What we keep (hardly anything)
Two lines of data per key. Here they are.
There is no account system at Valideo. You never give us an email address, a phone number or a name. The bot issues a key, and the key has an end date. That, plus the Telegram chat the bot replies to, is the whole customer record.
Kept
- The key and the date it expires
- The Telegram chat the bot delivers it to
- Total load per location, with no user identifiers, so we know when to add capacity
Never kept
- The sites you open or your DNS lookups
- Connection times tied to a key
- The IP address you connect from
- Card numbers or billing addresses: payment happens inside Telegram
What we cannot claim yet
We do not have a third party audit. Until we do, the argument rests on design: a service that never asks who you are has very little it could record. The client apps are open source projects that we do not control, so nothing on your device reports to us.
If a legal request arrived, the honest answer would be short: a key, an end date and a chat identifier.