Privacy Policy
Last updated: 26th of August 2026
This Privacy Policy explains what AGP LLC ("AGP," "we," "us") collects, why, and what happens to it, across tg.page and the dashboard at app.tg.page (together, the "Service").
0. Three Different People, Three Different Sections
This is the most important thing to understand before reading further, because almost nothing below applies equally to everyone. The Service involves three distinct people, and we hold very different amounts of data about each.
The Account Holder creates a project and connects a Telegram channel to it. They have an account with us, and Sections 1 through 8 describe what we collect about them. The Site Visitor reads a published site — whether it's hosted at a tg.page address or at the Account Holder's own custom domain — and has no account with us; Section 3 describes the limited, largely non-identifying data we collect about them. The Channel Author and their Telegram subscribers are the source of the published content; they have no account with us and have not agreed to anything with us simply because their public channel was published by someone else. Section 5 covers what happens around verifying a channel, and Section 4 covers what we retrieve from Telegram in the first place.
If you are a Site Visitor or a Channel Author and you have concerns about content published about you, see Sections 5 and 9, and Section 4 of our Terms of Service — together they explain that the Account Holder who published the content, not AGP, is responsible for it. You can reach us about content directly at legal@tg.page.
1. Data We Collect When You Create an Account
When you sign in with Telegram, we receive your Telegram ID, your username (or, if you have not set one, your first and last name), and the address of your profile photo. If you sign in by email instead, your email address becomes your sole identifier for the account. Beyond that, the Service itself generates and stores: your chosen interface language, your account role and status, your plan, when your trial started, a flag recording whether you have ever paid us (which, once set, is never cleared), any add-on slots you've purchased, lifetime counts of how many times you've used AI autofill or triggered a manual refresh (these counters are not reset by deleting a project), and your account creation date.
No password. You sign in with Telegram or a one-time emailed link — we never ask for or store a password.
Telegram accounts and email accounts are not linked. If the same person signs in once with Telegram and once by email, our systems treat these as two separate, unconnected accounts.
Your profile photo itself is not copied to our servers. We store the web address of your Telegram-hosted photo, and your browser loads the image directly from Telegram when you view the dashboard.
2. Cookies, Sessions, and Login Records
We set three cookies, all marked httpOnly (meaning they cannot be read by page scripts). A session cookie is set only on app.tg.page — the dashboard — and lasts 30 days; it holds a random token, and we store only a one-way hash of that token, never the token itself. A language-preference cookie, also set on the dashboard, lasts 365 days and simply records your chosen interface language. A third cookie is set only when you open a shared, unpublished preview link, lasts one hour, and contains a cryptographic signature tied to that project rather than any personal data.
Your session cookie is scoped only to app.tg.page and is never sent to a published site — including your own custom domain. Published pages are assembled from someone else's Telegram content, and we do not want your dashboard session anywhere near that boundary.
What we store about a session: while your session is active, we hold the IP address and browser user-agent you signed in with, in plain, unhashed form, tied to that session. This record is deleted when you log out or after 30 days, whichever comes first — there is no separate long-term archive of it.
Login history: separately, we keep a 90-day record of login attempts against your account — the login method used, whether it succeeded, and the IP address and user-agent used. We record exactly two outcomes: a successful login, or a login refused because the account is suspended. We do not log anonymous failed login attempts. This history is deleted automatically after 90 days, and immediately if you delete your account.
Browser storage: our own code does not write to localStorage, sessionStorage, cookies outside the three above, or IndexedDB. One exception: a third-party theming library we use on the dashboard stores your light/dark mode preference under the key theme in your browser's local storage — this happens only on the dashboard, never on a published site.
Published sites set no cookies and write nothing to your browser's storage, full stop — not even the theming preference above.
We use analytics and advertising tools on our marketing site and dashboard to understand how visitors use the Service, measure the effectiveness of our marketing, and, where enabled, show relevant advertising, including by building audiences based on site activity. Where required by law, we request your consent before these tools are active.
3. What We Collect About Site Visitors
This section covers anyone reading a published site — whether hosted at a tg.page address or at an Account Holder's own custom domain — who does not have an account with us.
We built this deliberately to collect as little as possible. Each page view or interaction is logged as a single row containing: which site and which post it relates to, the type of event, the page path (cut off after 300 characters), the referring page — only if it came from outside the site, and cut off after 120 characters — a two-letter country code, and a timestamp. We do not store, next to this record: any cookie, any visitor or device identifier, any browser fingerprint, the visitor's IP address, or their user-agent string.
A few details worth being precise about. We do briefly look at your IP address, but only to compute a short-lived rate-limiting key that prevents abuse of the analytics endpoint. That key is combined with a random value generated fresh each time our service restarts, expires after 60 seconds, and is never written down next to, or linked with, any analytics event — restarting the service changes the key derived from the same IP, so it cannot be used to track you over time. The country code comes only from a header supplied by our hosting/network provider (for example, cf-ipcountry), not from any IP-lookup database we maintain ourselves. We filter out known automated and bot traffic using pattern-matching on the user-agent string. The tracking beacon does not run inside an iframe, and only reports a referring page on a page's first load. The Account Holder who owns a site can see aggregate statistics derived from this data — view counts over time, top-performing posts, and top referring sites over the last 30 days — but they cannot see individual visitor records, because none exist.
Retention — an open point we're disclosing rather than glossing over: unlike most other data described in this policy, visitor analytics events currently have no automatic deletion schedule. They are retained for as long as the underlying project exists, and are deleted only if the project or account is deleted. We are evaluating whether to introduce a maximum retention window; this policy will be updated if and when we do.
Responsibility for your data as a Site Visitor. If you're reading a published site on the Account Holder's own custom domain, that Account Holder chose the domain, the branding, and the channel content you're seeing. As between AGP and the Account Holder, the Account Holder is responsible for their own site's compliance with the law that applies to their audience, including any disclosures they owe you. AGP acts as the infrastructure and analytics provider behind the scenes. If you have a request about your data as a visitor, you can still contact us directly at support@tg.page and we will address it.
4. Content Retrieved From Telegram
We do not retrieve, preview, or store a channel's content until its administrator has verified control of it and separately authorized the import, as described in Section 5. We do not operate a search tool, directory, or catalog of Telegram channels — we act only on a specific, verified channel, at its administrator's request.
Existing posts reach your site through a one-time historical import, done once at verification: we read them from Telegram's own public web preview of the channel (the same page format publicly reachable at t.me/s/<channel>) — the same page anyone can view in a browser — identifying ourselves to Telegram with a standard browser-style identifier rather than a custom one. New posts published after verification reach your site differently: our bot, added as an administrator of your channel, receives them through Telegram's Bot API as they're published, and we use that feed to keep your site current without re-reading the whole channel. The bot's API access is also used, separately, to verify who controls a channel and to send administrative notifications (see Section 5).
For each post, we store the message ID and date, cleaned HTML of its content, hashtags, links to any media, the full content of any poll (the question, every option, and the current vote percentages), the view count shown on Telegram, what the post was forwarded from and what it's a reply to where applicable, and a copy of the original message markup in Telegram's own raw format. For the channel itself, we store its name, avatar, and description.
We do not copy or re-host media files. A media address on a published page is ours, but requesting it returns a redirect to Telegram's own media servers. A practical consequence: a site visitor's browser connects directly to Telegram to load images or video, and Telegram can see that visitor's IP address as a result. The same is true for the channel's avatar image.
If a post is deleted on Telegram, it is removed from the published site the next time we sync — marked removed internally, and automatically reinstated if the same post reappears on Telegram. We also store a screenshot of each published page, saved as an image in our systems, meaning a visual copy of the channel's content, as published, is retained by us independent of the live page.
5. Verifying Who Controls a Channel
Before we import, generate a preview of, or publish any content from a channel, the Account Holder proves control of it by adding a bot we operate as an administrator of that channel — this applies on the free plan exactly as it does on paid plans. The process works like this: the person clicks a unique start link in Telegram, which tells us their Telegram ID; they then add the bot as a channel administrator, and Telegram separately confirms that to us, matching the same ID. While this is in progress, we temporarily store a hashed version of the verification token, its expiry, when the link was opened, the Telegram ID of the person who opened it, when the process finished, and, if it failed, why — and this record is cleared 14 days after completion.
Verifying control and authorizing import are two separate steps. Once verification succeeds, we separately ask you to confirm that you want that specific channel's content imported, before any of it is retrieved. That confirmation applies only to the channel you just verified, not to any other channel.
The finished project permanently retains when it was verified, the Telegram ID of the person who completed verification, the channel's internal chat ID, and, if applicable, when the bot was later removed.
One consequence worth stating plainly: if you sign in by email, completing this handshake attaches a Telegram identity to your account, because that identity comes from the verification process itself, not from how you log in. Your email-based account and your Telegram ID become linked at that point, even though your login methods otherwise remain unmerged (Section 1).
If our bot is later removed from a channel, we message the Account Holder directly on Telegram to let them know, and further syncing of that channel's content stops immediately. We may require the channel to be verified again before syncing resumes. A given channel can only be verified by one account; if two people attempt to verify the same channel, the first to complete the process controls it.
6. Who We Share Data With
The one-time historical import described in Section 4 means requesting your channel directly from Telegram (t.me) — this exposes the channel name and our own server's IP address to Telegram, but not any data about you or your visitors. Because we don't copy media, a visitor's browser fetches images and video straight from Telegram's media servers, which means the visitor's IP address goes directly to Telegram (see Section 4). If you sign in with Telegram, the login popup itself runs on Telegram's own domain (oauth.telegram.org), inside your browser. Beyond that, our contact with Telegram's Bot API (api.telegram.org) covers confirming the bot's own identity, sending you administrative messages, and — through our registered webhook — receiving new posts published to your channel after verification, so your site can stay current without us re-fetching the whole channel.
We use Resend to send the one-time login link emails, which means your email address and that link pass through their systems.
AI-assisted SEO suggestions require your separate, explicit opt-in for that specific channel. Turning this on for one channel does not turn it on for any other channel you may have, and you can turn it off again at any time. When enabled, we send that channel's name, description, and up to 30 of its posts, each cut to 300 characters, to OpenRouter, which runs the request against Google's gemini-2.5-flash-lite model. We use this only to generate suggestions for your own site — SEO fields, titles, structural suggestions, and similar output — and not to train, fine-tune, benchmark, or otherwise develop any AI or machine-learning model of ours, and not to build any dataset from Telegram content. The model doesn't act on its own: it returns suggested text, you review it before it's applied, and it passes through the same content-cleaning as anything you type by hand. We don't control, and this Policy doesn't describe, what OpenRouter or the underlying model provider do with a request on their own systems beyond fulfilling it — consult their own privacy terms if that matters to you.
Once your project has a live custom domain, the addresses of its published pages are pushed to IndexNow (api.indexnow.org), a shared protocol that forwards new or updated URLs toward participating search engines. We deliberately do not publish which search engines participate, because the list changes over time — please don't assume it means any specific search engine. Once a URL is submitted this way, it cannot be recalled — this is a one-way push, and neither removing the page nor changing robots.txt afterward undoes the submission. Separately, if you choose to enter a Google Search Console ownership-verification code in your SEO settings, that code is sent to Google — this is entirely optional and at your discretion.
If you're on a paid plan, Polar.sh receives your email address and your transaction and subscription data, since Polar acts as our payment processor and merchant of record (see Section 6 of our Terms of Service).
Infrastructure we run on, as processors rather than independent recipients: Railway hosts our application servers, background jobs, and our database and cache — including Postgres and Redis — all based in Frankfurt, Germany. A DigitalOcean server we operate in that same Frankfurt (fra1) region specifically serves custom domains, and Let's Encrypt issues TLS certificates for them. Our marketing site at the root tg.page domain is a separate codebase from the dashboard and product covered by this policy, and may have its own, separate practices.
We do not sell your data, and we do not share it with data brokers or advertisers.
7. Custom Domains — What This Means If You Connect One
If you're an Account Holder connecting your own domain on a paid plan, your domain, its DNS zone, and any email service tied to it remain entirely yours. We ask you to create two DNS records pointing at our infrastructure; we never ask for or take delegation of your domain.
TLS termination for your domain happens on infrastructure we operate, meaning the private key for your domain's certificate is generated and held on our server, not yours. This is standard for a hosting provider, but you should know it rather than assume otherwise. Certificates themselves are issued by Let's Encrypt, a public certificate authority, and as with any certificate from any public authority, your domain name is recorded in public Certificate Transparency logs — a feature of how web certificates work generally, not something specific to us, but one that means your domain becomes publicly discoverable through CT-log tooling once you connect it.
We are still finalizing exactly what our edge server logs about requests to custom domains and for how long; we will update this section once that is settled rather than assert a retention period we have not yet implemented. One domain can be connected to exactly one project, and vice versa.
8. How Long We Keep Things
Most of what we hold about you has a defined lifespan. A session record, including your raw sign-in IP, lasts 30 days or until you log out. Login history — IP address and device — lasts 90 days. A channel-verification attempt is cleared 14 days after it completes. Background job failure logs last 30 days.
Two things are different, and we're calling them out rather than letting them blend into the rest of the list. Magic-link email records stop granting access after 15 minutes, but the record itself — including the email address used — is kept permanently and is not tied to any account, so it is unaffected by account deletion; a record is created as soon as a link is requested, whether or not it is ever opened. Visitor analytics events have no fixed retention limit at all — see Section 3.
Everything else tied to an active project — posts, page screenshots, SEO settings — is kept for as long as the project exists. An unused free-plan project stays active for 7 days, is then frozen (visible but paused), and is deleted 30 days after that.
9. Deleting Your Account
You can delete your account yourself from the dashboard, or we may delete it as described in our Terms of Service. Doing so removes all of your sessions and login history, every project and its posts, SEO settings, sync state, all analytics collected on your sites, page screenshots, verification attempts, connected-domain records, and related routing data.
Some records survive account deletion, on purpose, and we want to be direct about exactly what and why, rather than imply deletion erases every trace of you. An account-closure log retains your username or email address, who closed the account, how many projects and sites you had, when your account was created, your plan, and the closure date. An administrative-action log retains labels identifying who performed an admin action and who it affected, which may include a name, email, or domain name depending on the action. A plan-change history retains your account identifier and label, what plan you moved from and to, who changed it, and any note attached. Background job failure logs may still reference a site you owned, for up to 30 days after the failure, independent of account deletion. And, as described in Section 8, magic-link email records are structurally separate from your account — keyed by email address, not by account ID — so account deletion does not reach them at all.
We keep these because closed-account and administrative records need to remain attributable — including, in the closure log, to the specific person who requested a closure — for our own accountability and dispute-resolution purposes. We do not keep them to continue using your data for any other purpose.
We do not currently offer a self-service "download everything you have about me" tool. If you would like a copy of the data we hold about you, contact support@tg.page and we will provide it manually.
10. Security
Session tokens, magic-link login tokens, and channel-verification tokens are all generated the same way and stored as one-way hashes, never in plain text — the raw token itself never sits in our database, only a hash of it. Beyond that, we do not currently apply field-level encryption to database contents, and we do not currently offer two-factor authentication — sign-in security rests on the security of your Telegram account or your email inbox. We do not currently maintain automated backups of our production database. We are describing our security posture as it stands, not as we might wish it to be, and we will update this section as it changes.
A practical note about login links: the emailed link that signs you in contains the raw access token as part of its address. It is single-use and expires after 15 minutes, but until it does, or until it is used, anyone who has that link can sign in as you — including someone who intercepts the email, finds it in your sent or forwarded mail, or reads it from a mail server's own logs. Treat a tg.page login email the way you would treat a temporary password: don't forward it.
11. Administrative Access
A small number of authorized administrators can, where necessary to operate or moderate the Service, see projects and posts belonging to any account — including posts that have been hidden from public view — connected domains, login history including IP addresses and devices used, and plan and usage information. This access is granted only through direct database configuration, not through any in-product control, and an administrator cannot remove their own access or delete their own account. Administrative actions — including removing a domain — are generally not announced to the affected Account Holder individually, though they will usually be visible as a change in what the account can do.
12. Your Rights
Depending on where you live, you may have rights over the personal data we hold about you — for example, to access it, correct it, delete it, restrict or object to its processing, or receive a copy of it in a portable format. We aim to honor these rights for every user regardless of location, as a matter of policy, not only where a specific law requires it.
How to exercise them: write to support@tg.page. Where a request can be handled through the dashboard — for example, deleting your account, Section 9 — we'll point you there; otherwise we will process it manually within a reasonable time. We do not currently have an automated self-service tool for access or export requests — see Section 9.
Our basis for processing your data is, depending on the data: performing our contract with you (account, hosting, and publishing functionality); our legitimate interest in operating, securing, and improving the Service (for example, login-attempt records and rate-limiting); your consent, where a feature is opt-in (for example, entering a Google Search Console verification code, or opting in to AI-assisted SEO suggestions for a specific channel); and legal compliance, where applicable.
Age. The Service is intended for users 18 years of age or older, matching the eligibility requirement in our Terms of Service. We rely on the representation you make when creating an account and do not independently verify age.
13. International Data Transfers
Because our infrastructure, our team, and the third parties listed in Section 6 are not all located in one country, using the Service typically involves your data being processed outside the country you're in — including, for many users, transfer to or processing within the United States and Germany. Where applicable law requires a specific safeguard for such transfers, we intend to rely on the mechanism appropriate to that transfer, such as the relevant third party's own standard contractual clauses; this section will be made more specific once our data-transfer arrangements with each processor are finalized.
14. Changes to This Policy
We may update this Privacy Policy from time to time. If a change is material, we will provide notice before it takes effect, in the same way described in our Terms of Service. The "Last updated" date at the top of this page always reflects the current version.
15. Language
This Privacy Policy is written and published in English, and the English version is the authoritative one. Where we make a translation available, it is provided for convenience; if it differs from the English version, the English version is the one that describes what we actually do.
16. Contact
Questions about this policy, or to exercise a privacy right described in Section 12: support@tg.page.
AGP LLC
1712 Pioneer Ave Ste 500
Cheyenne, WY 82001
USA