Skip to main content

Privacy Policy

Last Updated: September 1, 2026

Introduction

Welcome to Entergram! This Privacy Policy explains how we handle your data while using our Telegram CRM platform ("Service") and public website.

For personal data relating to your own account and use of the Service, the data controller is Entinel Technologies OÜ, a company registered in Estonia (reg. no. 17485993) with its legal address at Pärnu mnt. 139b - 14, Tallinn, 11317, Estonia, operating under the Entergram brand. For personal data of third parties that you process through the Service (such as your leads' or contacts' metadata), you are the data controller and we act as your data processor; see our Terms of Service for details.

1. We Never Access Your Messages

We do not read, store, or process the content of your Telegram messages. This includes:

- Text, photos, videos, voice messages, documents, or other files

- Private or group chats, channels, and call content

- End-to-end encrypted data

Only metadata needed to run your CRM features is collected. We do not store the content of your messages, and message content is never retained on our servers in readable form.

2. Metadata We Collect

To provide CRM features like tags, tickets, filters, dashboards, and analytics, we collect only non-content data exposed by Telegram's API, including:

- Chat IDs, group/channel names, and usernames

- Timestamps, sender IDs, message counts, and deletion flags

- Any tags, notes, custom fields, or tickets you create in Entergram

- Technical session information needed to keep your Telegram account connected

- Usage analytics (e.g., messages per hour/day) for dashboards and product improvements

On our public website, if you choose to subscribe to the newsletter, we collect your email address and a record of your consent.

3. Third-Party Services

We use trusted third-party services to operate and improve Entergram:

- Google Analytics, analytics used across entergram.com and app.entergram.com only if you accept analytics cookies. Your choice is shared across these subdomains, the script is not loaded at all until you accept, and Google's advertising features remain disabled.

- Stripe, secure payment processing.

- Supabase, authentication and account management for the application (app.entergram.com).

- Cloudflare - network security, bot protection, and content delivery for both websites.

- Sentry - technical error reporting, so we can detect and fix crashes. Error reports are scrubbed of sensitive values before being sent, and we do not use session replay: we never record your screen or your session.

- Brevo - subscription management and delivery of the newsletter you request. Brevo acts as our data processor for this purpose.

- Hosting, our public website and application run on dedicated infrastructure that we manage and are delivered through Cloudflare.

These services may temporarily handle limited metadata as part of their functionality, but they do not access your Telegram messages.

The public website may ask the application whether an existing sign-in session is valid so it can label the application button accurately. The application returns only a true/false result; the public website does not receive the session token, email address, user ID, or workspace data, and the result is not stored or used for analytics.

We do not use advertising cookies, ad networks, ad targeting, profiling, or third-party cross-site tracking on either entergram.com or app.entergram.com, and we never sell your personal data. If you consent, app.entergram.com sends limited product events such as account creation, onboarding completion, Telegram connection, trial activation and payment completion to Google Analytics. It never sends Telegram message content, phone numbers, usernames or email addresses. See our Cookie Policy for the full itemised list.

4. How We Use Your Data

The metadata we collect is used only to:

- Power dashboards, filters, tags, and tickets

- Generate analytics and activity summaries

- Maintain security and prevent abuse

- Send the newsletter you specifically requested and manage your communication preferences

- Comply with legal requirements

5. Legal Bases (GDPR & Similar Laws)

We process your data based on:

- Contractual necessity: to provide the CRM service you signed up for

- Legitimate interests: security, fraud prevention, and product improvement

- Your consent: for optional features you enable and for each email subscription you request. You can withdraw consent at any time by using the unsubscribe link in an email or contacting us. Withdrawing consent does not affect processing that occurred before withdrawal.

6. Data Sharing & Disclosure

We do not sell, trade, or rent your data. We may share metadata with third parties only when required for legal compliance, fraud prevention, or service operation.

7. Security

Your data is protected with strong measures, including encryption in transit and at rest, strict access controls, regular security audits, and secure development practices.

8. Data Retention & Deletion

We keep service metadata only as long as your account is active. When you delete your account or request erasure, all data is permanently removed within 30 days (except where legally required to retain records).

Subscription contact data is kept until you unsubscribe, withdraw consent, or we stop the relevant update service. After you unsubscribe, we may keep the minimum suppression and consent record needed to honour your choice and demonstrate compliance, for no longer than necessary.

9. Your Rights

You have full control over your data. You can:

- Download My Data – export all your data instantly

- Delete All My Data – immediately removes your data from your account, with full erasure from our systems and backups completed within 30 days

Service-account export and deletion controls are available in Settings → Data. For newsletter data, use the unsubscribe link in any email or contact hello@entergram.com to request access, correction, deletion, restriction, portability where applicable, or withdrawal of consent. You may also object to processing based on legitimate interests.

You have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or the competent supervisory authority in your country.

10. International Transfers

Your data is primarily processed within the European Union. Some sub-processors may process data in other countries; in such cases we rely on adequate safeguards (such as European Commission adequacy decisions or Standard Contractual Clauses) in compliance with the GDPR and applicable Estonian law.

11. Children

Entergram is not intended for anyone under 18. We do not knowingly collect data from children.

12. Updates to This Policy

We may update this Privacy Policy occasionally. The new version will always be posted here with an updated 'Last Updated' date.

For major changes (e.g., collecting new data types), we will notify you via email or an in-app notice before the change takes effect.

13. Contact Us

For questions, feature requests, or privacy concerns: hello@entergram.com

Entinel Technologies OÜ (reg. no. 17485993), Pärnu mnt. 139b - 14, Tallinn, 11317, Estonia.

We usually respond within a few hours.