Privacy policy
Effective September 30, 2026
Mentor Bots ("the service") runs AI mentor chatbots on Telegram and a dashboard where bot owners manage them.
It is run by Jonathan, an individual, not a company. Questions or requests:
raczjonathan12@gmail.com.
If you chat with a bot on Telegram
- What is stored: your Telegram user ID, your messages and the bot's replies, facts the bot
saves about you to remember them later ("memories"), and follow-up messages it schedules. Message text, memories
and scheduled-message purposes are encrypted at rest. The service also stores numeric representations of messages
(embeddings) so it can find relevant earlier conversation; these are not encrypted.
- Why: only to answer you and continue the conversation.
- Temporary data: incoming Telegram updates are deleted once processed, and stored answers used
to avoid duplicate replies are deleted after 24 hours.
- Deleting your data: send
/delete to the bot in a private chat. It erases your
memories, conversation, scheduled messages and stored answers for that bot. Your permission to use the bot is
kept until its owner removes you.
If you own a bot (dashboard account)
- Account: your email address and login, handled by our database provider's authentication
service. Accounts are created by invitation.
- Bot settings: the bot's configuration, its Telegram bot token and any API keys you save.
Tokens and keys are encrypted at rest and never shown in full again.
- Knowledge you add: documents, audio and video you upload, and text you add over the MCP
connection. Files are converted to text (recordings are transcribed), split into passages and stored with
embeddings so your bot can answer from them. The original files are deleted after processing. You can delete
any file's knowledge from the bot's Knowledge page, and deleting a bot deletes all of its data.
Google Drive
Bot owners can import files from Google Drive. This uses Google's file picker and the
drive.file permission, which only gives the service access to the specific files you pick (or that
it created), never your whole Drive.
- What is accessed: the files you pick, their names, types, sizes, versions, checksums and
links, and the email address and ID of the Google account you use, so an interrupted import resumes with the
same account.
- How: your browser downloads the picked files from Google and uploads them to the service.
The Google access token stays in your browser's memory; the service's servers never receive or store your
Google credentials.
- What is kept: the imported file's contents become your bot's knowledge, as with any upload,
along with the file's current name and Drive link (answers can link to the file; Google's own sharing settings
still decide who can open it). An unfinished selection is kept for up to 7 days so you can resume it.
- Use: the data is used only to provide your bot's knowledge. It is not sold, not used for
advertising, and the service does not use it to train AI models.
- Removing it: delete the file from the bot's Knowledge page, and revoke the service's access
at myaccount.google.com/permissions.
The service's use and transfer of information received from Google APIs adheres to the
Google API Services User Data Policy,
including the Limited Use requirements.
Service providers
These providers process data only as needed to run the service:
- Telegram: delivers messages between you and the bot.
- Supabase: database and login (hosted in the EU, Frankfurt).
- Hostinger: the server that runs the service.
- Google Gemini API: writes the bot's replies, creates embeddings and can transcribe
recordings; it receives the text or audio needed for each request. When a request uses a free-tier Gemini key,
Google's Gemini API terms allow Google to use that content to improve its products.
- Groq and Deepgram: may transcribe uploaded audio and video.
- Apify: collects public YouTube transcripts for bots built from YouTube channels.
Nothing is sold or shared for advertising.
Security and retention
Data is kept while the bot or account exists, unless deleted as described above. Secrets and conversation text
are encrypted at rest, and access to the database is limited to the service itself.
Your requests
To ask what data the service holds about you, or to have it corrected or deleted, email
raczjonathan12@gmail.com. Changes to this policy are posted on this page with a
new effective date.
Home