Mastak
How it worksFeaturesPricingFAQBlog
Log inStart free
Switching from ManyChat?→
How it worksFeaturesPricingFAQBlog
Start freeLog in →
Legal

Privacy Policy

We built Mastak to help you run real sales conversations at scale. That means handling some of your data and your customers' data carefully. This policy explains what we collect, why, and what you can do about it.

Last updated: July 2026

Contents

  1. What Mastak is and what this policy covers
  2. Data we collect
  3. Why we collect it
  4. Third-party processors
  5. Google user data and Limited Use
  6. How long we keep your data
  7. Your rights
  8. Cookies and local storage
  9. Security
  10. Children
  11. Changes to this policy
  12. Contact

What Mastak is and what this policy covers

Mastak is a cloud SaaS platform that connects to your Instagram and Telegram accounts, automates DM replies using AI, and runs sales conversations on your behalf. We're at mastak.app, and this policy covers everything that happens when you use our service.

It tells you what personal data we collect, why we collect it, who we share it with, how long we keep it, and what rights you have. If you have questions, email us at [email protected].

Data we collect

  • Account data: your name, email address, and a hashed (not plain-text) password when you sign up.
  • Connected account credentials: Instagram page/account IDs and OAuth access tokens from Meta, plus Telegram bot tokens you provide. Both are encrypted at rest with AES-256 before storage.
  • DM conversation content: the text of incoming DMs and Mastak's AI replies, stored per conversation thread. This is necessary for the AI to maintain context and memory across a conversation.
  • Contact data (your leads): Instagram usernames and Telegram user IDs of people who interact with your automated DMs. These are your audience members, not Mastak account holders.
  • Knowledge base files: documents, PDFs, and text you upload as the RAG knowledge base for your AI. Stored in Cloudflare R2, isolated per tenant.
  • Payment metadata: your plan tier, subscription status, and transaction IDs. We don't store card numbers — payment processors handle that.
  • Usage data: API call counts, token usage per conversation, feature usage logs, and error logs.
  • Technical data: IP addresses, browser and device type, session tokens — used for security and abuse prevention.

Why we collect it

  • Running the service: connecting to the Meta Graph API and Telegram Bot API, routing webhooks, processing DM conversations through the AI pipeline.
  • AI features: maintaining conversation context, running RAG queries against your knowledge base, generating AI replies via OpenRouter.
  • Billing: managing your subscription and sending billing notifications.
  • Security: detecting abuse, rate limiting, and preventing unauthorized access to tenant data.
  • Communication: sending you service emails (welcome, token expiry alerts, billing notices) via Brevo; newsletters if you opted in via beehiiv.
  • Legal obligations: retaining records as required by applicable law.

Third-party processors

We use the following services to deliver Mastak. Each one processes certain data on our behalf.

  • Meta / Instagram — Meta Graph API receives your connected page access tokens and sends/receives DM messages on your behalf. Meta's own data policy governs their side of that processing.
  • Telegram — the Telegram Bot API receives bot tokens from your account and sends/receives messages. Telegram's privacy policy applies to their platform.
  • Google — if you connect the Google Sheets or Google Calendar integration, Google receives and processes the data covered by the scopes you grant for the account you authorized. See "Google user data and Limited Use" below for what this covers and how it's used.
  • OpenRouter — LLM API routing. Conversation messages are sent to OpenRouter for AI model processing (default: GPT-4o mini). OpenRouter may route to underlying providers such as OpenAI or Anthropic. Per OpenRouter's API terms, conversation data is not used to train models.
  • Cloudflare — CDN, DDoS protection, and R2 object storage for knowledge base files and database backups. Data is processed under Cloudflare's DPA.
  • PostgreSQL (self-hosted, Dallas VPS — Virtarix/HIVELOCITY) — our primary database. This is our own infrastructure.
  • Redis (self-hosted) — queue and session data. Our own infrastructure.
  • Brevo — transactional email delivery (welcome emails, billing alerts, token expiry notices).
  • beehiiv — newsletter delivery, if you subscribed to Mastak updates.
  • ЮKassa — payment processing for Russian-card holders.
  • PayPro Global — payment processing for international cards.
  • NOWPayments — cryptocurrency payment processing.
  • Better Stack — uptime monitoring (receives health-check pings only; no user data is sent).

Google user data and Limited Use

If you connect a Google account to Mastak (for the Google Sheets or Google Calendar integrations), Mastak requests only the access needed for the feature you turn on:

  • Google Sheets (spreadsheets) — to append qualified leads as new rows to a spreadsheet you choose. We do not read or modify your other spreadsheets.
  • Google Calendar (calendar.events, calendar.freebusy) — to read your free/busy times so the assistant can offer open slots, and to create booking events when your customer confirms a time.

Mastak's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Concretely, data obtained through Google APIs is used only to provide and improve the user-facing features above. We do not sell it, use it for advertising, or use it to train generalized AI/ML models, and we do not transfer it to third parties except as needed to operate the feature or as required by law. Google OAuth tokens are stored encrypted (AES-256) at rest, isolated per account, and you can revoke access at any time by disconnecting the integration in your Mastak dashboard or at your Google Account permissions.

How long we keep your data

  • Account data: retained while your account is active. Deleted within 30 days of an account deletion request.
  • DM conversation logs: retained for 12 months from creation, then automatically deleted. You can request earlier deletion at any time.
  • Knowledge base files: retained until you delete them or close your account.
  • Payment records: retained for the period required by applicable financial regulations — typically 5 to 7 years.
  • Usage logs: retained for 90 days, then aggregated and anonymized.
  • Backups: database backups stored in Cloudflare R2 for 30 days, then deleted.

Your rights

  • Access: you can request a copy of the personal data we hold about you.
  • Correction: you can ask us to correct inaccurate data.
  • Deletion: you can request deletion of your account and personal data. Email us at [email protected].
  • Export: you can request an export of your data in a machine-readable format.
  • Opt-out of marketing: unsubscribe from newsletters at any time via the link in any email we send.

GDPR (EU/EEA users): in addition to the rights above, you have the right to object to processing, restrict processing, and lodge a complaint with your local supervisory authority.

Russian users (152-FZ): Mastak processes personal data of Russian citizens in compliance with Federal Law No. 152-FZ "On Personal Data." The primary database for personal data of Russian citizens is located on servers in Russia. You have the right to access, correct, and delete your personal data by contacting [email protected].

We respond to all rights requests within 30 days.

Cookies and local storage

  • Session cookies: we use these to keep you logged in. They expire when your session ends or when you log out.
  • UI preferences: we store your language setting in localStorage or a cookie.

We don't use third-party advertising cookies. We don't sell data to ad networks. We may use privacy-respecting analytics that process only aggregated, non-personal data. We don't use Google Analytics.

Security

  • Access tokens for Meta and Telegram are encrypted at rest using AES-256 before we store them.
  • All data in transit is encrypted via TLS. HTTPS is enforced by Cloudflare Full Strict mode.
  • Tenant data is isolated at the database level using Row Level Security (PostgreSQL RLS).
  • We don't log DM message content in plain-text server logs.

We don't hold SOC 2 or ISO 27001 certifications at this stage. Mastak is an early-stage product, and we'll pursue relevant certifications as we grow.

Children

Mastak is not directed at children under 16. We don't knowingly collect personal data from anyone under 16. If you think we've collected data from a minor, contact us at [email protected] and we'll delete it promptly.

Changes to this policy

We may update this policy as we add features or as legal requirements change. We'll notify active users by email of material changes at least 14 days before they take effect. The "last updated" date at the top reflects the current version.

Contact

For privacy questions, data deletion requests, or rights requests:

  • Email: [email protected] — use the subject line "Privacy Request"
  • Instagram: @mastak.app
  • Telegram: t.me/mastakapp
Mastak

Ready-made sales funnels with AI inside — Instagram, Telegram.

Product
  • How it works
  • Features
  • Pricing
  • Changelog
  • Roadmap
Compare
  • Mastak vs ManyChat
  • Mastak vs ChatPlace
  • Mastak vs BotHelp
  • Mastak vs manual DMs
Use Cases
  • For coaches
  • For course creators
  • For bloggers and creators
  • For freelancers
  • For Telegram channels
Company
  • About
  • Blog
  • Help center
  • Privacy policy
  • Terms of service
Connect
  • Instagram @mastak.app
  • Telegram t.me/mastakapp
  • [email protected]
© 2026 Mastak.Built for the DM closers.