vust

Privacy Policy

VUST Privacy Policy

Last updated: 2026-07-13

This policy explains what VUST collects to provide AI tools, operate paid access, support users, and keep the service reliable.

1. Data we collect

  • Telegram identifiers, such as Telegram user ID, chat ID, language, username, first name, or referral payload when available.
  • User messages, uploaded text, URLs, files, images, or prompts needed to provide the selected tool.
  • AI-generated outputs, tool status, delivery status, feedback, and support messages.
  • Payment status, entitlement data, pass key, Balance balance, trial counters, purchase events, and refund status.
  • Operational event and log metadata such as bot, surface, source, timing, provider, model, cost estimates, error codes, and safe request references.
  • Website usage metadata collected by hosting, analytics, security, and performance tools.
  • Session, guest-client, preference, and dismissal identifiers stored in cookies, local storage, or session storage.

2. How we use data

  • to deliver AI-generated results and Telegram bot responses;
  • to count free trials, subscriptions, passes, and Balance usage;
  • to grant and verify paid entitlements;
  • to handle support, refunds, abuse prevention, and debugging;
  • to monitor quality, cost, latency, errors, and service health;
  • to improve product flows and understand aggregate usage.

3. Processors and providers

VUST relies on third-party processors and infrastructure providers, including:

  • Telegram for bot delivery, Telegram user context, and Telegram Stars payment surfaces;
  • Tribute for supported external checkout and payment flows;
  • AI and model providers for text, image, search, analysis, or generation tasks;
  • hosting, database, storage, analytics, logging, and security providers such as Vercel and Supabase;
  • other tool-specific providers when a feature needs translation, extraction, search, or media processing.

To perform a requested action, VUST may transmit the submitted text, file, image, URL, and necessary context to the selected provider. Provider retention, abuse-monitoring, training, and international-transfer terms vary; VUST does not make a universal zero-retention or no-training promise for third-party providers.

VUST is independently operated. Naming a processor, model, API, or platform identifies a service used for a requested feature and does not mean that the provider sponsors, endorses, or operates VUST.

VUST does not sell personal data and does not share raw user inputs with advertisers or data brokers for their advertising purposes.

4. Public-source and marketplace data

Some VUST tools retrieve product, listing, price, availability, seller, review, or source-page data from a user-provided link, a publicly accessible page, an official API, or a contracted provider. Public accessibility does not by itself mean that content is open-licensed or free of third-party rights. VUST does not claim access to a brand's private systems or user account unless a feature explicitly requests and documents authorized access.

  • Publicly accessible source data may be processed transiently, cached, or stored as a structured snapshot when the selected feature requires it.
  • Review analysis records may include the submitted product URL, product name and rating, selected review text, derived signals, and generated analysis. A cache reuse window is not the same as physical deletion.
  • ReviewBot Price Watch stores a marketplace/product identifier, canonical URL, optional title, baseline and checked prices, currency, threshold, status, notification routing, and timestamps needed to deliver alerts.
  • Price snapshots are designed for bounded retention: the current cleanup policy targets snapshots older than 30 days. Price-watch import state is short-lived; the cleanup policy targets completed/expired states after 24 hours and daily counters after seven days.
  • A page may say "no storage" only when that exact tool path has been verified not to retain the submitted third-party content or derived records.

5. Cookies and browser storage

VUST uses cookies and browser storage that are necessary or useful for authentication, guest identity and quotas, tool history, security, interface preferences, cross-domain notices, and Telegram Mini App state.

  • Session cookies keep a signed-in session or clear stale access safely.
  • A guest-client identifier can distinguish anonymous usage and associated tool history.
  • Local or session storage can remember theme, dismissed notices, interface state, and the current Mini App launch context.
  • Browser controls may block or clear these values, but account, history, preference, or quota features may then reset or stop working correctly.
  • If VUST later adds non-essential advertising or cross-site tracking technologies, it must update this policy and provide notice or consent controls where applicable.

6. Payment and analytics privacy

  • VUST stores payment state and entitlement state needed to deliver access.
  • Public analytics and admin events must not include raw payment IDs, raw Telegram IDs, raw secrets, payment card data, or full wallet identifiers.
  • Payment processors may independently process payment details under their own terms and privacy policies.
  • VUST does not collect or store full payment card numbers through its own website.

7. Retention

VUST does not apply a universal "no storage" promise. Retention depends on the selected tool and the data needed for delivery, history, billing, support, abuse prevention, monitoring, and legal obligations.

  • Tool history may include submitted input and generated output. The current cleanup policy targets tool-history records after 90 days unless a narrower tool rule or earlier deletion applies. Humanizer history is narrower: it keeps safe lengths and operational metadata. Humanizer source/output needed for result controls, one-shot continuations, and limited quality review becomes unavailable after 24 hours and is removed by the next hourly cleanup.
  • Operational logs may be retained for debugging, incident response, analytics, and service reliability; current cleanup targets vary by log type.
  • Support conversations may be kept while the issue is open and for a reasonable period after closure.
  • Temporary caches and processing artifacts should be deleted or made ineligible for reuse after their operational purpose ends.
  • Review-analysis records currently have no blanket automatic-deletion promise. A documented purge policy must be introduced before VUST advertises a fixed deletion period for those records.
  • Price-watch subscription state currently has no blanket automatic deletion promise; users may request review or deletion, subject to records needed for security, billing, disputes, or law.
  • External processors apply their own retention and deletion terms.

8. User rights and requests

You may request access, correction, deletion, or review of your VUST data by contacting @vustbot.

Some records may need to be retained for security, billing, dispute, tax, fraud-prevention, or legal reasons. Support handling is manual.

9. Security

VUST uses practical safeguards such as access controls, transport encryption, secret separation, and privacy-safe logging patterns. No system is perfectly secure, and you should avoid sending unnecessary secrets or highly sensitive data to general-purpose AI tools.

10. Children and family use

Some VUST tools are used for study or family activities. Age, account, and parental-consent requirements depend on the user's jurisdiction and the relevant platform rules. A parent or guardian should supervise a minor's use and avoid submitting unnecessary personal data. If you believe a child provided personal data without the required authorization, contact support so we can review and remove it where appropriate.

11. Changes

VUST may update this Privacy Policy as products, payment rails, infrastructure, or legal requirements change. Material changes may be announced on the website or in relevant bots.

    VUST Privacy Policy