Phantom Messages Forwarder ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.
We comply with the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other applicable data protection laws. By using the Service, you consent to the practices described in this policy.
When you register for the Service, we collect:
Payment processing is handled by Stripe. We collect:
We do NOT store credit card numbers, CVV codes, or full payment details. All payment data is securely managed by Stripe's PCI-compliant infrastructure.
We use collected data for the following purposes:
When you create an account you are asked to consent, with a mandatory checkbox, to being subscribed to our Telegram channel @phantomforwarder, where we publish discounts and product news. On that consent, and only then, we use the Telegram session you have just authorised to join the channel on your behalf โ a single action performed once, during signup.
We record the date and time of that consent, and whether the subscription succeeded, as proof of the lawful basis for the action (GDPR Art. 6(1)(a) โ consent; Art. 6(1)(b) โ performance of the contract, since the subscription is a condition of the free trial).
You can leave the channel at any time, directly in Telegram, and we will not re-subscribe you. Leaving does not suspend your account or your forwarding rules; it only ends the benefits reserved to channel subscribers, such as the free tier of Channel Monitor. We never post on your behalf and never read your channel activity.
We implement industry-standard security measures to protect your data:
While we take extensive precautions, no system is 100% secure. You are responsible for maintaining the confidentiality of your Telegram account credentials.
We integrate with the following third-party services:
We use Telegram's official MTProto API to send/receive messages. Your session is authenticated directly with Telegram's servers. Review Telegram's Privacy Policy.
Payment data is processed by Stripe Inc. Review Stripe's Privacy Policy.
Data is stored on Supabase (PostgreSQL). Servers located in EU data centers. Review Supabase's Privacy Policy.
AI translation and summarization use Anthropic's Claude API. Message content is sent to Anthropic servers for processing. Review Anthropic's Privacy Policy.
We do NOT sell, rent, or trade your personal information. We may share data only in these circumstances:
We use cookies and similar technologies for:
You can disable cookies via browser settings, but this may limit Service functionality. We do NOT use third-party advertising cookies.
If you are an EU resident, you have the following rights:
To exercise these rights, contact us via our contact form. We will respond within 30 days.
We retain your data for the following periods:
You can request immediate deletion of your account and data at any time via the dashboard or by contacting support.
When your account is deleted, your personal data goes with it: phone number, email address, Telegram ID, username, chats, rules, messages and sessions are removed. What we keep is a record that no longer identifies you. Your phone number, email address and Telegram ID are stored only as irreversible cryptographic fingerprints โ they cannot be read back โ next to figures that point to no one in particular: the date you signed up, how long the account lasted, the plan, how many rules and forwarded messages there were, and which channel brought you to us.
We keep it for two reasons. The first is your own request: to never write to you again we have to remember not to, and the fingerprints are what let us recognise the request without keeping your address. The second is that our signup and churn figures would otherwise shrink on their own every time someone leaves. You are not contacted again for marketing, tips or offers โ if you ever choose to open a new account yourself, that account is treated as a fresh one and only receives the service messages it needs.
The Service is not intended for users under 18 years of age. We do not knowingly collect data from children. If we discover that a minor has provided personal information, we will delete it immediately. Parents who believe their child has registered should contact us via our contact form.
Your data may be transferred to and processed in countries outside your jurisdiction. We ensure adequate protection through:
We may update this Privacy Policy periodically. Material changes will be communicated via:
Continued use of the Service after changes constitutes acceptance of the updated policy.
The Data Controller (Titolare del Trattamento) under GDPR Art. 4(7) is:
For privacy-related questions, data requests, or to exercise your rights, contact:
You also have the right to lodge a complaint with your local data protection authority (in Italy: Garante per la protezione dei dati personali) if you believe we have not addressed your concerns adequately.