for example the /stock and /dom commands. No personal data is transmitted to these services — only the queried symbols, tickers or contract addresses.
5. Retention period
- Message content of the AI feature (only where actively opted into): stored for 24 hours if the group review function is activated, then deleted automatically.
- Automatically deleted bot/command messages: time-controlled deletion.
- Profile, activity and membership data: stored for the duration of use; deletion on request (see point 7).
- Ban entries: retained permanently for security reasons (see point 7).
6. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and objection, as well as the right to lodge a complaint with a supervisory authority — in particular the Bavarian data protection authority, since the controller is based in Bavaria:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 27, 91522 Ansbach
www.lda.bayern.de
7. Deleting your data
Send the bot the command /privacy — as group owner directly in the group, as a member in a direct message. This is a self-service deletion path covering every category of personal data described in point 2, without gaps.
For group owners
The owner (creator) of a group can use /privacy in the group to delete all of that group's data from the database in one step: configuration, every member's rank/XP data, AI conversation history, moderation and change logs, filter backups, sent messages/announcements, support requests — everything tied to that group. The bot then automatically leaves the group.
For individual users
In a direct message, /privacy lets you choose between two scopes:
- Delete data from one specific group only — removes your data from that group, other groups are unaffected.
- Delete all your data across every group — removes your data everywhere the bot has it.
Either way, this covers: profile data, rank/XP data, group memberships, AI chat history, activity/change history, posted contract entries (crypto tracking), bug/support reports, and your own mentions in moderation logs — both as the moderated person and, where applicable, as moderator/admin.
Data that belongs to a group
Where a data record belongs to a group and you are only noted as its creator (e.g. who set up a filter backup), the record itself is not deleted — only the name/ID link to you is removed. The group keeps its own configuration.
What is expressly not deleted
- Entries on cross-group scam/ban lists — Art. 17(3)(e) GDPR, overriding legitimate interest in the community's safety.
- Purchase receipts for Pro subscriptions — statutory retention duty (§ 147 AO / § 257 HGB), Art. 17(3)(b) GDPR.
- Your own opt-out preference (e.g. "excluded from AI features") — deleting it would undo the very preference you expressed.
8. Changes to this policy
This privacy policy may be amended if functions or legal requirements change. Last updated: 09/2026.