Zum Inhalt springen

Privacy checklist

Dieser Inhalt ist noch nicht in deiner Sprache verfügbar.

Work through this before you invite anyone. Retrofitting privacy after people have been working in a workspace for a month is much harder.


  • Each teammate connects their own Telegram → their inboxes stay private from each other by construction.
  • Or everyone connects the same account → one shared inbox, everyone sees everything on it.
  • Or a mix, per person.

Read What teammates can see first if you’re unsure. This choice determines more than any toggle.

Settings → Workspace → Privacy & Settings

  • Hide Telegram login chat from membersOn. Non-negotiable if you share accounts; it’s what stops members reading login codes.
  • Members can edit and delete messagesOff unless you have a specific reason. Telegram deletions are irreversible.
  • Members can see all analytics → decide deliberately. Off means members see only their own data.
  • Members can manage excluded chatsOff if you want exclusions to be a controlled decision.
  • Members can export their dataOff for contractors and short-term staff.
  • Members can delete ticketsOff. Editing is enough for almost everyone.
  • Share broadcast templatesOn if you want one message library.

Recommended configurations by team type are in Permissions & privacy settings.

3. Exclude what shouldn’t be there (2 min)

Section titled “3. Exclude what shouldn’t be there (2 min)”
  • Exclude personal chats, bots and dead groups on every connected account.
  • Confirm the count on each account card ({n} excluded).

Excluded chats

  • Your email account has 2FA. Entergram signs in with one-time email codes, so your inbox is the front door.
  • Your Telegram accounts have a 2FA password (cloud password) set in the Telegram app.
  • Every Public API key has the minimum scopes, a 30–90 day expiry and an IP allowlist where the caller has a fixed IP.
  • No key is doing double duty across two integrations — one key per integration, so you can revoke one without breaking the other.
  • Review Authorized apps under Personal Agents and revoke anything you don’t recognise.
  • Archive OAuth clients you no longer use — archiving revokes active grants and refresh tokens.

Public API keys · Personal agents


  • Members list — anyone who left the company still has a seat?
  • Pending invitations — revoke stale ones.
  • API keys — rotate anything older than 90 days; revoke unused keys.
  • OAuth grants — check Last used; archive dormant clients.
  • Log history — scan for anything surprising, filtered by member.
  • Export a backup of the workspace ZIP.

  1. Revoke first, investigate second. Revoke API keys and OAuth grants, remove the member, disconnect the affected Telegram account. All are reversible; a leak isn’t.
  2. Read the audit trail. Log history filtered by member, action and time range will tell you what was actually done.
  3. Rotate. New API keys, rotated client secrets, a fresh Telegram session.
  4. Contact support on Telegram from the sidebar’s Help & Support menu.

  • Anyone who has independently signed into a Telegram account can use the Telegram app directly. Entergram’s toggles govern Entergram.
  • Telegram’s own privacy settings (last seen, phone visibility, forwarding) are set in Telegram, not here.
  • Message content already sent — Entergram can restrict deletion, but it can’t unsend.