Privacy Policy
In short: we collect only what the Service needs in order to operate, store it in the Russian Federation, do not sell it to third parties and delete it on request.
This Policy describes what personal data the Boostix service (hereinafter the “Service”, “we”) collects, for what purposes we process it, to whom we disclose it and how we protect it. The operator of the Service is registered in the Russian Federation and complies with Federal Law No. 152-FZ “On Personal Data” and Federal Law No. 149-FZ “On Information, Information Technologies and Protection of Information”, as well as with the applicable international rules on the processing of users’ personal data.
The operator’s details (full legal name of the company, INN, OGRN, registered address) will be set out in the “Company details” section prior to the public launch of paid plans.
On any matter relating to the processing of personal data you may contact us at business@boostix.space — we respond within 10 business days.
We collect only the data that the Service requires in order to operate and to perform its obligations to you.
- Contact details — email, name, nickname, profile photo (if you uploaded one yourself);
- Telegram data — telegramId, username, name and profile photo — when signing in through the Mini App;
- Project data — what you have told us about your business in the questionnaire and the settings: niche, description of your audience, city, time zone, default styling;
- Payment data — processed by the payment gateway: the Service stores no card numbers, CVV codes or other sensitive payment details. What stays with us is the fact of payment and, for a card saved for automatic payments, its type and card scheme, its expiry date and its last four digits, so that you can see what you are paying with;
- Payout details for the referral programme — what you yourself entered in the request: the phone number for an SBP transfer, or the last four digits of the card, the cardholder’s name and the bank. They are needed solely in order to send you the money;
- Tokens for connected social networks — Telegram Bot API, Instagram Graph API, VK API, Pinterest API — are stored in encrypted form and are used solely to operate the connection: publishing at your command, reading the list of publishing targets and renewing the token itself;
- Connection metadata — the account identifier on the platform and the parameters of the publishing target; for Pinterest these are the name, URL, cover image and counters of every board in the account — all boards are saved on connection, there is no board selection step at this point — so that a board can later be chosen by name rather than by identifier;
- Publishing records — the time and the outcome of each delivery to every connected platform, so that you can see what was published, what was not and for what reason;
- User content — texts, references, knowledge base documents and RSS sources that you have uploaded to the project;
- IP address and browser string — are stored in one case only: alongside your consent to receive emails, as evidence that the consent was given, and for that purpose alone. They are not written to your profile card, and we build no profile of you from them. Besides that, the IP address is visible in the technical logs of the server and in the request-rate counters that protect sign-in against brute force — there it is short-lived and serves only the security of the Service.
What ends up inside your project is for you to decide. We neither require nor ask you to put personal data there — whether your own or anyone else’s: you can run a project under a made-up name, and the Service will work just the same. But if you do enter personal data into your texts, references or knowledge base, it will go to the provider of the AI model together with the generation request — as part of your own content and by your own decision. This is an explanation, not a disclaimer: what you have already uploaded we protect and disclose under the very same rules as the rest of the data.
Personal data is processed strictly to the extent necessary to achieve the following purposes:
- authenticating and identifying you in the Service;
- performing the obligations under the offer agreement: billing, debiting boosts, activating plans;
- generating content (texts, visuals, content plans) at your request;
- publishing content automatically to connected social network channels;
- providing technical support and communicating on matters concerning the operation of the Service;
- ensuring security and preventing fraud and abuse.
We do not use personal data for any purposes not provided for by this Policy.
Personal data is processed on one or more of the following legal grounds:
- your consent, given on registration and on acceptance of the terms of the offer;
- performance of the services agreement to which you are a party (the public offer);
- the legitimate interests of the operator in securing the Service, countering abuse and improving the quality of the product;
- compliance with the requirements of the applicable legislation of the Russian Federation.
You may withdraw your consent at any time — from that moment processing ceases, except where continued processing is necessary to perform the agreement or is required by law.
We disclose personal data to third parties only to the extent necessary for a particular feature of the Service to operate: a contractor receives exactly the data without which the feature cannot be performed, and does not receive the rest. The list of categories of recipients is closed and is set out below in full. We do not disclose the names of the contractors within a category: they change, whereas the category of recipient, the composition of the data disclosed and the purpose of the disclosure stay the same.
- Providers of AI models for text generation — the text of your task together with the project data (business description, tone of voice, rubrics, the relevant fragments of the knowledge base you uploaded) and the drafts of your posts: these are used to generate texts, content plans and captions. The data is sent exactly as you entered it — we do not anonymise it;
- Providers of AI models for image and video generation — prompts and the images you upload (references, product photos, logo) for generating pictures, as well as the voice-over text and video files for assembling clips and for speech recognition. You select the model yourself in the generation parameters, and that choice determines which provider the request goes to;
- Providers of AI models for vector search — fragments of knowledge base documents and descriptions of competitors’ niches, from which vector representations are built for searching the knowledge base. No images and no payment data are sent there;
- The search service — the search query composed from the topic of the post, when the retrieval of up-to-date facts is enabled. Neither your name nor your account identifier is included in the query;
- The service that delivers our service emails — the email address and the text of the message (sign-in code, notification that a generation is ready);
- The payment gateway — the payment details required to carry out transactions;
- Telegram, VK, Instagram, Threads, MAX, Pinterest — content and publication metadata, at your direct command. These platforms are named because you connect them yourself and must understand where your post will go;
- The cloud infrastructure on whose servers the Service is hosted.
A contractor within a category is switched by a setting of the Service — for example, if a provider fails or a model is changed. Who is in use at any given moment we will tell you on request at business@boostix.space. The appearance of a category of recipient that is not on the list constitutes a change to this Policy, and we notify you of it under the rules of section 10.
There are no web analytics counters on the list: none are installed on the site — see section 9 for details.
We do not pass user content to anyone for the training of models. How a contractor handles the data it receives on its own side is governed by that contractor’s own policy. Some of the recipients are located outside the Russian Federation — disclosure to them is a cross-border transfer and is carried out on the basis of the consent you gave on registration.
Only what is required to create a pin is sent to Pinterest: the images of the prepared post (no more than five), the title, and the description together with the hashtags. The board is the one you selected; if no selection was made, the pin goes to the earliest board connected for the account. Requests to Pinterest are made in three cases: when the account is connected, at the moment of a scheduled publication, and during the daily check of the token expiry date — the renewal request itself is sent only when less than a week of the token’s validity remains. We do not poll feeds or pin statistics. Access is limited to the account that you connected yourself: we neither read nor collect the data of other Pinterest users.
We do not sell personal data and do not disclose it for advertising purposes without your separate consent.
Data is stored on servers located in the Russian Federation (Ubuntu 24.04 LTS, PostgreSQL with at-rest encryption, Redis with password protection).
Protection measures:
- TLS 1.2+ encryption of connections to all external APIs;
- access to the production infrastructure restricted to SSH keys and granted on a least-privilege basis;
- daily database backups, encrypted and kept in a separate zone;
- logging of administrator actions and of key operations;
- regular dependency updates and security audits.
Notwithstanding the measures applied, no online service can guarantee 100% protection; we undertake to notify users of material security incidents in accordance with the requirements of the law.
Personal data is retained for as long as is necessary to provide the services and to comply with the requirements of the law.
- Active accounts — the data is retained for the entire period the Service is used;
- Social network connections — the access and refresh tokens together with the account metadata are deleted at the moment the platform is disconnected in the Service; for Pinterest the saved boards are deleted along with them, and posts scheduled for Pinterest are removed from the schedule and returned to drafts;
- Publishing records — remain in the account as history and are deleted together with the account;
- Deleted accounts — retained in backups for up to 30 calendar days so that recovery remains possible, after which the data is permanently deleted (safe-delete);
- Financial documents — retained for the periods established by the accounting legislation of the Russian Federation (up to 5 years);
Access may also be revoked on the platform side — for example, by removing Boostix from the list of connected applications in the Pinterest settings. The token ceases to be valid immediately, and the next scheduled publication will fail with an error. The connection data retained on our side remains until you disconnect the platform in the Service or delete your account; you may also write to us and we will delete it on request.
A request to delete an account is processed within 3 business days — send a message from the email address of the account to business@boostix.space.
Under Federal Law No. 152-FZ you have the following rights in respect of your personal data:
- the right of access — to obtain information about what data we process and on what grounds;
- the right to rectification — to require that inaccurate or incomplete data be corrected;
- the right to erasure — to require deletion of the data and termination of the processing (the right “to be forgotten”);
- the right to restriction of processing — to request that processing be suspended in disputed situations;
- the right to portability — to receive a copy of your data in a machine-readable format;
- the right to withdraw consent — at any time and without giving reasons;
- the right to complain — to lodge a complaint with Roskomnadzor or to apply to a court at your place of residence.
To exercise these rights, write to business@boostix.space — we respond within 10 business days.
The current version of this Policy is always available at https://boostix.space/en/legal/privacy, with the date of the last update stated on the page.
We notify users of material changes at least 14 calendar days before they take effect — by email, in the interface of the Service and on the site. If you do not agree with the new version, you may delete your account before the date the changes take effect, without any penalty.
Continued use of the Service after the changes take effect constitutes your acceptance of the new version of the Policy.
For all questions concerning the processing of personal data — business@boostix.space.