Privacy Policy
Last updated 2026-07-25. This policy explains what data Targa ("we", "us") collects, why, and the choices you have. It applies to the Targa dashboard, the @TargaM1Bot Telegram bot, and related services (together, the "Service").
The short version
We collect the minimum needed to run an anti-spam service: your email address for your account, and moderation records for the groups you protect. Detection records identify group members by their numeric Telegram id and display name — never by message text — and age out automatically. We don't track you across the web, we don't show ads, and we never sell data.
Data we collect
Account data. When you create a dashboard account we store your email address, a securely hashed password (we never store the password itself), the Telegram chat ids of the channels you connect, and each channel's plan. If you sign in with Google, Apple, or Telegram we store the identifier that sign-in method provides (your Google email, or an opaque Apple/Telegram id). If you enable push notifications in a Targa app, we store that device's push token. A single session cookie keeps you signed in; we set no tracking or advertising cookies.
Moderation and detection records. To protect the groups it's added to, the bot evaluates messages as they arrive. Message text is processed in the moment and is not stored in detection records. What the durable records contain is: spam scores, which detectors fired, the action taken, and — because moderation needs to say who — the numeric Telegram id and display name of the member involved, plus warn history, roles, and ban-list entries that group admins create. These records age out on fixed schedules (see Retention). Profile photos and bios are analyzed in memory only and never stored.
Spam examples you submit. When a group admin teaches the classifier with /spam or /ham, the text of that message is stored as a training example (without the author's identity) and deleted after at most 12 months.
Configuration you provide. Settings you save for a group — guardrails, locks, blocklist patterns, keyword filters, notes, welcome text — are stored so the bot can apply them.
Audit and server logs. The dashboard keeps an audit trail of configuration changes (kept up to 12 months); when you delete your account, your identity in it is anonymized. Our infrastructure keeps standard, short-lived server logs which may include IP addresses; they rotate automatically.
Support communications. If you contact us (for example on Telegram), we receive what you send us and use it to help you.
Payment data. Targa M1 is free and involves no payment data at all. If you buy a paid product (such as Targa M2, when available), payment is handled by our payment processor (Stripe). We receive plan and subscription status and a customer reference, not your card number.
AI detection tier (Targa M2)
If you enable the paid M2 tier on a channel (not yet generally available), ambiguous messages from that channel are additionally analyzed by AI providers acting as our processors (currently Anthropic; optionally OpenAI) — the message text is sent for classification, without member or channel identifiers. M2's own records key channels and actors by salted, opaque hashes; raw text held for analysis is deleted on a fixed 90-day schedule, and erasure requests cascade to it.
How we use data
We use this data to operate the Service: authenticating you, protecting the groups you connect, showing you protection stats and the decision log, sending you the push notifications you enabled, processing payments for paid products, responding to support requests, and keeping the Service secure and reliable. Aggregated, anonymized detection statistics also power the public Spam Index; nothing in it identifies you, your groups, or your members.
We do not sell or rent personal data, and we don't use it for advertising or profiling.
Legal bases
Where the GDPR or similar laws apply, we process account and configuration data to perform our contract with you; moderation records, detection signals, and security measures under our legitimate interest in providing effective anti-spam and fraud prevention to the groups that install the bot; and payment records to comply with legal obligations.
Sharing
We share data only with the service providers needed to run Targa: hosting infrastructure (Hetzner, Germany), content delivery and network security (Cloudflare), payment processing (Stripe), sign-in providers you choose (Google, Apple, Telegram), push delivery (Apple Push Notification service — moderation alerts you enable include the member name and action involved), and AI analysis for the M2 tier as described above. Each is limited to providing its service. We may disclose data if required by law, or to protect the rights, safety, or integrity of the Service. If Targa is ever part of a merger or acquisition, data would transfer under this policy's protections and we'd notify you.
Retention
Account data is kept while your account exists. Moderation and detection records age out automatically: per-message detection records after 90 days, member activity records after 180 days, admin-submitted spam examples after 12 months, monthly usage counters after 13 months, and the configuration audit trail after 12 months. Ban lists that group admins or federations maintain are kept while they remain in force, as an anti-abuse measure. Deleting your account immediately removes your email, password hash, sign-in identifiers, channel links, device push tokens, and any waitlist entries, anonymizes you in the audit trail, and deletes your payment-processor customer record if one exists.
Security
Passwords are stored only as salted hashes, all traffic is encrypted in transit with TLS, access to production systems is restricted, and detection records contain no message text. No system is perfectly secure, but we design so that the data we hold is of little use to an attacker.
Your rights and controls
You can disconnect any channel, change your password, download a copy of your data (Account → Download your data — an immediate JSON export of your account, channels, devices, and settings history), and delete your account, all self-serve from the dashboard — no email required, no waiting period. Depending on where you live, you may also have legal rights to access, correct, export, delete, or restrict processing of your personal data, and to lodge a complaint with a supervisory authority. Access, export, and deletion are the self-serve controls above; for anything else — or if you can't sign in — contact us below and we'll respond within 30 days.
Group members: if you're a member of a group protected by Targa (rather than an account holder), the durable data we hold about you is limited to your numeric Telegram id, display name, and any moderation events (warns, roles, actions, ban-list entries) in that group — no message text. Most of it ages out automatically on the schedules above. Moderation decisions in a group are controlled by that group's admins; to have your records erased sooner, contact us below and we'll erase them within 30 days, except ban-list entries retained as an anti-abuse measure.
International transfers
Our servers are in the European Union (Germany). Targa is used globally, so support channels and third-party providers may process data outside your home country; where required, we rely on recognized transfer safeguards such as standard contractual clauses.
Children
The Service is not directed at children and we don't knowingly collect personal data from anyone under 13 (or the higher minimum age in your jurisdiction). If you believe a child has provided us personal data, contact us and we'll delete it.
Changes to this policy
When this policy changes we'll update the date above; for material changes we'll give notice in the dashboard before they take effect.
Contact
Questions or data requests: reach us on Telegram at @targapraetorian, or via Support.