Document

Privacy Policy

Last updated: June 30, 2026

This is a short, plain-language policy. If anything is unclear — write to support@actionvaults.app, I'll answer personally.

1. Who we are

Action Vaults is a product of Raven Systems (one of the company's projects) that connects to your working Telegram groups and helps you find files, discussions, and decisions using AI.

Contact for all questions about personal data: support@actionvaults.app.

2. What data we collect

2.1 Telegram account data

When you sign in through the Telegram Login Widget, we receive your public data from Telegram:

  • · Telegram User ID
  • · First name, last name, username (if set)
  • · A link to your avatar (if set)

This data is used only to identify you in our dashboard. We do not request your phone number, email, passwords, or other sensitive data.

2.2 Data from groups

When you add @Action_Vaults_bot to a Telegram group, the bot gets access to that group's content: messages, files, voice notes, video, images, links, and metadata (sender, time).

We store this so we can later answer your questions about the group's content. The bot does not see private messages and has no access to groups it was not added to.

2.3 Derived data

From the source files and messages we generate: transcriptions of voice and video (Whisper), text extracted from PDF/DOCX/XLSX/PPTX/images, brief AI summaries, and vector embeddings for semantic search. All of it is tied to a specific group and does not cross between groups.

2.4 Technical logs

Standard server logs: IP address, user-agent, request times. Kept for 30 days, needed for diagnostics and protection against attacks.

2.5 Data from Slack

If you connect Slack (an integration on the Business plan), the bot gets access only to the channels it was invited to and that you selected to keep memory of: the messages, files, and metadata (author, time) of those channels, as well as the public names of participants (to attribute messages). Private messages and channels the bot was not added to are not read. The data is stored and processed the same way as Telegram-group data and does not cross between workspaces. The Slack access token is stored encrypted.

3. Why we need this data

  • Search and answers: so the bot can find relevant fragments of the conversation and answer questions.
  • Transcription: so you can search the content of voice notes and video.
  • Reports: to generate digests, project overviews, and risks.
  • Billing: tracking plan limits (number of AI requests, files, groups).

We do not sell data. We do not use it to train third-party AI models. We do not show ads.

4. Who we share data with

To power the AI features we use third-party services (sub-processors). Data is passed only in the amount needed for a specific operation and is not retained by providers to train models:

  • OpenRouter (Google Gemini) — AI answers, meaning extraction, request classification.
  • Cohere — vector embeddings for semantic search (multilingual).
  • Groq — transcription of voice and video via the Whisper-large-v3 model.
  • Hosting and storage (EU) — servers, files, databases.
  • Vercel (EU) — hosting of the web interface.
  • Cloudflare — DNS and DDoS protection.
  • Telegram — the messenger through which the bot works and authorization is carried out.

Hosting and storage are with infrastructure providers in the EU. The full up-to-date list of sub-processors is available on request at support@actionvaults.app.

When (if) we add payments, Stripe will be added to process payments. Card data does not reach us — only Stripe processes it.

5. Where data is stored

Files and the database are hosted with infrastructure providers in the EU. Integration secrets (for example, the Slack access token) are stored encrypted, and backups may be encrypted on export. We do not claim end-to-end encryption of all content “at rest” — we strengthen data boundaries iteratively and honestly describe what is already done. Backups are created daily and stored in the same region.

The web interface is hosted on Vercel (Edge, EU region). Vercel stores only static assets (HTML/CSS/JS); your data does not go there.

6. How long we keep it

  • Group messages, files, transcriptions — until you delete the group or leave your account.
  • Technical logs — 30 days.
  • Backups — 7 days.
  • A deleted account or group — we erase all related data within 24 hours from the production database and within 7 days from backups.

7. Your rights

At any time you can:

  • · View your data — through the web dashboard (groups, files, transcriptions, extracted objects).
  • · Request an export — write to us by email and we will prepare an export of your data. There is no one-click self-service export yet — the export is done manually on request.
  • · Delete a group — through the dashboard → “Delete group.” All of the group's data is erased within 24 hours.
  • · Delete your account and all data — write to us at support@actionvaults.app and we will delete the account and related data. There is no separate “Delete account” button in the dashboard yet — deletion is by request.
  • · Disconnect Slack — in the dashboard → “Connections” → “Disconnect.” Ingest from the channels stops; to erase already-collected data, write to us.
  • · Withdraw consent — simply remove the bot from the group. After that it collects nothing more for that group.

8. Cookies and analytics

We use only functional cookies: a session cookie for the web dashboard (needed to keep you logged in). There are no advertising or tracking cookies.

At this stage we do not use analytics like Google Analytics or Mixpanel. If we ever add any — it will be stated here, and the analytics will be anonymous and self-hosted (Plausible or similar).

9. Children

The Service is not intended for children under 16. We deliberately do not collect data about children. If you are a parent and believe your child has provided us with data — write to support@actionvaults.app and we will delete it.

10. Changes to the policy

If we materially change this policy — we will send a notice via the bot and update the “Last updated” date at the top of the page. Minor edits (typos, wording clarifications) — we simply update the date.

11. Contact

For any questions about personal data, to request an export or deletion — support@actionvaults.app. We respond within 24 hours.

Privacy Policy — Action Vaults