Skip to content
DigitalCostBot
Home Sign in Register
Home / Personal data processing policy

Personal data processing policy

Current version dated 2026-08-02

This policy describes what data the DigitalCostBot service at https://digitalcostbot.com processes, why, on what basis and for how long. The data controller is [operator details not set — fill them in config/app.php]. Questions about data processing: [operator details not set — fill them in config/app.php]. This is a translation for convenience; in case of any discrepancy the Russian version of this document prevails.

1. What data is processed

The service collects the minimum needed to operate an account. Full name, phone number, identity document details and bank card details are never requested and never stored.

  • Email address — the account identifier, used for sign-in, password recovery and service notifications.
  • Password hash — an irreversible value; the password itself is not known to the controller.
  • Telegram user and chat identifiers — only if you connected the Telegram bot.
  • Profile settings: language, time zone, base currency, reminder preferences.
  • Financial records you create yourself: amounts, dates, service names, categories, projects and comments.
  • Technical session data: sign-in time, a hash of the IP address and of the user agent, used to protect the account.
  • Payment data: internal order number, amount, status and the provider's operation identifier.

2. What the service does not collect

  • Bank card details — these are entered on the payment provider's side and never reach the controller.
  • Access to bank accounts, statements or online banking.
  • The contents of your mailbox, files or contacts.
  • Special categories of personal data and biometrics.

3. Purposes and legal basis

  • Providing the service and performing the contract (the public offer).
  • Sending service notifications about charges, limits and account state.
  • Security: protection against password guessing, detection of unusual activity, the audit log.
  • Compliance with statutory obligations, including retention of payment records.
  • Marketing messages — only with separate consent, revocable at any time and independently of service notifications.

4. Sharing with third parties

The controller does not sell personal data. Data is shared only to the extent a specific feature requires.

  • The payment provider, when you pay for a plan: the amount, order number and email address for the receipt.
  • Telegram, when you use the bot: the text of your messages and the service's replies.
  • The AI parsing provider: only the expense text and a limited list of your category, project and service names. Email, password, payment details and full operation history are not sent.
  • The hosting provider, as a processor, for running the service and its database.

5. Storage and retention

The database of users who are citizens of the Russian Federation is located in the Russian Federation as required by Federal Law No. 152-FZ. The specific hosting location is stated in the contract with the hosting provider.

  • Account data and financial records — for as long as the account is active.
  • After account deletion, data is erased within 90 days, except for records the controller must retain by law.
  • Security logs — 30 to 90 days.
  • The action audit log — up to one year.
  • Payment records — for the period required by accounting and tax law.

6. Your rights

Requests should be sent to [operator details not set — fill them in config/app.php] and are answered within the statutory time limits.

  • Obtain information about the processing of your personal data.
  • Require correction, blocking or erasure of inaccurate or unlawfully obtained data.
  • Export your records in a machine-readable format.
  • Withdraw consent to processing and delete your account.
  • Complain to the supervisory authority or through the courts.

7. Security measures

  • All traffic is served over HTTPS.
  • Passwords are stored as irreversible hashes; integration secrets are stored encrypted.
  • Access to data is separated by workspace.
  • Request rate limiting and protection against password guessing.
  • Action logging and regular backups.

8. Changes to this policy

A new version is published on this page with its date. Significant changes are additionally announced by email. The date of the current version is shown at the top of this document.

See also

  • Terms of service
  • Consent to recurring charges
  • Use of cookies
DigitalCostBot

AI-powered tracking for work expenses and subscriptions.

Personal data processing policy Terms of service Use of cookies

© 2026 DigitalCostBot