Legal

Privacy Policy

Last updated: August 29, 2026

Who we are

Danny is a personal AI assistant available via Telegram and web (dannyai.io).

Operator: Alexey Sysoev, based in Russia.
Contact: [email protected]

What data we collect and why

We collect only what is necessary to provide Danny.

Web (Google sign-in)

  • Name and email — account identifier and personalisation
  • Profile picture — shown in the interface when provided by Google

Telegram

  • Telegram user ID — account identifier
  • Display name — personalisation
  • Telegram interface language — default language

We do not collect your phone number or Telegram username from Telegram by default.

What you share in conversation

  • Messages and replies (conversation history)
  • Voice: audio is transcribed; we store the text transcript, not the audio file
  • Photos/PDFs: analysed then discarded; extracted facts may be saved as memory when the feature allows
  • Expenses, tasks, reminders, calendar data you ask Danny to store
  • AI memory entries (facts, preferences, notes Danny saves for you)
  • Message reactions and reports — thumbs up/down stores the referenced Danny message ID, channel, reaction, purpose, and timestamps without copying message text; a problem report may contain text you enter

Settings

  • Timezone, language, communication style
  • Privacy mode (how much Danny stores)
  • Voice reply preference

Technical / cookies

We use essential cookies or local storage for language, authentication, and cookie-consent choice. Optional analytics or marketing cookies are off by default until you opt in via the cookie banner.

We do not collect card numbers — payments go through Robokassa.

How we use your data

  • Provide the assistant: replies, memory, reminders, history across devices
  • Personalise behaviour based on what you shared
  • Use content-free thumbs up/down reactions to identify product-quality issues
  • Operate and secure the service (auth, rate limits, abuse prevention)

We do not sell your data, use it for advertising, or use private conversations and message reactions to train AI models. Automated reflection over authorised account history personalises your service; it is not model training or advertising profiling.

A normal message, reaction, or product report is not training consent. Any future contribution program would require a separate, clear opt-in that states its purpose and scope and is never applied retroactively.

Third-party services (processors)

  • OpenAI — message content (and when used: audio for transcription, images for vision) under OpenAI's privacy policy. We do not send your account id as a marketing identifier to OpenAI.
  • ElevenLabs — text of Danny's reply for voice synthesis when voice is enabled (policy)
  • Google — OAuth sign-in
  • Telegram — bot delivery when you use Telegram
  • Robokassa — payments; we store subscription tier only, never card data
  • Cloudflare — CDN/security; may process IP for security (policy)

Cross-border processing: AI providers may process data outside Russia (including the United States). Our application database is hosted on private VPS servers (United Kingdom, as of this policy). By using the service you acknowledge these transfers are required to provide Danny.

Storage and security

Data is stored on private VPS infrastructure with TLS in transit, access controls, and per-owner isolation. No system is perfectly secure. If a breach affects your data, we will notify you as required by applicable law.

How long we keep data

We keep data while your account is active, unless you delete it sooner:

  • Conversation history — until you clear it or delete the account
  • Message reactions — with the referenced Danny message; deleting that message or the account deletes the reaction. Historical rows from an older feedback prototype remain quarantined from active product use and dataset/training export until reviewed retirement, while remaining available in your account export
  • Memories — until you delete them or delete the account
  • Expenses / tasks / reminders — until you delete them or the account

Your controls (self-service)

  • Export — download a JSON copy of your account data from Account settings (signed-in web) or the Telegram Mini App settings; the export includes active reaction metadata and quarantined legacy feedback rows for your verified linked identities
  • Delete account — permanent deletion from Account settings / Mini App (typed confirmation required)
  • Privacy mode — limit what Danny stores
  • Clear history — clear conversation history in-app or via bot commands where available
  • Forget — delete memory entries via product commands / memory UI

You can also email [email protected] for help with any request.

EU/EEA residents (GDPR)

Where GDPR applies, you may request access, rectification, erasure, portability, restriction, or objection. Legal bases typically include performance of a contract (providing the service) and, for some quality features, legitimate interests. Contact us at the email above; we aim to respond within 30 days. You may lodge a complaint with your supervisory authority.

United States (summary)

We do not sell personal information for money. Danny is not directed at children under 13. If you need a California (CCPA/CPRA) request, email us; we will process it in good faith under applicable law.

Children

Danny is not intended for users under 13. We do not knowingly collect data from children under 13. Contact us to delete such an account if discovered.

Changes

We may update this policy when the service changes. We will post the new version with an updated date. For significant changes we will notify active users where practical.