Privacy
Most of what Paygram holds is already public, and a lot of it was not collected from the people it names. This policy sets out exactly what there is, where it came from, and what happens to it.
- Effective
- 18 September 2026
- Version
- 1.0
- Applies to
- Site, bot, Mini App and ledger
1Scope
Paygram operates this site, the Telegram bot, the Mini App and the ledger behind them, and is responsible for the data described in this policy. “Paygram”, “we” and “us” below mean Paygram.
This policy does not cover Telegram, Privy, pump.fun, Solana validators, or any other service Paygram reads from or pays through. Those services have their own policies, and what they do with your data is governed by them.
2What we hold
- Tokens
- Mint address, name, symbol, image, description, website, and the routing wallet set as fee recipient.
- Recipients
- The Telegram handle a token names, Telegram's numeric user or chat id once known, display name, and chat type (user, group, channel).
- Bindings
- The Solana wallet bound to a handle after a claim — a Privy embedded address or an external address — and when ownership was last verified.
- Fees and payouts
- Amount collected, transaction signatures, escrow under each handle, and each payout attempt.
- Claim sessions
- Telegram Mini App initData used once to prove the signed-in user, or a Privy access token used the same way. We do not keep the raw initData after verification.
- Site requests
- Ordinary server and CDN logs, including IP address and user agent, kept for security and debugging.
There is no Paygram account password and no email profile unless you write to us. A recipient who never claims leaves only the public handle a deployer typed, plus whatever Telegram's public profile API returns for that handle.
3Where it comes from
Almost all of it is read from public sources or created by the deployer. Token data comes from the chain and from the token's own metadata. The recipient handle is the @username the deployer typed. Telegram ids, photos and chat-creator status come from Telegram's Bot API when we look a handle up or verify a claim.
This is the part worth being direct about. If a token names you, Paygram holds a record about you that you did not give it and were not asked about. That is how the product works. It is also why a handle page is public rather than quiet: the person it concerns should be able to find out that it happened.
4Why we hold it
Each field exists because a payment cannot be made or evidenced without it. The handle and Telegram id identify who is owed. The claim signature ties an obligation to the on-chain event that created it. Re-checking ownership exists because Telegram usernames move. The payout record is the receipt.
None of it is used to build an advertising profile, to target ads, or to make an automated decision about a person beyond “is this the current owner of the handle, and have they opted out”. There are no advertising or analytics trackers on this site.
5What we never hold
No private keys and no seed phrases. Paygram never asks for them. A Privy embedded wallet is created by Privy; exportable keys stay with the recipient. No password for your Telegram account. No card, bank or payment-instrument details — payouts are SOL on Solana. No government identity documents. No browsing profile, and no cross-site tracking.
6Who else sees it
A claim passes through Telegram (to prove who you are) and, when you use it, through Privy (to attach a wallet). What reaches them is what those products need to sign you in. Infrastructure providers handle data in passing, including the host, the database, and the Solana RPC we read the chain through. They act on Paygram's instructions and for no other purpose.
Data may be disclosed where the law requires it. Beyond that, nothing is sold, rented or shared. There is no data brokerage here.
7What is public by design
Registered tokens, amounts routed, handle pages, leaderboards and payout confirmations are meant to be seen. The transparency of the ledger is a feature of the product rather than an oversight.
When this site is running in simulation mode, the people, tokens and payments you see are fictional. They are not records about real Telegram users. Live mode uses real handles and real on-chain amounts.
8How long we keep it
Ledger records are kept for as long as the ledger exists. They are the record of what was owed and what was paid, and deleting them would remove the evidence that a payment was made to the person it was made to.
An opted-out handle stays on the do-not-pay list so we do not pay it again. Server and CDN logs are kept for a short operational period and then discarded. On-chain records are permanent and are outside anyone's control, including ours.
9Security
Access to the ledger is restricted, traffic is encrypted in transit, and treasury signing keys are held separately from the application. No system is perfectly secure, and Paygram does not claim otherwise. What limits the damage here is the shape of the data: there are no credentials, no payment instruments and no identity documents to lose.
10Your choices
You can ask Paygram to stop paying a handle and to remove it from the site's surfaces. How to do that is on the opt-out page. You can also ask for a copy of what the ledger holds about a handle, or for a correction if something is wrong. Write to [email protected].
On-chain records cannot be deleted by Paygram or by anyone else. A payment already sent on Solana remains on Solana.
Depending on where you live you may have further rights over personal data, including access, correction, deletion, restriction, objection, and portability, and you may complain to your local data protection authority.
11Children
Paygram is not directed at children and is not intended for anyone under 18. It does not knowingly hold data about children, and a handle believed to belong to a child will be removed from the site's surfaces on request.
12Changes to this policy
This policy may change as the product does. The version in force is the one published here, identified by the effective date and version at the top of the page. Material changes will be noted on the site.
13Contact
Paygram is contactable at @usepaygram on Telegram and at [email protected]. A message sent anywhere else does not reach us.