GDPR
What we keep, and why
Haminja needs your Telegram identity, your location and your album to work. Instead of hiding that, we say it plainly: this page lists every category of data, why we keep it, its legal basis and how long it stays. Every table here maps to one table in our database.
Version 1 · Last updated 5 October 2026
Text inside [[ ]] is replaced with official information before final publication.
Our principle
We keep your real identity, location and photo album because the product needs them: for "people near you", for introductions based on your real life, and so that messages actually reach you. In return we make four promises: we list every piece of data publicly here; we use each piece only for the stated purpose and enforce that in code; we encrypt everything in transit and at rest; and you can export and delete it yourself, without asking anyone.
The data table
This is exactly the table we committed to in the system design.
Telegram ID, username, first name, language
- Why we keep it
- Account, login, sending you messages, abuse prevention
- Legal basis
- Contract
- Retention
- Until account deletion (+1 year hashed tombstone)
Profile (name, age, gender, prompts, bio, interests, voice)
- Why we keep it
- Showing you to matches, matching
- Legal basis
- Contract / consent for special categories
- Retention
- Until deletion
Location (latest point or city)
- Why we keep it
- "People near you", distance display
- Legal basis
- Consent (revocable; city-only fallback)
- Retention
- Latest point only; 30 days after last activity
Album photos and derived tags/embeddings
- Why we keep it
- Profile display, finding people with similar life
- Legal basis
- Consent per photo visibility
- Retention
- Until you delete the photo
Assistant conversation and memories
- Why we keep it
- Your personal assistant remembers you
- Legal basis
- Contract
- Retention
- 90 days (transcript), memories until you delete them
Chats with matches
- Why we keep it
- Delivering messages, safety screening
- Legal basis
- Contract
- Retention
- Until either side deletes, max 12 months inactive
Reports, blocks, moderation records
- Why we keep it
- Safety, legal obligations
- Legal basis
- Legitimate interest / legal
- Retention
- 2 years
Verification result (yes/no + vendor reference)
- Why we keep it
- Keeping fake accounts out
- Legal basis
- Legitimate interest
- Retention
- Until deletion; vendor holds documents per its policy
Technical logs (IP, device, errors)
- Why we keep it
- Security, debugging
- Legal basis
- Legitimate interest
- Retention
- 30 days
Our promises, in plain language
- 1
We never publish your data
Your profile, photos and location are never shown anywhere outside Haminja. No search engines, no social networks, no public pages. Your coordinates are not even given to other users, only a rounded distance.
- 2
We never use it for another purpose
Each piece of data is used only for what the table above says. No advertising, no profiling for resale, no vague "product improvement". This limit is enforced in code and in database roles, not just in this text.
- 3
We never train AI on your content
Your messages, photos and conversations with the companion are not used to train any model, by us or by our AI provider. The companion's knowledge base contains only our own content.
- 4
We never sell it
Not the data, not "aggregated insights", not user lists. Selling data will never be our business model.
Companies we work with
Only three categories of third parties touch any of your data, each for one defined job and under a data processing agreement (DPA).
-
- Role
- Hosting of servers, database and photo storage
- Where
- Germany (Falkenstein / Nuremberg)
- Notes
- All data and backups encrypted and EU-only. [[DPA_LINK]]
-
- Role
- Selfie liveness check and age estimation
- Where
- Estonia (EU)
- Notes
- We keep only a yes/no result and a reference number; no identity documents are stored with us. [[VERIFICATION_VENDOR — being finalised]]
-
- Role
- Language models behind the companion and message safety screening
- Where
- United States
- Notes
- Content is sent only to generate a reply and is not used for model training. We use zero-data-retention terms for the models where that option exists; transfers are covered by a data processing addendum with EU Standard Contractual Clauses.
Retention, in plain language
The same table as above, as a list:
- Account data: until you delete your account.
- Location: only the latest point is kept, no history; deleted 30 days after your last activity.
- Companion transcript: 90 days. The memories the companion keeps about you are visible to you, and you delete any of them yourself.
- Conversations with matches: until either side deletes, or 12 months after the last message.
- Reports and moderation records: 2 years (legal obligation).
- Internal audit log: 1 year. Technical logs: 30 days.
- "Delete my account" wipes everything within 24 hours. The only thing that remains is a hashed tombstone of your Telegram ID, kept for 1 year so that a banned person cannot return with a new account. Your identity cannot be reconstructed from it.
- For users aged 15 to 17 the periods are halved: companion transcript 45 days, conversations 6 months, companion memories 30 days.
Your rights
You do all of this yourself, inside the bot or the Mini App, without writing to anyone. If something does not work, email us.
-
Export
The /export command in the bot gives you a zip with all your data (JSON + photos). GDPR Articles 15 and 20.
-
Delete everything
The /wipe command in the bot, or the "Delete account" button in the Mini App. Everything is gone within 24 hours. Article 17.
-
Withdraw location consent
Switch to city-only or turn location off completely at any moment. The latest point is deleted immediately.
-
Withdraw album consent
Per photo you choose: visible, visible only after an introduction, or used for matching only. Deleting a photo also deletes its derived tags and embeddings.
-
See and delete companion memories
Under "Me" you see exactly what the companion remembers about you and delete any item.
-
Complain
You have the right to lodge a complaint with the data protection authority of your EU country. List of authorities: edpb.europa.eu
Users under 18
In the EU the minimum age is 18 (Telegram's own terms). Outside the EU, users aged 15 to 17 can join, in a fully separate pool, with city-level location only, no precise point stored, and halved retention periods. Details on the Safety page.
Government and law-enforcement requests
We respond only to requests that come from a competent judicial authority in the country where the company is registered ([[ENTITY_COUNTRY]]) and through the official legal channel. Direct requests from other countries, including Iran, are not answered; the requester is told to use international judicial cooperation. Every request is reviewed by a lawyer, we notify the user wherever the law allows, and we publish request statistics here once a year.
Child sexual abuse material is the exception and is reported to NCMEC / IWF or the local authority as the law requires.
Data protection impact assessment (DPIA)
Because we process location, photos and (if you volunteer them) sensitive data, a full DPIA under GDPR Article 35 is maintained and updated with every significant change. You can request a summary by email.
Data requests contact
Haminja's data protection contact. Reply within 30 days at most, usually much sooner.
[[ENTITY]] — [[ENTITY_ADDRESS]]