Privacy Policy
In short
- Palm photos go to an AI model (OpenAI via OpenRouter) for analysis and are not saved on our server. A reduced copy stays only on your phone.
- We keep your Telegram ID, your Telegram name, your readings, your Oracle chats, purchases and support requests — the app cannot work without them.
- We do not sell data, show ads, or use trackers or cookies.
- You can delete your data in the app profile (“Delete my data”) or through /support in the bot.
- The service is for people aged 16 and over.
1Who provides the service
Personal Palmist by SOLONSKY — the bot @solpalmist_bot and the mini app at palmist.solonsky.net — is provided by Aleksei Solonskii (brand SOLONSKY; “we”), who is also the controller of your data.
- NIE: Z1518958C.
- Address: Calle Suiza 24, 26, 46024 Valencia, Spain.
- Email: support@solonsky.net.
It is an independent app: Telegram did not create it and is not responsible for it. For any question about your data, write to us with the /support command in @solpalmist_bot — the fastest way — or to the email above.
2What data we receive and why
- Telegram data. When you open the app, Telegram passes us your ID, first and last name, @username, a link to your profile photo and your Telegram language. We use them to recognize you, show your profile and history, and choose the language.
- Palm photos. The photos you take in the app and the hand points your phone finds on them. The server passes the photos to the AI model for the reading and uses the hand points itself for measurements; it writes neither to the database nor to files. The reading keeps only the lines and features found — coordinates on the photo, without the photo itself.
- Readings. The text of the reading, the lines and features found, the theme, the language and the date.
- A name on the reading. If a quick reading is for someone else and you enter their name, the name is kept in the reading and printed on the image. It is not passed to the AI model.
- Reading records. The request number, a checksum of the photos (the photo cannot be restored from it), the status and the error code. They keep a payment from being charged twice and return a reading to your balance if something fails.
- Oracle. Your questions, the Oracle’s answers and how much text the model processed. Separately, the time of each question, without its text: the daily and monthly question limits are counted from it.
- Purchases. What was bought, how many Stars, the date, the Telegram payment number, the subscription end date, and the details of Stars transactions the bot receives from Telegram, including those of the Telegram affiliate program. Telegram processes the payment; we never receive card details.
- Balance and promo codes. How many readings and Oracle questions are on your balance and which promo codes have been activated on your account.
- Support. Your messages and our replies, the request type, your @username and the chat number. A screenshot sent to the bot stays on Telegram’s servers — we keep only a link to the file. A screenshot from the app is reduced by your phone, saved without metadata and kept by us.
- The language you chose for the bot and the app.
- Visits. When the bot was started and the app was opened — for the owner’s statistics on how many people use the service.
- AI outages. If your reading or question failed during an outage at the AI provider, we keep your Telegram ID to message you once when everything works again.
- Technical logs. Error codes, processing steps and how long they took — without photos, texts or names. Cloudflare’s log of every request with its IP address is switched off for our service. We also count what each AI request cost: the model and the number of tokens, without photos or text. When the app or the server runs into a failure, we record its kind, the place in the program, the screen and the app version. Numbers, links and anything in quotes are removed from the error message, and the text of an error in the app itself is not kept at all. To count how many people a failure affected, the record gets a pseudonym that changes every day: without our secret key it does not reveal your Telegram ID.
We process this data to do what you ask for: make a reading, answer a question, complete a purchase and handle your support requests. We send photos for analysis with your consent: the app asks for it before the first photo and keeps the date of your consent and the version of its text.
3Who receives the data
- Telegram — the messenger, the bot platform and Stars payments. Telegram processes data under its own privacy policy.
- Cloudflare — hosting. The app’s server runs on Cloudflare Workers, and the database is kept in Cloudflare D1. Cloudflare sees your device’s IP address in order to deliver the request, but its log of every request with the IP address is switched off for our service. Cloudflare keeps our technical logs, without photos, texts or names, for up to 7 days, and deleted data stays in the database’s backup history for up to 30 days.
- OpenRouter — the service that routes requests to the AI model. According to its documentation, it does not store request and response texts unless the account owner turns this on, and it keeps metadata such as the number of tokens and the response time. OpenRouter may send a request to the same OpenAI model hosted on Microsoft Azure or Amazon Bedrock; according to OpenRouter, they do not store requests or train models on them. If OpenRouter is turned off, requests go directly to OpenAI.
- OpenAI — the GPT models that look at the palm photo and write the reading and the Oracle’s answers. We send requests without response storage on OpenAI’s side (the store: false setting). According to OpenAI’s documentation, API data is not used to train models, and abuse-monitoring logs, which may contain requests and responses, are kept for up to 30 days. OpenAI automatically checks images for prohibited content.
The AI model receives the photos and an enlarged crop of the palm, the theme and language of the reading, the reading text and your questions to the Oracle. The hand points are not passed to the model: the server uses them itself for measurements. Your name, @username and Telegram ID are not passed to the model either; instead of the ID, the model provider gets a pseudonym — a fixed code derived from the ID, which helps prevent abuse.
The service owner sees your name, @username, ID, language, the number of visits and readings, your balance, purchases and support requests in the admin panel — to answer in support and check payments.
The owner also gets notifications in a private Telegram channel: about a failed or a completed reading, a failed Oracle answer, a purchase and a support request. A notification contains your name, @username, Telegram ID and language and what happened: the error code; the reading's topic, how many photos it used, how long it took, how it was paid for and how many purchases and redeemed promo codes you have in total; what was bought and for how many Stars; the request's topic and how many screenshots it has — without the text of the request or the screenshots themselves. A copy is kept in our database for 30 days, and the message in the channel stays until the owner deletes it.
We do not sell data or pass it to advertisers. We may disclose it only at the lawful request of an authorized body.
The servers of Cloudflare, OpenRouter, OpenAI, Microsoft and Amazon may be located in other countries, including outside yours.
4What is kept on your device
The app uses no cookies, advertising identifiers or visit counters. Telegram’s storage on your phone keeps:
- reduced copies of your palm photos without metadata — to show the lines on the photo, the posters and a repeat reading;
- the language you chose and technical flags, such as a note that the app has already updated.
“Delete my data” in the profile erases the photo copies and the record of your photo consent; the chosen language stays. The palmist.solonsky.net website remembers only the page language you picked.
Hand detection while you take the photos runs on the phone itself: frames from the viewfinder are sent nowhere — only the photos you take go for analysis — and the phone loads the files of this program from our own site, palmist.solonsky.net, not from third-party servers.
5How long we keep data
- Your profile, readings, Oracle chats and support requests — until you delete them.
- Screenshots from the app — up to 60 days. If all such screenshots together take up more than 100 MB, the oldest are deleted first.
- Records of Oracle questions the AI did not answer because of an outage (without the question’s text) — 7 days.
- Records of who an AI outage affected (Telegram ID and reason) — 30 days after the outage ends; then the Telegram ID is erased from them.
- The time of Oracle questions (without their text) — 62 days: the daily and monthly limits are counted from it, so “Delete my data” does not erase it.
- Copies of the owner’s notifications — 30 days.
- Records of technical failures — 30 days; the daily pseudonyms in them — 7 days.
- Records of visits (starting the bot and opening the app) — 13 months.
- Our technical logs at Cloudflare (without photos, texts or names) — up to 7 days.
- Purchase records — as long as they are needed for refunds, payment disputes and accounting, even after the rest of your data is deleted.
- Deleted data stays for up to 30 days in the backup history of the Cloudflare D1 database, from which the owner can restore the database to an earlier moment; after that it is gone from there too.
- If the service closes, we will delete all data.
6Your rights
You can find out what data about you is stored, get a copy of it, ask us to correct or delete it, and withdraw your consent to sending photos.
- Delete your data — the “Delete my data” button in the app profile. It deletes from the server your readings (paid ones too — unused readings stay on your balance) and the records of reading attempts, Oracle chats, support requests with their screenshots, your name, @username and chosen language, your photo consent, records of AI failures and the daily pseudonyms in the records of technical failures; it erases your name and @username from the copies of the owner’s notifications, and from your phone the photo copies. When you open the app again, Telegram passes your name and @username again. Visits stay in the statistics with no link to you. Purchases, balance, the Oracle subscription, activated promo codes, the bonus reading already used, the time of Oracle questions for the limits, the record of the deletion itself (Telegram ID and time) and your chat with the bot in Telegram are kept. Messages already sent to the owner’s channel stay. Deletion cannot be undone.
- Withdraw consent to photos — with the same “Delete my data” button: before the next photo the app asks for consent again. Without consent, new readings are not available.
- Everything else — a copy of your data, corrections, deletion on request, questions — through /support in @solpalmist_bot or at support@solonsky.net. We reply within 30 days and may ask you to write from the same Telegram account to make sure the request is yours.
If you believe we are violating your rights, you can complain to the data protection authority of your country; in Spain, the AEPD.
7Age
The service is meant for people aged 16 and over. We do not collect parental consent, so people under 16 may not use it. If we learn that data belongs to someone under 16, we will delete it. Parents can write to us through /support.
8How we protect data
The server checks Telegram’s signature on every request, all connections use HTTPS, promo codes are stored only as a hash, and only the owner can open the admin panel, by a list of Telegram IDs.
9Changes to this policy
We may update this policy. A new version will appear on this page with a new date. We will tell you about significant changes in advance in the bot or in the app.
This policy is written in Russian; translations are provided for convenience. If the versions differ, the Russian one applies.