This policy describes what data NO DJ needed anymore (“the bot”, a Telegram bot, operated from nodjbot.iteratio.ru) collects, why, how it is protected and how you can delete it.
1. Data we collect
From Telegram
- Your numeric Telegram user ID — to tell users apart and keep your settings.
- The text of your requests and the track lists generated for them.
- Links to playlists the bot created for you.
- Your settings (preferred number of tracks, default music service) and a daily request counter used for usage limits.
From Google (YouTube), only if you connect YouTube
- OAuth access and refresh tokens for the scope
https://www.googleapis.com/auth/youtube. - The name of your YouTube channel, to show you which account is connected.
We do not request and do not receive your email address, contacts, watch history, subscriptions, likes or the contents of your existing playlists.
From Yandex, only if you connect Yandex Music
- An OAuth token for Yandex Music and your account login.
2. How we use Google user data
The YouTube token is used for one purpose only: when you press the “create playlist” button in the chat, the bot creates a new playlist in your YouTube account and adds the tracks you approved. The bot does not perform any action in your account without such an explicit request.
The use and transfer of information received from Google APIs by NO DJ needed anymore to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- Google user data is used only to provide the playlist feature described above.
- Google user data is not sold, not used for advertising, and not transferred to third parties.
- Google user data is not used to develop, improve or train any artificial-intelligence or machine-learning models, and is never sent to an AI model provider.
- No human reads Google user data, except with your explicit consent for a specific support request, when required for security purposes, or when required by law.
3. Track suggestions and AI
To suggest tracks, the text of your request is sent to a third-party AI model provider through our own server. Only the request text is sent — no Telegram ID, no tokens and no data from Google or Yandex.
To check whether suggested tracks exist, the bot searches the public music catalogs by artist and title. These searches are not tied to your account.
4. Storage and protection
- Data is stored on our own server. Access tokens are encrypted at rest with a key kept separately from the database.
- All connections to Google, Yandex and Telegram use TLS.
- Results of catalog searches are cached for no longer than 30 days.
- Server logs contain technical events (for example, “user connected a service”) with your Telegram ID, are size-limited and rotated.
- Database backups, if made, are kept no longer than 30 days.
5. Sharing
We do not sell or share personal data. Data leaves our server only as needed to provide the service: requests to Telegram to deliver messages, requests to Google or Yandex on your behalf when you create a playlist, and request text to the AI provider as described in section 3.
6. Your choices and deletion
/logoutdisconnects a service: the token is revoked at Google and deleted from our storage immediately. When the last service is disconnected, your requests, track lists and settings are deleted as well.- You can revoke the bot's access to YouTube at any time on the Google security settings page.
- To request deletion of all your data, or a copy of it, write to support@iteratio.ru. We respond within 30 days.
7. YouTube and Google
NO DJ needed anymore uses YouTube API Services. By connecting YouTube you agree to the YouTube Terms of Service. Google's handling of your data is described in the Google Privacy Policy.
8. Children
The bot is not directed at children under 13 and does not knowingly collect their data.
9. Changes and contact
If this policy changes, the new version is published on this page with a new effective date; material changes are announced in the bot. Questions: support@iteratio.ru.
Кратко по-русски
- Что храним: числовой ID в Telegram, тексты запросов и списки треков, ссылки на созданные плейлисты, настройки, счётчик запросов. При подключении YouTube — OAuth-токен и имя канала, при подключении Яндекса — токен и логин.
- Зачем токен YouTube: только чтобы по кнопке создать плейлист и добавить в него одобренные треки. Без явного действия в чате бот в аккаунте ничего не делает.
- Кому передаём: никому. Данные Google не продаются, не идут в рекламу и никогда не отправляются в модели ИИ. Модели уходит только текст запроса — без ID, токенов и данных аккаунтов.
- Как защищаем: токены зашифрованы, ключ хранится отдельно от базы; кэш поиска и резервные копии живут не дольше 30 дней.
- Как удалить:
/logoutотзывает токен у Google и стирает его сразу, вместе с последним сервисом стираются запросы и настройки. Отозвать доступ можно и самостоятельно в настройках безопасности Google. Запрос на полное удаление или копию данных — на support@iteratio.ru.
Использование данных, полученных от Google API, соответствует Google API Services User Data Policy, включая требования Limited Use. Обязательной считается английская версия выше.