Privacy Policy
Miraclaw AI · miraclaw.io · Last updated: September 18, 2026
Who we are
Miraclaw AI is a personal AI assistant available via the Telegram bot (@miraclaw_ai_bot) and the mini-app at miraclaw.io. Contact: t.me/murgulets · murgulets@gmail.com.
The data controller and service provider is Lyudmila V. Murgulets (Мургулец Людмила Васильевна), self-employed under the Russian professional income tax regime, INN 782576583516. Postal address: 191186, St. Petersburg, Malaya Konyushennaya st., 4/2, apt. 183. Phone: +7 921 963-87-68. Commercial terms are set out in the public offer and the terms of service.
What we collect
- Your Telegram account basics (ID, name) — to operate your assistant account.
- Messages you send to the bot — to generate responses; recent history is kept to maintain conversation context.
- Profile details you choose to fill in (name, interests, preferences) — to personalise answers.
- Optional connected services (Google Calendar, Yandex Disk/Mail, Mail.ru Mail) — see below.
Connected services (OAuth)
Integrations are strictly opt-in. When you connect an account we store the OAuth tokens (see Data protection & security below) and access data only on your explicit request (e.g. “what’s on my calendar tomorrow”, “add a meeting on Friday at 3pm”) or for a feature you enabled (the opt-in morning briefing).
- Google Calendar (
calendar.events): we read your upcoming events to remind you of them, and create events when you ask us to. We do not modify or delete events you didn’t ask us to change, and we never touch any other Google data (no Gmail, no Drive, no Contacts). - Yandex: list files on your Disk (read-only) and read recent mail headers (read-only IMAP).
- Mail.ru: read recent mail headers (read-only IMAP).
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google Calendar data is used solely to provide the user-facing calendar features described above. We never sell your data, never use it for advertising, and never use it to train AI/ML models. It is not transferred to any third party except the AI model providers that process your direct request (see “AI processing”), and only to the extent needed to fulfil that request.
Data protection & security
We apply the following safeguards to sensitive data (OAuth access/refresh tokens and any calendar or mail content retrieved on your request):
- Encryption in transit. All traffic between your device, our mini-app, our servers and the providers’ APIs is protected with TLS/HTTPS.
- Encryption at rest. OAuth access and refresh tokens are encrypted with AES-256-GCM before being written to our database; the encryption key is held in the server environment, never in the database, and never exposed to clients.
- Least privilege. We request the narrowest scope that powers the feature (
calendar.eventsonly — not full Calendar, and no Gmail/Drive/Contacts scopes). - Network isolation & access control. The application backend is not exposed to the public internet; it is reachable only through our authenticated application layer. Database and Redis run on a private network and are not publicly reachable.
- Access on request only. Connected-account data is fetched only when you ask for it or for a feature you explicitly enabled. We do not continuously mirror or bulk-export your Google data.
- Instant revocation. Disconnecting a service in the mini-app (Профиль → Интеграции) deactivates the stored token immediately, after which we can no longer access that account.
- Minimisation. We retain only what a feature needs (e.g. event titles/times for reminders); we do not build advertising or marketing profiles from connected-account data.
AI processing
Message content is processed by third-party AI model providers (via OpenRouter) and media generation providers (fal.ai) solely to produce the response you requested. We do not use your content — including any connected-account data surfaced in a request — to train models.
Payments
Payments are handled by payment partners, not by us. Card and SBP payments for subscriptions and token packs are processed by Tribute (tribute.tg); payments in Telegram Stars are processed by Telegram. We never receive or store your card number, CVC or bank credentials.
When a payment succeeds, the partner sends us a notification. From it we use: your Telegram user ID and Telegram username; the identifier and name of the purchased subscription or digital product; the billing period and the date your access expires; the payment type (regular, gift or trial); and the purchase or transaction identifier. For a refund or cancellation we additionally use the refund flag, the refunded amount, the payment status and the refund reason supplied by the partner. We keep these records as proof of payment and for tax reporting.
The notification may contain further fields we do not use. If its event type is one we do not recognise, the notification body (up to 400 characters, which may include any field the partner put in it) is forwarded to the service owner’s private Telegram channel so that a person can process the payment or refund manually; that channel is accessible to the operator named above and is not public. The payment partners process your payment data as independent controllers under their own privacy policies.
Retention & deletion
Data is kept while your account is active. You can disconnect any integration at any moment in the mini-app (tokens are deactivated immediately). To delete your account data entirely, use the mini-app or contact @murgulets / murgulets@gmail.com — we delete on request. You may also revoke our access directly from your Google Account permissions page.
Кратко по-русски
Мы храним только то, что нужно для работы ассистента. Интеграции (Google Календарь, Яндекс, Mail.ru) подключаются добровольно и используются только по вашему запросу. OAuth-токены шифруются перед сохранением (AES-256-GCM), передача данных идёт по HTTPS, бэкенд не доступен из интернета напрямую. Данные Google Календаря используются исключительно для функций календаря, не продаются, не идут в рекламу и не используются для обучения моделей. Отключить интеграцию или удалить данные можно в любой момент.
Оплата проходит на стороне платёжных партнёров: картой и через СБП — Tribute (tribute.tg), в Telegram Stars — Telegram. Реквизиты карты нам не передаются и у нас не хранятся. Из уведомления партнёра мы используем ваш Telegram ID и имя пользователя, идентификатор и название купленной подписки или товара, период и дату окончания доступа, тип платежа (обычный, подарок, пробный), номер покупки, а при возврате — признак, сумму, статус и причину возврата. Этого достаточно, чтобы открыть доступ и выдать чек. Если событие пришло с незнакомым именем, его тело (до 400 знаков) пересылается в служебный Telegram-канал владельца сервиса, чтобы платёж или возврат разобрал человек.
Оператор персональных данных и исполнитель услуг — Мургулец Людмила Васильевна, самозанятая (налог на профессиональный доход), ИНН 782576583516. Почтовый адрес: 191186, г. Санкт-Петербург, ул. Малая Конюшенная, д. 4/2, кв. 183. Телефон +7 921 963-87-68, murgulets@gmail.com. Условия оплаты и возврата — в Публичной оферте, правила пользования — в Пользовательском соглашении.
