Privacy policy
This page sets out what data XMBoost collects, why it is needed, who it is shared with and what you can do about it. No legal fog: if any mechanism works differently from what is described here, treat it as a bug and write to us.
Revision of 29 July 2026.
1. Who processes the data
Operator — CRYPTORUN LIMITED, a company registered in Hong Kong (Company No. 3243374, Business Registration No. 74957982), address: Unit 305, 11/F, Sun Fung Industrial Building, 8-12 Ma Kok Street, Tsuen Wan, Hong Kong. The Service is the XMBoost platform, which finds messages containing a commercial enquiry in public Telegram chats and delivers them to the client as leads.
Questions about data: [email protected] or support on Telegram.
2. What data we collect
2.1. Account data
- the email address and name you provided when signing up;
- the password — only as an irreversible hash (bcrypt); the plain password is not stored and is not available even to us;
- the two-factor authentication secret, if you have enabled it;
- your Telegram ID and username — if you linked Telegram to your account or set up lead delivery;
- interface language, time zone, notification settings;
- the account activity log: sign-ins, settings changes, payment operations.
2.2. Project data
- the website address and business description you provided when creating the project;
- the client profile, keywords, instructions for the AI, the delivery threshold;
- the list of connected source chats and the chat where leads are delivered;
- files with a list of chats, if you uploaded them yourself.
2.3. Technical data
- Your IP address and browser parameters at sign-up and sign-in (device type, screen resolution, time zone, font set, graphics subsystem characteristics) — an anonymised device fingerprint is derived from them in the form of an irreversible hash;
- session cookies and technical request logs.
The device fingerprint is a hash string. It cannot be used to reconstruct the original parameters, identify a person or track you across other websites: it is not shared anywhere and is used only inside the platform, for the purpose described in section 3.2.
2.4. Payment data
We neither receive nor store card numbers, CVV codes or wallet credentials — they are handled by the payment provider on its own side. All that reaches us is the amount, the currency, the payment status and a technical transaction identifier. The balance, the payment history and referral programme accruals are stored by us.
2.5. Messages from public Telegram chats
This is the essence of the service, so we explain it in detail. The platform reads messages in the public Telegram chats connected to a project and processes:
- the text of the public message;
- the author’s public data: the identifier, the username and the display name exactly as Telegram shows them;
- the chat title, the time it was posted and the link to the message.
What we do not do:
- we do not read private correspondence or closed chats we have no access to;
- we do not post messages, do not reply, do not add reactions and do not run mailings;
- we do not collect phone numbers and do not buy contact databases.
A message that the AI has recognised as a commercial request is delivered to the client as a lead. From that moment on the client is an independent operator of that data and is responsible for how they handle it (see terms of use). The author of a message may require us to delete their data from our database — the contacts are in section 8.
2.6. The client’s connected Telegram account
If you connect your own Telegram account to monitor chats you are a member of, the session is stored encrypted and used strictly for reading. We do not send messages on your behalf, do not change your profile and do not read your private conversations. You can disconnect the account at any time — the session is then deleted.
3. Why we do this
3.1. To make the service work
To create and run your account, find and deliver leads, show statistics, accept payment, answer you in support, send emails about the state of your account (email confirmation, the first lead, the end of the free period, invoices and payment reminders). The basis is performance of the contract with you.
3.2. To grant the free period only once
The free period is meant for one person, not for one registration. To stop it being claimed over and over from new email addresses, we check four signals when granting it: the account owner’s Telegram, the website domain from the project settings, the sign-up IP address and the device fingerprint. The IP and the device are taken into account only where a free period has already been claimed from them.
What this means in practice:
- We do not block anyone. You can create as many accounts as you like, and all of them stay fully functional.
- The only consequence of a match is that the free period is not granted a second time; access is opened by buying a plan.
- If we got it wrong — you really have not had a free period — write to support, we will sort it out by hand and grant it.
The basis is our legitimate interest in not letting a free offer turn into a free service paid for by our paying clients.
3.3. To keep the platform secure
Request logs, the activity log and rate limiting are needed to protect against password guessing, automated attacks and abuse, and to investigate incidents. The basis is our legitimate interest.
3.4. To improve the product
We look at anonymised usage statistics: how many leads are found, which settings work better, where people get stuck in the interface. There is no separate advertising profiling and no sale of data — client data is never sold or passed to advertising networks in any form.
4. Cookies
We use only what the platform cannot work without:
- session cookies — so that you stay signed in;
- service cookies that protect against request forgery;
- the theme you chose — it is kept in the browser’s localStorage and is never sent to the server.
There are no third-party advertising or tracking cookies on the platform, so there is no consent banner either: there is nothing to switch off.
5. Who the data is shared with
For the service to work, part of the data is processed by vendors. Each of them receives the minimum necessary and has no right to use the data for its own purposes.
| Vendor | Why | What they receive |
|---|---|---|
| Vercel, Railway, Neon | hosting for the platform, background services, the Telegram bot and databases | account and project data, technical request logs, IP address |
| Telegram (Telegram FZ-LLC) | reading open chats and delivering leads | chat and message identifiers, identifier of the lead recipient |
| Zoho (Zoho Corporation B.V., EU) | domain email service: sending the platform’s emails | email address, contents of the message |
| DeepSeek, Z.ai (GLM), MiniMax, OpenRouter, Anthropic | analysis of messages and generation of a relevance score | the text of a message from an open chat, project settings (customer profile, selection criteria) |
| NOWPayments | accepting payments | payment amount and status; payment details are processed by the provider (we neither receive nor store them) |
Separately about AI models: what goes for analysis is the text of the message from the public chat and the settings of your project. Passwords, payment data and the contents of your private correspondence are never sent there.
Apart from our vendors, data may be disclosed at the mandatory demand of a competent authority — only to the extent expressly required by law.
6. Where the data is stored
The Operator is registered in Hong Kong, and our subprocessors’ servers are located outside your country of residence, including in the European Union and the United States. By signing up, you understand and accept that your data will be processed across borders. We choose providers that publish their data protection commitments, and we pass each of them only the necessary minimum.
7. How long we keep the data
- Account and project data — for as long as the account exists. After the account is deleted, they are erased within 30 days, except for information we are required to keep by law (for example, accounting records for payments).
- Leads and messages from chats — for as long as the project exists; when the project is deleted, they are deleted with it.
- Free period eligibility signals (sign-up IP, device fingerprint, website domain) — 24 months, and they survive the deletion of the account. Otherwise the “one free period per person” rule could be sidestepped by deleting the account and signing up again. These records are not linked to your email or your name and are used for nothing other than checking eligibility for the free period.
- Security journals and technical logs — up to 12 months.
8. Your rights
You can:
- obtain a copy of the data we store about you;
- correct inaccurate data — some of it can be edited right in your account settings;
- delete your account and your data (subject to the reservation in section 7);
- object to processing that relies on legitimate interest;
- withdraw your consent where the processing is based on it;
- lodge a complaint with a data protection supervisory authority.
Send your request to [email protected] from the address the account is registered to — we will reply within 30 days. If you are the author of a message from a public chat and want us to delete your data, write to the same address and include the link to the message.
9. How we protect the data
- traffic encryption (HTTPS) on all pages;
- passwords — an irreversible hash, two-factor authentication if you want it;
- sessions of connected Telegram accounts and bot tokens are stored encrypted;
- employee access to client data is limited by role and written to a log;
- rate limiting and protection against automated attacks.
No protection is absolute — if an incident does affect your data, we will tell you about it and about the measures we have taken.
10. Minors
The service is intended for business and is not meant for persons under 18. We do not knowingly collect their data; if such data has reached us — tell us, and we will delete it.
11. Changes to this policy
If we make material changes, we will update the revision date at the top of the page and notify you by email or in the platform interface no later than 10 days before they take effect. By continuing to use the service after that date, you accept the new revision.
12. Contacts
CRYPTORUN LIMITED (Company No. 3243374, Business Registration No. 74957982), Unit 305, 11/F, Sun Fung Industrial Building, 8-12 Ma Kok Street, Tsuen Wan, Hong Kong. Email: [email protected]. Phone: +971 58 581 0802. Support: @xmboost_bot.

