Viewgram Privacy Policy
1. The short version
- Viewgram is a third-party app built on the open-source Telegram client. It is not an official Telegram app. Your Telegram account, messages, channels, groups, photos and videos travel directly between your device and Telegram's servers. Viewgram does not run the Telegram account system, and our servers do not receive or store that content.
- Viewgram's own servers store only the limited data listed in section 5: membership status and purchase records, daily-active records, heatmap viewing statistics, cloud-sync data and feedback tickets. The heatmap and cloud sync are free for everyone, on by default, and can be switched off in Settings.
- Before you agree to this policy on first launch, the app sends no request to Viewgram's servers.
- Speech recognition for subtitles runs entirely on your device. Audio is never uploaded.
- Viewgram contains no advertising SDK and no third-party analytics or crash-reporting SDK. We do not sell your data and do not track you across apps or websites.
- At any time you can delete most of the data we hold about you, or withdraw your consent, in Settings › About & Feedback (see section 10).
2. Who we are
Operator: VIEW TECH LTD(Company No. 17054082,England and Wales) ("we")
Contact email: support@viewgram.org
Website: https://viewgram.org
In-app contact: Settings › About & Feedback › Send Feedback
3. Definitions
- "Viewgram", "the app": the Viewgram for iOS application.
- "Telegram": Telegram Messenger and the servers and services it runs; Viewgram is not affiliated with it.
- "Viewgram's servers", "our backend": the service we provide through the gateway api.viewgram.org, with the database and authentication service hosted on Supabase.
- "Telegram user ID": the number Telegram assigns to your account; not your phone number.
- "Viewgram Pro": the paid features bought as an Apple in-app subscription.
- "Sync key": a random 32-byte key the app generates per Telegram account and keeps in iCloud Keychain; the server stores only its SHA-256 hash.
- "Anonymous session": an anonymous account created for this device on our backend; it contains no phone number or email.
- "You": an adult user of Viewgram.
4. The Telegram part: what we do not do
Viewgram connects to Telegram's servers over Telegram's MTProto protocol. Sign-in (phone number, login code, two-step password), messaging, channel and group content, media download and upload, voice and calls, contact sync, push notifications and Telegram's translation service are handled by Telegram, under Telegram's Terms of Service (https://telegram.org/tos) and Privacy Policy (https://telegram.org/privacy).
- We do not send your message content, contacts, phone number, calls, chat history or media files to Viewgram's servers.
- We cannot read your Telegram cloud chats and cannot sign in to, recover or delete your Telegram account for you. Deleting your Telegram account is done through Telegram's own functions (in the app: Settings › Privacy & Security › "If away for" and related options).
- Viewgram rearranges Telegram content in its interface (the recommendation feed and so on); this happens on your device.
5. Data stored on Viewgram's servers
The app reaches our own backend (a database and authentication service hosted on Supabase, region: Singapore (hosted by Supabase, AWS ap-southeast-1)) only through our gateway api.viewgram.org, which runs on Cloudflare. After you agree to this policy, the following is sent and stored:
| Data | What it contains | When it is sent | What it is for | Where it is stored | How long |
|---|---|---|---|---|---|
| Anonymous session | An anonymous account created for this device on our backend; the sign-up carries the app marker "view-ios" and your Telegram user ID (a number) | The first time you use a feature that needs a session (heatmap, cloud sync, purchase verification, feedback, deleting cloud data); the heatmap and cloud sync are on by default, so usually soon after you agree | Recognising membership status, attaching your feedback to you | Supabase authentication service | anonymous sessions are kept while the account is in use and are not purged on a schedule today; a sync-account row, together with the synced data hanging on it, is deleted after 24 months without use; Delete My Cloud Data does not delete the anonymous account itself |
| Membership lookup | Your Telegram user ID; the reply says whether membership is active, the plan and the expiry date | When the app opens, returns to the foreground or refreshes membership | Deciding whether Viewgram Pro is active | The lookup itself is not kept; the daily-active record it writes is the next row | See "Daily-active record" |
| Feature-flag lookup | Your Telegram user ID and whether the account has Telegram Premium (yes / no) | When the app opens | Per-account feature switches (for example staged rollout, turning a feature off) | Answered on the spot | — |
| Daily-active record | Your Telegram user ID, the date, the number of lookups that day | Each time membership is looked up | Counting how many people use the app each day | Our database | kept for 13 months, then deleted |
| Membership status and purchase record | After you buy Viewgram Pro: the transaction Apple signed (original transaction ID, product, purchase and expiry dates, environment) and the account's sync key; the server keeps only the SHA-256 hash of the key and updates the record when Apple reports a renewal, expiry or refund. No name, email, payment details, phone number or messages | On purchase, on Restore Purchases and on later refreshes | Confirming that the subscription is valid, so that Pro features follow the real subscription | Our database | Kept while the subscription is active; deleted 24 months after the subscription ended |
| Video heatmap viewing statistics (free, on by default for everyone, can be switched off in Settings; uploaded only for videos in channels and groups) | The video split into 100 segments: how many passes actually played each segment, where seeks landed, watch time; the video's file number on Telegram (no chat, message number or text); a device identifier (see note 3 below) | Overwritten every 30 seconds while you watch a video in a channel or group, once more when you close the video or go to the background; queued on the device while offline for up to 7 days. Runs automatically, without asking each time | Drawing the "most replayed" curve on the progress bar | Our database | kept without a fixed deletion date, because the more complete the statistics the more accurate the curve; it holds no name, phone number, message ID or text and is linked only to a device identifier; what this device submitted can be deleted at any time in Settings › About & Feedback › Delete my cloud data; the request IDs used for deduplication are deleted after 30 days; what this device submitted can be deleted in the app |
| Cloud-sync data (free, on by default for everyone, runs automatically when iCloud Keychain is available for your Apple ID; can be switched off in Settings › Watching › Cloud Sync) | Videos you watched in channels and groups (source ID, message ID, time watched, video size and length); videos you saved from channels and groups and the category names you made; the categories you gave channels and groups; the matching deletion markers; and a random device identifier generated on this device (to tell devices apart, unrelated to hardware) | About 1.5 seconds after a change and when the app returns to the foreground, then checked every 60 seconds; runs automatically, without asking each time | Syncing between devices signed in to the same Apple ID | Our database | Until you delete it or use Delete My Cloud Data; a sync account not used for 24 months is deleted together with its data; deletion markers are purged on the server after 180 days |
| Hash of the sync key | For each Telegram account the app creates a random 32-byte sync key on your device and keeps it in iCloud Keychain; the server stores only its SHA-256 hash | When syncing, verifying a purchase and deleting cloud data | The server recognises "the same data" by this hash instead of trusting the Telegram user ID the app reports | Our database | Same as the sync data and purchase record it belongs to |
| Feedback tickets | The text you write (4 to 4,000 characters), the category, an optional contact, app version and build, device model, OS version, language, and our replies. The current version does not support attachments | When you submit or reply to feedback | Handling your issue | Our database | Resolved or closed tickets are deleted 24 months after the last update (their messages go with them); open tickets are not deleted automatically; tickets from this device's session can be deleted in the app |
What you should know about this data:
- Sync data and your Telegram user ID. The synced rows do not contain your Telegram user ID; the server files them under an internal account number derived from the sync-key hash. However, every row also records the anonymous session that wrote it, and that session was created with the Telegram user ID the app reported. So, technically, we could link synced data to your Telegram account. We do not do this for advertising or any purpose unrelated to the features.
- Source IDs are information too. The channel and group IDs in your history and categories reveal which channels and groups you follow. Please weigh this when deciding whether to leave cloud sync on (it is on by default and can be switched off in Settings).
- The heatmap device identifier is computed on your device by hashing the system app identifier (identifierForVendor) together with a fixed salt and your account with SHA-256 and keeping part of the result. The original identifier cannot be recovered from it, two accounts on the same phone get unrelated identifiers, and it is used only to count one device once per video. The aggregated heat curve contains nothing that maps to a person.
- Never uploaded: history, favorites and heatmap data of videos from private chats, secret chats and self-destructing (timed) messages are never uploaded. Videos in secret chats and self-destructing messages are not even recorded in the history on your device.
- IP addresses and network logs. When your device connects to api.viewgram.org, Cloudflare, as the network provider, processes connection information including your IP address. Our gateway removes the client-IP headers supplied by Cloudflare when it forwards a request to the backend. The database platform (Supabase) and its infrastructure may keep their own operational logs.
- Administrative access. Our operators read and handle this data through an internal admin console (for example answering tickets, granting or revoking membership, viewing aggregate statistics). The console is not open to users, and every change is written to an audit log.
6. Data kept only on your device
- Watch history, video favorites and categories, search history, "not interested" videos, hidden channels and groups, the local heatmap cache, and playback preferences stay on your device by default. Only while cloud sync (section 5) is running (it is on by default and can be switched off in Settings) are watch history, video favorites and source categories from channels and groups synced.
- Subtitles: speech recognition during playback is done on the device by the sherpa-onnx engine and its models; audio is not uploaded. The models are downloaded the first time you turn subtitles on: about 240 MB for the base pack (SenseVoice and Silero VAD), plus about 160 MB (ReazonSpeech) for Japanese videos. They are downloaded from Hugging Face (huggingface.co) and GitHub (github.com). By default this happens over Wi-Fi only; on cellular, a personal hotspot or Low Data Mode the app asks for your consent first.
- Subtitle translation: when subtitles are translated into the language you choose, the text to translate is processed by Telegram's translation service (see section 7), not by our servers.
- Thumbnails and tags: the mosaic thumbnails of videos and the grouping of #tags in the recommendation feed are computed on your device from what the message itself carries.
- Voice-to-text: voice messages and the music player's captions use Apple's speech-recognition framework set to on-device only; a language without an on-device model fails instead of sending audio to Apple's servers.
- On-device data is deleted when you uninstall the app. When you sign out of a Telegram account, the app removes that account's local favorites, history, search history, the queue of heatmap data waiting to be sent, and the session on our backend, but keeps the sync key (in iCloud Keychain) so that signing in to the same account again recovers your cloud data. To disconnect completely, use Delete My Cloud Data first.
7. Third parties and recipients
| Service | Role | What it may see |
|---|---|---|
| Telegram | Account, messages, media, translation, push | Everything you do in Telegram; the text to translate for subtitles; Telegram's privacy policy applies |
| Supabase | Our backend database and authentication (the project address sits behind the gateway) | The data in section 5. Database region: Singapore (hosted by Supabase, AWS ap-southeast-1) |
| Cloudflare | Network forwarding for the gateway api.viewgram.org | Requests passing through the gateway (including connection information such as IP); the gateway stores no business data |
| Apple | App Store purchases and subscriptions, iCloud Keychain (stores the sync key), APNs push | Apple processes your payment and we never see payment details, your name or your email; push notifications are sent by Telegram's servers via APNs, our servers send none |
| Hugging Face, GitHub | Download of subtitle model files | The download requests your device makes (IP and similar) |
| Google reCAPTCHA | The human check Telegram may ask for at sign-in or sign-up | Triggered by Telegram's sign-in flow; Google's privacy policy applies (https://policies.google.com/privacy) |
Notes:
- Purchases: Viewgram Pro is an auto-renewing App Store subscription. We cannot see your card details. Purchase receipts go only to our server (see "Membership status and purchase record" in section 5), never to Telegram.
- "Global web search" (third-party search bots): not available in this version. The code remains but cannot be switched on by a server flag or a user setting. If a future version offers it, this policy will be updated and you will be told before use, because it sends your search text, through your own Telegram account, to third-party bots.
- Analytics and advertising: Viewgram has no advertising SDK, no attribution SDK, no third-party analytics SDK and no crash-reporting SDK. It does not use App Tracking Transparency and does not track you.
- We do not sell, rent or exchange your data with anyone. We disclose data to authorities only where the law requires it or where it is necessary to protect users and the service.
8. Purposes and legal bases
| Purpose | Data | Legal basis (where applicable) |
|---|---|---|
| Providing features (membership, cloud sync, heatmap, feedback) | All of section 5 | Performance of the service contract with you; the heatmap and cloud sync are on by default, we disclose them in this policy and give you a switch in Settings, with no separate consent step; model downloads on cellular ask for your consent first |
| Deciding and switching features per account | Membership lookup, feature-flag lookup | Performance of the contract |
| Aggregate statistics, knowing whether the app is used | Daily-active record, heatmap aggregates | Our legitimate interest in understanding and improving the product |
| Keeping the service stable and preventing abuse (deduplication, rate limits, retries) | Heatmap device identifier, feedback rate limiting (per session) | Our legitimate interest in the security of the service |
| Answering your requests and legal obligations | Feedback tickets, deletion and export requests | Compliance with legal obligations; your consent |
The agreement screen on first launch is your informed consent to this policy; how to withdraw it is in section 10. Withdrawing does not affect the lawfulness of processing done before the withdrawal.
Applicable data-protection laws: the UK GDPR and the Data Protection Act 2018; the EU GDPR as well when you are in the EU; and any other data-protection law of the place where you are. Where the law of your place of residence (for example the EU General Data Protection Regulation, GDPR, or Malaysia's Personal Data Protection Act, PDPA) gives you rights this policy does not mention, that law prevails.
9. Retention
| Data | Retention |
|---|---|
| Cloud-sync data | Until you delete it or use Delete My Cloud Data in the app; a sync account not used for 24 months is deleted together with the synced data hanging on it. Deletion markers (tombstones) are kept on the server for 180 days and then purged |
| Heatmap viewing statistics | Kept without a fixed deletion date, because the more complete the statistics the more accurate the curve; it holds no name, phone number, message ID or text and is linked only to a device identifier; what this device submitted can be deleted at any time in Settings › About & Feedback › Delete my cloud data; the request IDs used for deduplication are deleted after 30 days (what this device submitted can also be deleted in the app) |
| Daily-active records | Kept for 13 months, then deleted |
| Anonymous session and account rows | Anonymous sessions are kept while the account is in use and are not purged on a schedule today; a sync-account row, together with the synced data hanging on it, is deleted after 24 months without use. Delete My Cloud Data does not delete the anonymous account itself or the sync-account row (the clear marker hangs on it); to have them removed completely right away, ask through feedback |
| Feedback tickets | Resolved or closed tickets are deleted 24 months after the last update (their messages go with them); open tickets are not deleted automatically; feedback submitted by this device's session can be deleted with Delete My Cloud Data |
| Membership status and purchase records | Kept while the subscription is active, so that a subscription you bought is not affected; deleted 24 months after the subscription ended |
| On-device data | Under your control; deleted when the app is uninstalled |
When a period ends or you delete the data, it is removed from our database; backups and infrastructure logs are overwritten within the hosting providers' regular cycles.
10. Your rights and how to delete
- Delete inside the app: Settings › About & Feedback › Delete My Cloud Data. It deletes the cloud-sync data tied to this sync key (history, video favorites and their categories, source categories) and the heatmap statistics and feedback tickets submitted by this device's anonymous session, and syncs a "cleared" marker to your other devices signed in to the same Apple ID, which then clear their synced copies. It does not delete: membership status, your Telegram account, data kept only on devices (private chats and the like), daily-active records, or heatmap statistics and feedback submitted from your other devices.
- Withdraw consent: Settings › About & Feedback › Withdraw Consent. Afterwards the app sends nothing more to our servers and shows the agreement screen again before the next use; Telegram itself keeps working. Withdrawing does not delete data already on the server; use Delete My Cloud Data first.
- Switch off the heatmap and cloud sync: both are free for everyone, on by default and run automatically, without asking each time. Turning off "progress-bar heatmap" in Settings stops recording, discards the current statistics and empties the on-device queue; turning off Settings › Watching › Cloud Sync stops syncing new content. Data already on the server does not disappear because of that; delete it with Delete My Cloud Data (point 1).
- Access, correction, export, deletion, restriction and objection: for deletions the app cannot do, for access to, correction or export of your data, and, where applicable law allows, to restrict or object to a processing, use Settings › About & Feedback › Send Feedback or email support@viewgram.org. We handle requests within 30 days; if the in-app deletion fails, the app points you to this route. To verify that it is you, we may ask you to submit the request from inside the app.
- Complaints: if you believe our processing breaks applicable law, you have the right to complain to the data-protection authority where you live.
- Delete your Telegram account with Telegram's own functions; that is separate from Viewgram's cloud data.
Using the app after deletion creates new records.
11. Security
- Communication with our backend uses HTTPS.
- The sync key is stored in iCloud Keychain (available after the device's first unlock); the server stores only its hash. The backend session is stored in the device keychain.
- Database tables are closed to clients by default; clients read and write only through restricted server functions, sync functions require a valid session and the sync key, and purchase verification requires a transaction signed by Apple.
- The admin console is open to operators only, and every change is written to an audit log.
- We do our best to protect data, but no method of transmission or storage is completely secure.
12. International transfers
Our backend and your device may be in different countries or regions; the servers of Cloudflare, Supabase, Telegram, Hugging Face and GitHub are also spread across regions. By using Viewgram you accept that the relevant data may be processed outside where you live. We apply the measures in section 11 and, where applicable law requires it, rely on a transfer mechanism that law recognises.
13. Children
Viewgram is not intended for anyone under 18 and does not knowingly collect data from minors. Viewgram has no age verification of its own: you must meet Telegram's age requirement for registering an account, and you must be an adult to use Viewgram. The content Viewgram shows comes from the channels, groups and users you joined on Telegram and may include adult material; whether content can be viewed is decided by Telegram's rules. If you find a minor using the app, tell us through the contact above and we will delete the related cloud data.
14. Changes to this policy
When the policy changes we update this page and the same text in the app, the "Last updated" date and the version number. For material changes the agreement screen is shown again in the app, and until you agree once more the app sends no data to Viewgram's servers.
15. Contact
Operator: VIEW TECH LTD(Company No. 17054082,England and Wales)
Email: support@viewgram.org
Address: Suite 1310, 5 Brayford Square, London, E1 0SG, United Kingdom
Website: https://viewgram.org
In the app: Settings › About & Feedback › Send Feedback