Privacy Policy
This policy explains how tldw.fast collects, uses, stores, and protects user data.
Last updated: 2026-07-08
1. Service overview
tldw.fast is a Telegram-first summary and archive service. Users can subscribe to supported sources such as YouTube channels and Naver blogs, receive generated summaries through Telegram, and browse saved summaries on the web.
2. Data we collect
We collect only the data needed to operate the service:
- Telegram account identifiers, such as Telegram user ID, username, and first name.
- Subscription settings for sources selected by the user.
- Content metadata, summaries, original text, transcripts, and processing status for subscribed sources.
- Favorites saved by the user.
- Operational logs needed to diagnose failures, abuse, queue status, and delivery issues.
- Optional Google account information when the user connects Google to import YouTube subscriptions.
3. Google user data
If a user chooses to connect a Google account, tldw.fast requests access to read the user's YouTube subscriptions. The service uses Google OAuth and the YouTube Data API for this purpose.
- Requested scopes: OpenID, email, and YouTube readonly access.
- Data accessed: Google account identifier, email address, and YouTube subscription list.
- Purpose: to show the user's YouTube subscriptions and let the user select channels to import into tldw.fast.
- Storage: imported or cached YouTube subscription records may be stored in the service database for the user's account.
- Use limitation: Google user data is not sold, used for advertising, or transferred to unrelated third parties.
Protection mechanisms for Google user data include:
- Google OAuth tokens are encrypted at rest and are not exposed in the web interface.
- All Google OAuth redirect and web application traffic is served over HTTPS.
- Access to Google user data is limited to the authenticated user account and configured administrator accounts needed for operations and support.
- The service requests only the scopes needed for the YouTube subscription import feature and does not request write access to the user's Google or YouTube account.
- Operational logs are used for debugging and abuse prevention, and the service avoids intentionally logging OAuth access tokens or refresh tokens.
- Server credentials and encryption secrets are stored outside the public web root and are not included in client-side code.
- Users can unlink Google access from the Google import page; after unlinking, stored Google OAuth tokens are removed from the service database.
tldw.fast's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. How we use data
- To authenticate users through Telegram.
- To manage user subscriptions and preferences.
- To fetch source content, generate summaries, and deliver them to Telegram.
- To provide a web archive, favorites, and subscription management features.
- To monitor service health, retry failed jobs, prevent abuse, and debug operational issues.
5. Data sharing
We do not sell personal data. We do not share Google user data for advertising. Data may be processed by infrastructure, database, hosting, messaging, and AI model providers only as necessary to operate the service features requested by the user.
6. Data retention
Account, subscription, summary, archive, favorite, and operational records may be retained while the service account remains active or as needed for service reliability. Original text and transcripts may be retained to support archive, search, quality review, and future user-facing features.
7. Security
The service uses administrative, technical, and operational safeguards to protect personal data and Google user data from unauthorized access, disclosure, alteration, and loss.
- HTTPS is used for web access and Google OAuth flows.
- Google OAuth tokens are encrypted at rest.
- Admin and operational views are restricted to configured administrator accounts.
- Database access is limited to the application process and authorized server operators.
- Secrets and credentials are stored in server-side configuration and are not published to users or client-side bundles.
- Service logs are reviewed for operational reliability and abuse prevention, and sensitive credentials are not intentionally logged.
- Access and operational logs are reviewed to detect unauthorized access or abuse, and server and application security updates are applied as needed.
8. User choices and deletion
- Users can unlink Google from the Google import page.
- Users can remove subscriptions and favorites from the web interface.
- Users may request account or data deletion by contacting the service administrator through the Telegram bot.
9. Children's privacy
tldw.fast is not intended for children under 13. We do not knowingly collect personal data from children.
10. Changes
We may update this Privacy Policy as the service changes. Material changes affecting Google user data will be reflected here before the service uses that data in a new way.
11. Contact
For privacy questions or deletion requests, contact the service administrator through our Telegram bot.