In short: Engflow uses Telegram data to sign you in, stores your learning progress, and uses first-party technical and product analytics to operate and improve the Service. If you open Engflow from a tracked website link, Engflow may link that website session to your Engflow account. We do not sell personal data or use advertising trackers.
1. Who is responsible for your data
Engflow is currently operated by its creator as an individual, not by a registered company. In
this policy, “Engflow”, “we”, and “the Service” mean the person operating Engflow. You can contact
the data operator through @engflow_bot with
the /support command.
This policy covers the Engflow Telegram Mini App, the Engflow bot, engflow.me, and support requests. Telegram processes data independently under its own privacy policy and is not part of Engflow.
2. Data we collect
Telegram data
- Telegram user ID, name, username, interface language, and profile photo when Telegram provides them to the Mini App.
- Technical Mini App launch data required to verify that a session is authentic.
Learning data
- Selected course, settings, level, and interface language.
- Learned, hidden, and favorite words, answers, review intervals, streaks, and progress.
- Exercise activity and technical errors connected with a learning session.
Payments and support
- Purchase type, Telegram Stars amount, date, status, and Telegram payment identifier.
- Premium status, expiration, auto-renewal cancellation, refunds, and purchase history.
- Support messages, username, name, and any information you choose to include in a request.
Engflow does not receive your bank card number, billing address, or details of the account used to buy Stars. Telegram handles Stars purchases and the native payment interface.
Website and technical analytics
- Depending on the visitor's region, Engflow either starts first-party product analytics on the first page view with an opt-out, or asks for permission before analytics starts.
- A random session identifier, sections viewed, button clicks, scroll depth, and periodic activity signals.
- Viewport size, browser language, referral source, and allowed UTM parameters.
- For the public blog counter, article address, counted-view time, and a one-way hash of a random per-article browser-session token. The counter does not store a Telegram account or raw IP address.
- When analytics is active, Engflow may add the random session identifier to a link that opens Engflow in Telegram.
- If Telegram returns this identifier in authenticated Mini App launch data, Engflow links the landing session and its recorded website events to the Engflow account that opened the Mini App.
- Privacy-notice version, your choice, language, choice time, and Global Privacy Control or Do Not Track signals. We do not store an IP address or User-Agent in the choice record.
- IP address and standard technical logs that may be processed by our servers and hosting providers.
When an analytics session starts, the server may add country, region, city, and ASN derived locally from the IP address. The raw IP address is not copied into the product analytics event. We do not record product search text and currently do not use landing data for advertising profiles.
The linked data helps Engflow measure the path from a website visit to verified sign-in and later product use. The random session identifier is not a password or login credential. A tracked link can be copied or opened with another Telegram account, so attribution is an estimate. Engflow does not use it to decide account access, payments, or security actions.
IP address and approximate network location
- An IP address may be stored in server sessions and security events to protect accounts and investigate abuse.
- The IP address may be used to derive country, region, city, ISP, ASN, network range, and VPN, proxy, Tor, mobile, or hosting indicators.
We use IP-derived network signals for approximate location, regional privacy settings, security, fraud prevention, and abuse detection. These signals are approximate and are not proof of a person's precise location.
When a payment invoice is created or an administrator performs a manual security check, the IP address may be selectively sent over HTTPS to proxycheck.io to detect VPN, proxy, Tor, hosting-network, and abuse indicators. Engflow disables provider-side query tagging, caches normalized indicators, and does not retain the full provider response or precise location returned by it. A failed check does not block a purchase.
3. Why we use data
- Contract: sign-in, progress sync, reviews, Premium, purchases, and support.
- Product analytics and attribution: understand how people use the website, which pages or buttons lead to verified Engflow sign-in, and how attributed users later use the product.
- Legitimate interests: security, abuse prevention, error diagnosis, and product improvement.
- Legal obligations: payment records, refunds, disputes, and binding government requests.
4. Cookies and browser storage
The landing page currently does not use advertising cookies or third-party advertising pixels.
First-party sessionStorage holds a random session ID, queued events, and sections
already viewed. Session entries are removed when the browser session ends. Engflow does not use
this identifier to recognize a visitor across separate browser sessions.
A blog article may store a separate random token in sessionStorage after a meaningful
view. The server stores only its one-way hash to avoid counting reloads and retries more than once
per article and day. This token is not linked to Telegram, advertising, or a visitor identity and
disappears when the browser session ends.
When analytics is active, the random session ID may be included in an Engflow Telegram link. If Telegram returns it when the Mini App opens, Engflow stores an attribution event that connects the landing session with the Engflow user record. The session ID is not a login credential.
After an explicit choice or an automatic refusal through a “Necessary only” link, Global Privacy
Control, or Do Not Track, a necessary localStorage entry stores a random preference
ID, the notice version, permission or refusal, and the time it changed. If analytics is refused,
Engflow stops new website analytics events, attempts to clear browser analytics entries, and
removes the session ID from Telegram links. Opting out does not automatically delete events
already sent to the server or an attribution already created. You can request deletion or
unlinking through support.
You can change your decision with the control below when no automatic refusal is active. Opening
engflow.me/?nostats=1 selects and stores “Necessary only”. Engflow also
honors active Global Privacy Control and Do Not Track signals. On a page opened with
nostats=1, or while a browser privacy signal is active, analytics cannot be enabled
until the page is reloaded without that signal. The stored refusal continues until you change it.
If browser storage access is blocked, the refusal still applies on the current page, but you may
need to clear Engflow site data in your browser settings to remove stored analytics entries.
5. Who receives data
We share data only as needed to operate the Service:
- Telegram, for authentication, Mini Apps, tracked-link delivery, bot messages, Stars, receipts, subscriptions, and refunds.
- Hosting, database, file storage, and content delivery providers.
- proxycheck.io, for selective VPN, proxy, Tor, hosting-network, and abuse indicators during payment and manual security checks.
- Technical contractors working under our instructions and confidentiality obligations.
- Government authorities when disclosure is legally required or necessary to protect rights and safety.
We do not sell personal data or share it with advertising networks.
Data source attribution: IP Geolocation by DB-IP.
6. International processing
Engflow is available internationally, and Telegram or our infrastructure providers may process data outside your country. We select providers with appropriate safeguards and use available contractual transfer mechanisms where applicable law requires them.
7. Retention
- Account and progress data: while your account is used or the data is needed to provide the Service.
- Payment records: while needed for refunds, disputes, accounting, and legal obligations.
- Support requests: until resolved and for a reasonable period afterward for dispute history and safety.
- Technical analytics and attribution records: Engflow currently has no fixed automatic deletion period. We keep them in pseudonymous or linked form while needed to understand and improve the product.
- Privacy-choice records: for as long as needed to respect your decision and demonstrate lawful processing.
You may request deletion or unlinking of website analytics connected to your account. Engflow may retain aggregated data that no longer identifies or links to an account. Backups may remain for a limited additional period until they rotate out. Data may be retained longer when required by law or an active dispute.
8. Security
We use Telegram init data verification, access controls, encrypted connections, rate limits, logging of critical actions, and backups. No online service can guarantee absolute security. Do not send passwords, Telegram login codes, seed phrases, bank card data, or bot tokens to support.
9. Your rights
Depending on your location, you may ask to:
- access your data and receive a copy;
- correct inaccurate data;
- delete your account and data;
- restrict or object to processing;
- receive portable data or withdraw consent;
- complain to a competent data protection authority.
Send /support to @engflow_bot
and describe your request. We may verify account ownership before disclosing or deleting data.
Deletion may not cover records that we must retain by law.
10. Children
Engflow is not intended for children below the age at which they can independently consent to data processing and use Telegram under the rules of their country. Where parental or guardian consent is required, it must be obtained before using the Service.
11. Changes and contact
We may update this policy when the product, infrastructure, or law changes. The current date is shown at the top. We will provide notice of material changes in the Service or through the bot where reasonably possible.
Data questions: @engflow_bot, command
/support. See Support for more details.