Privacy Policy
Last updated: September 21, 2026 · Version 2026-09-21
This policy explains how Silenia Drive ("Silenia", "we") handles information on silenia.org and in the Android and iOS applications. Features and controls may vary by platform and app version. Using Silenia or reading this policy does not give consent to optional error reporting.
- Your content. Telegram content is exchanged directly between your device and Telegram. Usage and error reports do not contain your messages or files.
- Mobile usage reporting. Standard is the default. Minimum omits the Telegram identity and still reports basic account-linked installation and app data.
- Optional error reports. Where offered, these require a separate, initially unchecked consent checkbox. You can continue without agreeing.
1. Your Silenia Account
We process your Silenia account identifier, public numeric Silenia ID, sign-in provider, email address, display name, and profile image where supplied. Sign-in options may include email, Google, or Apple; the website currently uses Google sign-in. Supabase handles authentication and stores the account profile. Your Silenia account is separate from your Telegram account.
2. Telegram, Files, and Device Access
You choose whether to authorize a Telegram connection. The mobile app uses TDLib locally; the website uses a direct browser connection. Telegram authorization keys and caches stay on your device, not in Silenia's Supabase database. Telegram receives the credentials needed for Telegram sign-in, such as your phone number and login code.
Messages and files you choose to access are fetched from Telegram and processed on your device. Files and notes you choose to store through the drive are sent to your Telegram Saved Messages. A contact or location you choose to share is sent to the Telegram destination you select. Device permissions for files, photos, camera, contacts, or location are used for the requested feature, not to populate diagnostic reports.
Usage reporting and error diagnostics do not create Telegram chats, contacts, bots, messages, or folders. They do not copy Telegram phone numbers, messages, contacts, file names, file contents, login codes, passwords, or session keys to Supabase. The limited Telegram identity included in Standard mobile usage reporting is described below.
3. Mobile Usage Reporting: Standard and Minimum
Usage reporting helps us understand which signed-in installations are active, identify affected app versions, and investigate abuse or service problems. Reports are associated with your Silenia account. They are not anonymous.
- Both levels: a random Silenia installation identifier, Android or iOS, app version and build, operating-system major version, and reporting level. We also keep server receipt times and first/last activity times. The installation identifier is generated for Silenia; it is not an advertising ID or hardware serial number.
- Standard (default): when a local Telegram session is already authorized and ready, also sends its numeric Telegram user ID, display name, and username. These are device-reported details, not verified proof of Telegram-account ownership.
- Minimum: does not read or send the local Telegram identity for reporting. Switching to Minimum ends the previous server-side Telegram observation and schedules it for deletion as described under Retention.
You can change the level in the mobile app's Diagnostics settings. There is no in-app off switch for basic usage reporting. Reports are limited to sign-in, relevant setting or session changes, and returning to the app after a configured interval; this is not a record of every screen, tap, or successful operation. These mobile reporting levels do not describe the website's browser-local Telegram connection.
4. Optional Technical Error Reports
Error reports are separate from usage reporting. In app versions that offer them, the checkbox starts unchecked. Checking it and confirming Continue grants consent for the displayed policy version, account, and installation. Continuing unchecked declines; access to the app does not depend on agreeing. Standard mode alone is not consent.
The documented initial scope is media playback failures: a decoder could not start or failed, a container is unsupported, or a source is unavailable. A report contains an approved event and failure code, occurrence timing/counts, and bounded installation, platform, app/build, and OS-version metadata. It is associated with your Silenia account to help diagnose affected installations. It is not an anonymous report or a recording of what you played.
Reports exclude raw logs, exception text, stack traces, screenshots, screen recordings, Telegram identity or content, file names or paths, URLs, search text, clipboard contents, precise location, and credentials. This feature is not a general crash-recording service. Only approved event types can be accepted, subject to collection controls, sampling, and daily limits. Publishing this policy does not enable error reporting.
You can withdraw consent in Diagnostics settings. Choosing Minimum also stops optional error collection and sending; returning to Standard does not grant consent again. Withdrawal clears queued error reports locally before contacting the server, including when offline. A request already sent may finish, and reports already received follow the retention and deletion rules below. We store consent decisions, their times, and the policy version so that your choice can be applied and checked. A new consent-policy version requires a new explicit grant before optional collection resumes.
5. Security and Connection Data
Hosting and authentication providers receive connection information such as IP addresses, request times, and browser or client information to deliver and protect their services. The mobile app does not add an IP address to its usage-report payload. This does not prevent a network provider from seeing the address used to connect.
Where enabled, Google Play Integrity on Android and Apple App Attest on iOS help assess whether a request comes from a recognized app installation. We process verification challenges, proofs, and bounded verdict/key metadata, without retaining raw proof tokens after verification. These checks do not verify Telegram-account ownership. Availability depends on platform, build, and server configuration.
Authorized administrators can view account, installation, reported Telegram identity, and approved diagnostic metadata for support, reliability, and security work. Access is restricted; protected administrative reads and changes require additional authentication and are audited. Diagnostic access does not provide access to your Telegram messages or files.
6. Purposes and Service Providers
We use information to operate accounts and requested file features, maintain service reliability, respond to support and deletion requests, and investigate abuse and security incidents. Optional error reporting relies on your separate consent. We do not sell personal data or use it for advertising.
- Supabase: authentication, account profiles, usage and diagnostic metadata, consent records, and server functions. Supabase privacy policy.
- Google and Apple: the sign-in and app-integrity services used on your platform. Google privacy policy; Apple privacy policy.
- Telegram: the direct connection, account authorization, and content storage you choose to use. Telegram privacy policy.
- Cloudflare: website hosting, delivery, and security. Cloudflare privacy policy.
Providers may process data in countries other than your own. Their privacy notices describe their processing and international-transfer arrangements. We may also disclose information when required by applicable law. Contact us with questions about the data associated with your Silenia account.
7. Local Storage and Security
The website stores the Supabase sign-in session and preferences in browser storage; Telegram authorization and caches use a separate per-user IndexedDB database. Signing out of Silenia on the web disconnects the running Telegram client but preserves its local authorization for your next sign-in on that browser. Unlink Telegram or clear site data to remove that local authorization.
The mobile app stores its local Telegram session, preferences, cached or offline content, and any pending diagnostic queue on the device. The error queue is encrypted and limited to 100 events. Local data may remain until you remove it, unlink the relevant session, clear app storage, or uninstall the app, subject to the operating system's storage behavior.
We use encrypted connections and restricted server access. Browser security policies and device protections reduce risk, but no system guarantees absolute security. Your browser profile, extensions, operating-system account, and device also affect local security. We use essential storage for these features, not third-party advertising or tracking cookies.
8. Retention
Server records use scheduled, bounded cleanup with these retention windows:
- Usage-report receipts: 30 days.
- Ended Telegram observations: 30 days after they end.
- Active Standard Telegram observations: a rolling 90 days from refresh.
- Integrity challenges: 7 days; revoked App Attest keys: 90 days.
- Playback error records, including their occurrence counts, if enabled: 30 days.
- Diagnostic delivery receipts: 30 days.
- Diagnostic daily aggregates without account or installation identifiers: 13 months.
- Administrator audit records: one year.
- Revoked installation records: 90 days after revocation.
Account profiles, active installation/security records, and consent decisions remain while needed for the active account. Scheduled cleanup is not an instantaneous remote wipe. Deleting an account removes its linked records as described below; audit records may retain a pseudonymous administrative identity for their stated security retention period. Provider connection logs follow the provider's applicable retention rules.
9. Account Deletion and Your Choices
To request deletion without opening or reinstalling Silenia, email contact@silenia.org with the subject "Silenia account deletion request", preferably from your sign-in email. The mobile app also provides an account-deletion entry. We may ask for a limited account ownership check. Never send passwords, Telegram login codes, session keys, or recovery codes.
After verifying ownership, we delete the Silenia authentication account and profile, installations, usage receipts, Telegram observations, consent records, and linked integrity and diagnostic records held in Supabase. We normally complete a verified request within 30 days and confirm by email. Narrow records required for a legal obligation or a security investigation may be retained only for that purpose and duration; we will explain any applicable exception when responding to your request.
Deleting Silenia does not delete your Telegram account or content stored in Telegram. Remove that content in Telegram if desired. We cannot remotely erase cached files or authorization stored in every browser or device you have used; unlink Telegram and clear local data there. Uninstalling the app alone does not request deletion of your Silenia account.
You can choose Minimum usage reporting and decline or withdraw optional error-report consent independently of Telegram authorization. Depending on applicable law, you may have rights to access, correct, export, delete, restrict, or object to processing of your personal data, and to complain to a data-protection authority. Contact us to exercise these rights. Withdrawing consent does not change processing already carried out before withdrawal.
10. Children
Silenia is not directed to children under 13 (or the minimum age required in your jurisdiction), and we do not knowingly collect their personal data.
11. Changes to This Policy
We update the date and version when this policy changes. Material changes will be disclosed through the service or store listing before the related new collection is enabled. Updating the policy does not itself grant consent or expand an existing optional error-report consent to a new version.
12. Contact
For Silenia Drive privacy questions, data requests, or deletion requests, contact contact@silenia.org.
© 2026 Silenia. Cloud architecture for personal data and connected services.