Legal

Privacy Policy

This policy describes which personal data the CypherGuard bot processes, for what purpose, with whom it is shared and how long it is stored.

1. Controller

The controller responsible for data processing under the GDPR is:

Satyr Labs
Stefan Hiemer
Am Lugenbach 15a, 87653 Eggenthal
E-Mail: satyr@CypherGuardBot.com
Telegram: @SatyrCypher

2. What data is processed & why

The bot only processes data required for its function as a moderation and community bot:

Data categoryPurpose
Telegram user ID, usernameIdentification for moderation, rank system, Pro management
First/last name (in moderation logs)Traceability of admin actions in the log channel
Name-change historyDetection of fake admins and scam attempts
Message content (only with AI feature active — opt-in, available to all Pro groups, off by default)Context for AI replies, group reviews and welcome messages
Contact-form entries (name, e-mail, message)Processing your enquiry; sent directly to the controller, not stored separately
Activity & XP dataRank system, karma, statistics
Group memberships, last activityGroup management, statistics, analytics dashboard (Pro)
Posted contract addresses & stock tickers (e.g. /pnl, /stock, contract auto-reply buttons)Crypto/stock tracking, automatic reply buttons, traceability of who queried what and when
Ban entries (ID + reason)Protection against known scammers (also cross-group)
Payment references (Telegram Stars)Management of Pro subscriptions and purchases
Settings-change log (admin ID + change)Audit log: traceability of who changed which setting
Tag-notification opt-out statusRespecting the user's choice to disable mention DMs

3. Legal basis

Processing is based on different legal grounds depending on the purpose:

  • Moderation, rank system, group administration: Art. 6(1)(b) GDPR (performance of a contract — providing the bot's function) and Art. 6(1)(f) GDPR (legitimate interest in spam/scam protection).
  • AI features: Art. 6(1)(a) GDPR (consent) — the feature is off by default and must be actively opted into from the menu.
  • Pro subscriptions & payment processing: Art. 6(1)(b) GDPR (performance of a contract); purchase receipts additionally rest on Art. 6(1)(c) GDPR in conjunction with the statutory retention duties under § 147 AO / § 257 HGB.
  • Scam-/ban-list entries: Art. 6(1)(f) GDPR (legitimate interest in protecting the community), with the exception from erasure resting on Art. 17(3)(e) GDPR.

4. Sharing with third parties

Personal data is only transmitted to third parties in the following cases:

  • Hosting (ZAP-Hosting GmbH & Co. KG, Münster, Germany): Bot and website run on a server located in Frankfurt am Main, Germany. A data processing agreement (Art. 28 GDPR) is in place with the provider.
  • Telegram (Telegram FZ-LLC): All message transport and payment processing run through Telegram. Telegram's privacy policy applies additionally.
  • Google (Gemini AI): Only in groups where the AI feature has been actively opted into (available to all Pro groups, off by default): message content and a pseudonymised user reference are transmitted to Google for processing. This may involve a transfer to the USA; Google's privacy policy applies additionally. You can opt out at any time via /optout in a direct message to the bot.
  • Payment processing: Payments are made via Telegram Stars. Telegram does not store order data and forwards it to the payment provider; please direct payment enquiries to the controller named above.

Crypto and financial-data services (incl. CoinGecko, DexScreener, Yahoo Finance, Etherscan, GoPlus/honeypot check, NewsAPI) are used for market and stock queries — for example the /stock and /dom commands. No personal data is transmitted to these services — only the queried symbols, tickers or contract addresses.

5. Retention period

  • Message content of the AI feature (only where actively opted into): stored for 24 hours if the group review function is activated, then deleted automatically.
  • Automatically deleted bot/command messages: time-controlled deletion.
  • Profile, activity and membership data: stored for the duration of use; deletion on request (see point 7).
  • Ban entries: retained permanently for security reasons (see point 7).

6. Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability and objection, as well as the right to lodge a complaint with a supervisory authority — in particular the Bavarian data protection authority, since the controller is based in Bavaria:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 27, 91522 Ansbach
www.lda.bayern.de

7. Deleting your data

Send the bot the command /privacy — as group owner directly in the group, as a member in a direct message. This is a self-service deletion path covering every category of personal data described in point 2, without gaps.

For group owners

The owner (creator) of a group can use /privacy in the group to delete all of that group's data from the database in one step: configuration, every member's rank/XP data, AI conversation history, moderation and change logs, filter backups, sent messages/announcements, support requests — everything tied to that group. The bot then automatically leaves the group.

For individual users

In a direct message, /privacy lets you choose between two scopes:

  • Delete data from one specific group only — removes your data from that group, other groups are unaffected.
  • Delete all your data across every group — removes your data everywhere the bot has it.

Either way, this covers: profile data, rank/XP data, group memberships, AI chat history, activity/change history, posted contract entries (crypto tracking), bug/support reports, and your own mentions in moderation logs — both as the moderated person and, where applicable, as moderator/admin.

Data that belongs to a group

Where a data record belongs to a group and you are only noted as its creator (e.g. who set up a filter backup), the record itself is not deleted — only the name/ID link to you is removed. The group keeps its own configuration.

What is expressly not deleted

  • Entries on cross-group scam/ban lists — Art. 17(3)(e) GDPR, overriding legitimate interest in the community's safety.
  • Purchase receipts for Pro subscriptions — statutory retention duty (§ 147 AO / § 257 HGB), Art. 17(3)(b) GDPR.
  • Your own opt-out preference (e.g. "excluded from AI features") — deleting it would undo the very preference you expressed.

8. Changes to this policy

This privacy policy may be amended if functions or legal requirements change. Last updated: 09/2026.