Privacy Policy
Last updated: 31 August 2026
1. What this document is, and where to write
This document explains what data the Sarafun project collects and stores: the «Sarafun» Telegram Mini App, the Telegram bots connected to it, the sarafun.app website and short links of the form sarafun.app/s/. The community is based in Valencia, Spain. The data is processed within the European Economic Area, so we describe the processing in the terms of the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and honour the rights listed below.
We do not publish the name of the project's owner, the name of a legal entity or a postal address. The only channel for data enquiries is hello@sarafun.app. Write there to exercise any right from section 15, to complain about someone else's publication about you, or to report an error in this text. We reply no later than one month after receiving your enquiry. The project has no separate data protection officer; enquiries are read by the project's owner.
So that we do not hand your data to a stranger, we will ask you to confirm that you are who you say you are: to write from the same Telegram account, or in another way available to you.
2. Age
The service is intended for people over 18. By registering, you confirm that you are 18 or older.
There is no automated age check in the app, and we say so plainly. Telegram does not pass us a date of birth, and we do not ask for one anywhere ourselves. This means we put no technical barrier in front of a minor — there is only this condition. If you learn that an account is being used by someone under 18, write to hello@sarafun.app and we will delete the account.
3. Where this document applies
This document covers the data that passes through the «Sarafun» Mini App, which is opened through any of our bots. It also covers the data that passes through the Telegram bots themselves: both your private correspondence with a bot and the publications that a bot sends to the community groups. It covers the data of the sarafun.app website as well, including the public preview pages behind short links. Separately, it covers information about the members of the community's Telegram groups that are connected to the app: among them are people who have never opened the app (section 8).
The landing site contains no forms, and no analytics or advertising scripts. One cookie is nevertheless set on it: sarafun_lang, with a lifetime of one year and the attribute samesite=lax — it remembers the language you chose for the page. Alongside it, the same setting is written to the browser's local storage under the key sarafun-lang-pref. Both are strictly functional and serve the language switcher only.
Processing inside Telegram itself — the messenger, accounts, chats, the Telegram Stars payment system — is carried out by Telegram under its own rules. We have no influence over it, and this document does not govern it.
4. What data we collect
Telegram identifier. At every sign-in, Telegram passes us the numeric identifier of your account, your @username, first name, last name, a link to your profile photo and your interface language. The numeric identifier is a permanent label by which we recognise you at each sign-in; it is also what ties your account to everything else. Further on we refer to it as your «Telegram identifier».
Profile photo. We not only display the photo from the Telegram link, but also download it as a file to our own server, so as not to depend on the availability of their CDN.
Profile details. What you enter yourself: your bio, profession, company, «where you're from», skills, «who I'm looking for», links to social networks and a website, interests and your current city. You also edit your first and last name yourself — they are captured at registration and are no longer overwritten from Telegram.
Account settings and internal markers. Notification toggles, quiet hours, time zone, colour theme, the last bot you used, a marker that you have blocked the bot, the time of your last activity, the date on which you accepted this policy, your role, and the reason for a ban if one has been applied.
Activity log. We record significant actions: opening a page, starting a session, viewing an event, signing up for an event, creating content. Alongside the action we store a free-text note — for example, the title of an event or the list of profile fields that were changed. The client session identifier goes there too, as does an attribution marker for where you came from: which chat or which link. When a session starts, we additionally record the device type, the Telegram version and the selected theme.
A word specifically about the snapshot of another person's name. When you tap «message» on another member, or open their external link, the log receives not only that person's identifier but also their name at that moment. This is a deliberate decision, not a side effect: without the name the activity feed is unreadable. What happens to these snapshots when a person deletes their account is described in section 11.
Search queries and filters. We store these separately from the activity log. We record: the normalised text of the query, up to 60 characters; the range into which the number of results found falls; the filters applied, as short codes; the screen on which the search was made; the client session identifier; and your city at the time of the query. Personal views — «Mine», «Going», your own listings — are excluded from this collection.
Feedback. The text you send through the feedback form, and the category you chose.
Sessions. We store the identifier of the token issued, the bot through which you signed in, the device type and the language. Alongside them: a truncated IP address, from which no individual device can be identified. Then come the times of sign-in, last activity, expiry and revocation, together with the reason for revocation if the session was revoked. The full IP address and the full User-Agent are not stored in the application database — the single exception is described in section 14.
Notification logs. For every notification sent: the recipient, the type, the delivery status, the Telegram error code and error text, the message identifier and the sending bot. We do not store the text of the notification.
Bot reachability. For every «user — bot» pair: whether you have started the bot with the /start command, whether it is blocked, when that happened, and when you were last seen.
Event participation. Here we store:
- sign-ups for events and the participation status;
- join requests, with the free-text message to the organiser and the reason for the decision;
- the co-organiser role;
- check-in records: who was checked in, when, by whom, and whether by QR code or manually;
- subscriptions to discussions and to sign-ups.
User content. The events you create, together with their images. Comments, ratings from one to five, written reviews, reactions. Requests in the «Looking for» section and replies to other people's requests. Listings in the item-sharing section — photo, description, the district where the item is handed over. Loan requests with a free-text message. Recommendations. Referral posts. Content reports with a free-text reason. Communities (topic hubs) that you create — name, description, cover, avatar, city and a link to the associated Telegram group — as well as your community subscriptions and moderator rights in them.
Random Coffee. The capacity in which you take part (Man, Woman, Family couple) and who you would like to meet — that is, information about sex and marital status. A snapshot of these values in every round in which you registered. The pairs formed and their status. Your feedback on meetings, including a free-text comment about a specific person — it is never shown to your partner. If a partner has no @username, you can ask the bot to pass on your contact details: we store the time of such a request and which member of the pair sent it. Your «Already know each other» list: the people you have marked so that you are not paired with them. Only you can see it — the person marked is never told and receives no notification. It works both ways and only within your own city.
Community chats and bot messages in them. For every connected chat we store its title, @username and photo. For every publication and broadcast sent by a bot we store the full text of the message, the message identifier in Telegram and internal data — the event title, the button captions, and the name of the administrator or moderator whose action triggered the sending.
Payments. When you donate through Telegram Stars, we store the amount, the Telegram payment identifier and the bot that received the payment. Payment credentials are not passed to us and are not processed by us.
Administrative logs. Administrators' actions on accounts and content, with structured notes, including the reason for a ban and a snapshot of the event sign-ups that were removed. A history of content edits, with fragments of the changed text. A security alert log — its entries may contain a first name, last name, @username and Telegram identifier, and, in certain cases, also information about the browser together with a truncated IP address.
Information about the members of connected Telegram groups. Described separately in section 8.
5. Why we process this, and on what lawful basis
For each purpose below we state the lawful basis under Article 6 GDPR.
Running your account, displaying your profile, event participation, publishing your content, the operation of the «Looking for», sharing, recommendations, communities and referrals sections, and transactional notifications for your subscriptions — performance of a contract with you (Article 6(1)(b)). By accepting this policy at registration you enter into a relationship with us for the provision of the service. Without the data listed, the service does not work.
Matching members for introductions by interests, skills, profession and city — performance of a contract (Article 6(1)(b)): this is a stated function of the service.
Taking part in Random Coffee, and the processing of information about sex and marital status — your consent (Article 6(1)(a)). You fill in the Random Coffee profile voluntarily and delete it yourself, without deleting your account. Two limitations: while a round is running in which you have already been paired, the app will not let you delete the profile — that becomes possible once the round has finished; and a snapshot of the values you gave remains in rounds that have already passed and in currently active ones.
Optional digest notifications — new events, new requests, new sharing listings, new referrals — your consent (Article 6(1)(a)). They are off by default, you switch them on manually, and you withdraw consent with the same toggle.
Protecting the service against abuse — legitimate interest (Article 6(1)(f)). This covers rate limiting, the detection of scraping and brute-force attempts, the alert log, sessions with a truncated IP address, and web-server logs. The interest lies in the availability of the service and the safety of members' data.
Content moderation, handling reports, the administrative audit trail and the edit history — legitimate interest (Article 6(1)(f)) in maintaining a safe environment and in being able to examine a disputed situation on the evidence.
Product analytics — the activity log, search queries and filters, notification delivery statistics — legitimate interest (Article 6(1)(f)). We want to understand which features are used and what content the community is missing. To be honest about it: in the statistics this data is counted in aggregate, but the admin area also has a per-person activity feed, with filters by action and by date. You have the right to object to this processing (section 15).
The snapshot of another person's name in the log when you move to a conversation or follow an external link — legitimate interest (Article 6(1)(f)) in handling complaints about unwanted approaches and in judging whether the service leads to real contact.
Storing the texts of publications and broadcasts in chats — legitimate interest (Article 6(1)(f)): the bot uses them to edit a message it has already sent, to retry a failed send, and to deal with complaints about the content of a publication.
Information about the members of connected Telegram groups — legitimate interest (Article 6(1)(f)); details in section 8.
Accepting donations — performance of a contract (Article 6(1)(b)); keeping the payment record — compliance with a legal obligation to account for incoming payments (Article 6(1)(c)).
Special categories of data under Article 9 GDPR — health, religious belief, political opinions, biometrics and the like — we do not deliberately collect. That said, we do not control what you write in free-text fields. A profile bio, a comment, a request, a recommendation or a feedback message is stored exactly as you sent it.
6. Who can see your data
Your profile is visible to every community member signed in to the app. That is the point of the service: the app exists so that members can find one another. Do not put anything in your profile that you are not prepared to disclose.
In three cases data leaves the app, and it is worth knowing this in advance.
The first is short links. The app issues links to profiles, listings, requests and recommendations. The page behind such a link serves a name, a photo and a short description to anyone who has the link — no sign-in required. The link is signed and cannot be guessed by brute force. But anyone can forward it.
The second is image files. Uploaded pictures, including profile photos, are served from direct addresses without authorisation.
The third is publications in groups. When an event is published, the bot sends a message to the community's Telegram groups containing the organiser's name and a link to their profile. These messages are seen by all members of the groups concerned, and they are stored in Telegram.
The following are not shown to other members: the technical data from section 4 — the activity log, sessions, search queries, notification logs; notification settings; the text of your feedback; Random Coffee meeting feedback; and the reports you have submitted. Meeting feedback is never seen by the person it is written about.
App administrators can see accounts, content, the activity log for a particular person, the administrative audit trail and the statistics. They need this access for moderation and for handling enquiries.
7. Who we share data with
We do not sell data and we do not share it for advertising or for profiling in someone else's interests. Data is nevertheless shared, and here are the cases.
Telegram Messenger. Telegram is our infrastructure provider. Sign-in to the app goes through it, all notifications in private messages are sent through it, events are published to groups through it, your session token is stored in it and Telegram Stars payments are processed by it. Everything that goes to Telegram — a name, the text of a publication, the content of a notification — is thereafter processed by Telegram under its own privacy policy.
The project owner. Text sent through the feedback form is also copied by the bot as a private message to the main administrator, and it remains in his Telegram correspondence. Deleting your account does not affect that copy in Telegram.
Hosting. The application and the database run on a rented server within the European Economic Area. We rent the machine from a hosting provider and make no claims about any certifications it may hold.
Backups. We keep automatic copies of the database for 30 days; one copy is held separately from the main server. From this follows a consequence for the right to erasure: for up to thirty days after your account is deleted, your data still sits in those copies. Two things are worth calling out separately, because they do not fall under the thirty-day period. The first is the occasional manual database snapshot that we take before major changes; those are kept for longer. The second is a separate copy of the uploaded files: it grows but does not replay deletions, so an image erased on our side may remain in it.
The list of cities is taken from the open GeoNames dataset (section 17). None of your data goes to GeoNames.
We do not ourselves transfer data outside the European Economic Area. Such a transfer is possible inside Telegram's infrastructure, which is outside our control.
8. Data about people who do not use the app
The app processes data about people who have never used it themselves and have never accepted this policy. They have rights over that data, so we set out plainly what is stored about them and how it can be deleted.
Members of connected Telegram groups. For every community group connected to the app we store a list of members: Telegram identifier, first name, last name, @username, a marker for a Telegram Premium subscription, interface language and status in the group. The data is collected through Telegram's interfaces — by a service account that is a member of the group, and from events about changes in membership. A substantial part of these records is not linked to any active account. These are both people who have never used the app and people whose account has been deleted or banned. The lawful basis is legitimate interest (Article 6(1)(f)) in understanding the community's reach, in knowing to whom an announcement has already been delivered, and in moderation.
An administrator can export a chat's member list as a file — Telegram identifier, first name, last name and @username. The export is used for moderation and for tracking reach; every such operation is recorded in the administrative log.
We should state a limitation up front, so as not to promise the impossible. The service account rescans the membership of active chats regularly. If we delete a record at your request while you remain a member of the group, it will reappear at the next scan. It can only be deleted for good once you have left the group; until then we can delete it only temporarily.
Subjects of recommendations. A member may publish a recommendation about a person outside the app or about a company, creating a card with a name, photo, city, category and contact details: website, Telegram, WhatsApp, Instagram, telephone, email, address, map link. This information is entered by the author of the recommendation, not by the subject. The lawful basis is legitimate interest (Article 6(1)(f)) in exchanging trusted contacts within the community. If a recommendation concerns you and you do not want it, write to hello@sarafun.app — we will hide or delete the card.
Names in other people's log entries. As stated in section 4, when someone moves to a conversation or follows an external link, the log receives the name of the person they approached. If that person deletes their account, we erase their name from other people's entries too — exactly how is described in section 11.
Texts about third parties. Comments, requests, meeting feedback, content snapshots in reports and notes on administrative actions may contain information about other people. We do not edit them in advance; we act on an enquiry or a report.
9. How long we keep each category
Your account, profile details and settings are kept until you delete the account. Your content is more complicated: some of it survives account deletion under the byline «Deleted user», some is hidden, some is erased — the exact breakdown is in section 11. Inactive accounts are not deleted automatically: if you do not delete your account yourself, this data will be kept indefinitely.
Fields that survive account deletion. The Telegram identifier — re-registration and protection against ban evasion rest on it. Along with it, the following remain untouched: city, time zone, quiet hours, colour theme, role, registration date, last-activity time and the last bot used. Everything else in the account is anonymised (section 11).
Activity log. 365 days from each entry. Two kinds of entry are excluded from the cleanup and kept indefinitely. The first is messages sent through the feedback form: this is your own text, not telemetry, and within the app it is stored only here; the copy that went to the main administrator in Telegram is covered in sections 7 and 11. The second is internal markers recording that a profile-completion reminder has already been sent.
Search queries and filters. 365 days from the entry.
Sessions. Deleted once more than 90 days have passed since the token expired. They are also deleted immediately — both when an account is deleted and when it is banned.
Notification logs. Event reminders and records of problem deliveries (error, bot blocked, sending deferred) — 400 days. The rest — 90 days. Account deletion does not affect these records.
Bot reachability markers. Kept for as long as the account exists, and deleted together with it. A ban does not affect them.
Event join requests. Decided requests — approved, declined, withdrawn, expired, and those cancelled because the event was cancelled — are deleted 90 days after the event starts. A request on which the organiser never made a decision is marked expired automatically four hours after the event ends, and is deleted under the same rule.
Event sign-ups, co-organiser roles, subscriptions and check-in records. Not deleted automatically.
Communities and subscriptions to them. There is no automatic cleanup. Subscriptions and moderator rights are deleted together with the account; a community awaiting moderation is rejected, while one already published remains.
Random Coffee feedback and pairs. Kept indefinitely, including the free-text feedback — regardless of whether the author or their partner has deleted their account.
Content reports and the administrative audit trail. Indefinitely.
Content edit history and the security alert log. 400 days. The record of who made an edit is retained even after that person's account has been deleted.
Community chats and the texts of publications and broadcasts sent to them. Indefinitely; there is no automatic cleanup. Records of failed publications are deleted once more than 7 days have passed since the event was created.
Information about the members of connected Telegram groups. Indefinitely; there is no automatic cleanup.
Donation records. Indefinitely, and they are not deleted even on request: the obligation to keep records of payments received limits the right to erasure in this respect.
Logs of internal background tasks. 30 days.
Uploaded images. Kept for as long as the associated record exists. Files not linked to any record are deleted after 24 hours.
Web-server logs. 15 days. Application logs — roughly a month, and the error log longer.
Database backups. 30 days for automatic copies; manual snapshots taken before major changes, and the separate copy of the uploaded files, live longer (section 7).
10. What we do with the data received from Telegram
At sign-in Telegram passes us a first name, last name, @username, a link to a photo and an interface language. What happens to these fields afterwards differs, and this matters for the right to rectification.
First name and last name are captured at registration. We do not overwrite them at subsequent sign-ins — you may have changed them in the app to suit yourself, and overwriting your edit with data from Telegram would be wrong. You can change your first and last name directly in your app profile.
The @username, profile photo and interface language are refreshed from Telegram at every sign-in. They cannot be changed in the app — change them in Telegram, and the new value will be picked up at your next sign-in.
11. Deleting your account
You can delete your account yourself in your profile settings. Below is a precise description of the consequences.
Anonymised. Your first name is replaced with «Deleted user». The following are erased:
- last name and @username;
- both photo links, the photo file itself on the server, and the internal markers of its synchronisation;
- interface language;
- bio, profession, company, «where you're from», skills, «who I'm looking for»;
- links to social networks;
- the record of your acceptance of this policy.
The account is marked inactive and every token issued becomes invalid. The marker that you have completed the app introduction is cleared, and optional digest notifications are switched off. The recommendation-subject card about you is renamed to «Deleted user» — this is where deletion differs from a ban, where the name is preserved.
What happens to the activity log. In your own entries the free-text note is erased — paths with parameters, snapshots of other people's names, the texts of messages sent through the feedback form. The rows themselves remain: they point to an account that has already been anonymised and are needed for aggregates such as «how many people viewed events on this day». They are deleted under the general rule — 365 days from each entry.
In other people's entries that hold a snapshot of your name, we erase precisely the name. Where someone tapped «message you», the note is cleared entirely. Where someone opened your social link, only the platform name remains: «LinkedIn». The app then substitutes «Deleted user», and the feed stays readable without naming you.
One exception we will name outright. Immediately after deletion, an entry about the deletion itself is added to the log, and it preserves a snapshot of the event sign-ups that were erased. That entry lives for a year.
Search queries. The query text and the filters applied are cleared in all of your rows. The rows themselves — signal type, screen, the range of the number of results, city and client session identifier — remain until the general 365-day limit.
Feedback. The text of your message is erased together with the rest of the log notes; the row recording the fact of the message remains indefinitely. Important: the copy of the text that the bot sent to the main administrator in Telegram remains in his correspondence — we cannot delete it from Telegram.
Deleted entirely:
- sessions;
- bot reachability records;
- all event sign-ups — with the first person on the waiting list automatically promoted;
- join requests, together with their free-text message;
- co-organiser roles;
- your interests;
- all subscriptions: to discussions, to sign-ups, to requests, to organisers in both directions, to communities, as well as community moderator rights;
- your Random Coffee profile and registrations in rounds that have not yet started;
- your «Already know each other» list — both your own marks and other people's marks about you;
- all referral posts;
- the file of your profile photo.
Hidden, but retained in the database. Your requests in the «Looking for» section and your replies to other people's requests are marked as deleted — the text is kept so as not to destroy other people's replies under your requests. Draft and rejected events are marked as deleted and disappear from the app; their text stays in the database, while the images uploaded to them are deleted from disk. Sharing listings are deactivated, but their description, photo and handover district remain; active loans are closed and pending requests are declined. Recommendations awaiting moderation are hidden. Communities awaiting moderation are rejected.
Left unchanged. Your Telegram identifier and the internal fields from section 9. Comments, ratings and written reviews on events — under the byline «Deleted user». Published and cancelled events, together with their images. Published recommendations and your «I recommend them too» marks. Published communities that you created. Reports you have submitted. Event check-in records. Random Coffee meeting feedback, including its free text. Registrations in rounds that have already started or finished, together with the snapshot of the sex and household composition you gave. Notification logs. Donation records. The administrative audit trail. The content edit history. The security alert log — it may contain your name, @username and Telegram identifier.
In the records about Telegram group members, only the link to your account is cleared. The first name, last name, @username and Telegram identifier in those records remain.
On your device the app erases form drafts, the markers of dismissed hints, saved filters and internal flags, clears the tab's temporary storage and deletes the token from Telegram's cloud storage.
In the database backups the deleted data still exists and disappears as they rotate — within thirty days. The two caveats from section 7 apply here as well: occasional manual database snapshots are kept for longer, and the separate copy of the uploaded files does not replay deletions, so an image erased on our side may remain in it.
Re-registration is possible. It creates a new profile, requires you to go through the app introduction again and to accept the policy; your role is reset to that of an ordinary member.
The main administrator's account cannot be deleted through the interface — this is a safeguard against losing control of the service.
12. Banning an account
A ban is applied by an administrator when the community rules are broken. In terms of what happens to data, it works fundamentally differently from deletion.
A ban anonymises nothing. The account is marked inactive, the tokens issued become invalid, and the reason for the ban is stored. First name, last name, @username, photo and the whole profile remain in the database as they are, the photo file is not deleted, and the name remains visible in administrative search and on the recommendation-subject card. This is a deliberate decision: lifting a ban should restore the profile as it was.
Some data, however, is deleted irreversibly at the same time, and lifting the ban will not bring it back. The following are deleted:
- sessions;
- all event sign-ups — with the first person on the waiting list promoted;
- join requests, together with their free text;
- co-organiser roles;
- all subscriptions: to discussions, sign-ups, requests, organisers and communities, including moderator rights;
- the Random Coffee profile and registrations in rounds that have not yet started.
Rejected with no way back: events awaiting moderation; communities awaiting moderation; referral posts awaiting moderation.
Hidden but retained: your requests and replies are marked as deleted; published referral posts are hidden; recommendations awaiting moderation are hidden; sharing listings are deactivated, active loans are closed and pending requests are declined. Active Random Coffee pairs are marked as not met, and the partners receive a cancellation notification. The link to chat-member records is cleared.
Comments and ratings are not affected and remain signed with your real name.
The activity log and search queries are not anonymised on a ban — unlike on deletion. They are deleted under the general one-year rule, with the same two exceptions named in section 9: feedback text and the internal reminder markers remain, and a ban does not anonymise them.
An entry is added to the administrative audit trail with the reason for the ban and a snapshot of your event sign-ups and join requests. It is kept indefinitely.
Form drafts on your device survive a ban — the app does not clear them.
If you consider a ban unjustified, or if you would like your data to be deleted after it rather than retained, write to hello@sarafun.app.
13. Data on your device and in Telegram's storage
The app uses no advertising or tracking cookies and does not track you across sites. The single cookie on the landing site is covered in section 3.
Session token. After sign-in the token is saved in Telegram's cloud storage and tied to the «you — this particular bot» pair. This is so that you do not have to sign in again the next time you open the app. The token survives closing the app; it is erased when the account is deleted, and becomes invalid on a ban and on a change of role.
The device's local storage. The app keeps form drafts there, containing the text you have entered:
- an event;
- a sharing listing;
- a request;
- a recommendation;
- a referral post;
- the app introduction;
- feedback.
Alongside the drafts sit the markers of dismissed hints, the city and community filters you have selected, and a few internal flags. This data is stored on your device and does not go to the server: it reaches us only when you submit the form yourself. When an account is deleted, the app clears everything listed, including the referral-post draft and the filter keys.
Client session identifier. A random identifier is generated each time the app is launched. It accompanies activity-log and search-query entries within a single visit and makes it possible to see the sequence of actions inside it. It is not shared between visits: a new one is generated at the next launch.
14. Technical logs outside the database
Web-server logs. For the app domain app.sarafun.app and for the pages of the landing site, the web server records the full IP address, the full User-Agent, the request path and method, and the response code. We use these records to protect against scanning and automated attacks. The retention period is 15 days. The lawful basis is legitimate interest (Article 6(1)(f)).
Application logs. These are kept in structured form and contain the user identifier and the type of action. The IP address, User-Agent, authorisation headers and secrets do not reach these files.
The User-Agent exception. Where there are clear signs of an automated attack, the full User-Agent and a truncated IP address are written to the alert log in the database. Such entries are rare and are kept for 400 days.
15. Your rights
You hold the rights set out in Articles 15–22 GDPR. To exercise any of them, write to hello@sarafun.app. So that we do not hand your data to a stranger, we will ask you to confirm that it is you — for example, by replying from the same Telegram account you use for the app.
Right of access (Art. 15). You have the right to obtain confirmation that we process your data and a copy of it. There is no automated export in the app — we prepare the extract by hand, so a reply may take up to a month.
Right to rectification (Art. 16). You change your profile details, first name, last name and settings yourself at any time. Change your @username, photo and interface language in Telegram — they will be refreshed on our side at your next sign-in (section 10).
Right to erasure (Art. 17). Delete your account in the settings, or write to us. Section 11 describes what is erased and what remains. The right is limited — here is exactly where.
- We are obliged to keep the record of a donation.
- The administrative audit trail, the edit history and the alert log remain as an evidence base under legitimate interest, and are deleted under their own retention rules.
- The Telegram identifier is retained to protect against ban evasion.
- Data lives for up to thirty more days in the automatic backups; manual database snapshots and the separate copy of the uploaded files live longer (section 7).
- Records about the members of connected Telegram groups keep your name and @username for as long as you remain in the group (section 8).
- Random Coffee meeting feedback, including its free text, remains indefinitely.
- Notification logs and check-in records are not subject to erasure.
- Published content remains under the byline «Deleted user».
The full breakdown is in section 11. On a separate request we will consider erasing particular records beyond the standard procedure.
Right to restriction of processing (Art. 18). There is no separate suspension mode in the app — we say so plainly rather than describe a mechanism that does not exist. The closest thing to it is a ban, but a ban deletes part of the data, so it is not a suspension. If you request restriction of processing, we will stop using your data manually and tell you exactly what we have done.
Right to object (Art. 21). You may object at any time to processing carried out on the basis of legitimate interest. That is primarily product analytics — the activity log and search queries — the snapshot of your name in other people's entries, and the storage of information about the members of connected groups. Against digest notifications you may object unconditionally: switch off the relevant toggles in your settings. Transactional notifications without which the service does not work — for example, about your sign-up for an event — will continue to arrive.
Right to data portability (Art. 20). You have the right to receive the data you have provided in a machine-readable format. There is no automated export mechanism; we prepare it by hand on request.
Withdrawal of consent (Art. 7(3)). The consents from section 5 are withdrawn in the settings: you delete your Random Coffee profile in the Random Coffee section, and switch off optional digest notifications with the toggles. One limitation for the Random Coffee profile: while a round is running in which you have been paired, the app will not let you delete it — wait for the round to finish, or write to us. Withdrawal does not affect the lawfulness of processing carried out before it.
Right to lodge a complaint (Art. 77). You have the right to complain to a data protection supervisory authority — in your country of residence, of work, or of the alleged infringement. In Spain this is the Agencia Española de Protección de Datos (aepd.es).
There is no automated decision-making with legal effects (Art. 22) in the app. The matching algorithm produces a list of suggestions and affects only the order of the cards.
16. Security
We take technical and organisational measures proportionate to the risks. The connection to the application is protected by TLS. The data that Telegram passes at sign-in is verified by a cryptographic signature with a time limit. Access rights are checked on every request, so a change of permissions takes effect immediately. Only administrators have service access to the data, and their actions are recorded in the audit trail. We do not disclose how the protective mechanisms are built: publishing that would make an attack easier.
Secrets and tokens do not reach the logs. The full IP address and browser details are stripped from the application logs.
No measure offers an absolute guarantee. If an incident occurs that creates a risk to your rights, we will notify the supervisory authority, and, where the risk is high, you as well, within the time limits laid down in Articles 33 and 34 GDPR.
17. Data sources
The list of cities and their attributes is taken from the open GeoNames dataset (geonames.org), which is distributed under the Creative Commons Attribution 4.0 licence.
18. Changes to this policy
We update this policy as the service evolves. The date of the latest revision is given at the top of the document.
The revision published in the app is the one in force. The same revision is published on the sarafun.app website in Russian and in English translation; in the event of a discrepancy, the Russian revision in the app prevails.
We announce substantive changes — new categories of data, new purposes of processing, longer retention periods — in the Telegram community and in the app. If you continue to use the service after the changes take effect, the updated revision applies to the processing that rests on the contract and on legitimate interest. Processing that requires consent we will resume only once we have obtained it.
19. Status of this document
The wording on lawful bases, retention periods and limitations of rights describes how the service actually works.
If you notice a discrepancy between what is written here and how the service actually behaves, write to hello@sarafun.app. We will correct either the text or the behaviour of the service.
See also: Terms of Use.